Josip Franjković - archived security blog

Saturday, 6 December 2014

Reading local files from Facebook's server (fixed)

›
Hello, Recently I found a vulnerability in Facebook which allowed me to read local files from Facebook's servers. The vulnerable part...
3 comments:
Friday, 5 September 2014

Step-by-step: exploiting SQL injection(s) in Oculus' website.

›
Hello, Some time ago Jon of Bitquark tweeted that he found a SQL injection and RCE in one of Facebook's acquisitions. You can find ...
Thursday, 21 November 2013

Facebook bug bounty: secondary damage (one report that leads to more bugs), fairness, and why I really like reporting to Facebook

›
Hello, Usually, the process for bug bounty is as follows: Person finds a bug, reports it to company Company fixes the bug $$ sent t...
3 comments:
Tuesday, 30 July 2013

SQL injections in Nokia sites.

›
Hello, I have found out about Nokia security reward program somewhere mid-April. Reports of people getting one or more mobile phones mad...
Tuesday, 23 July 2013

How I found my way into Instagram's Ganglia, and a bug with Facebook likes.

›
Hello, I have recently taken part in Facebook Whitehat reward program, and here are some of my findings: Access to Instagram's Ga...
2 comments:
Thursday, 3 January 2013

Google.com cross site scripting and privilege escalation in Consumer Surveys

›
Hello, I have recently found a persistent cross site scripting and privilege escalation in Google Consumer Surveys . Here are proofs of ...
‹
Home
View web version
Powered by Blogger.