General

Microsoft Yammer Clickjacking - Exploiting HTML5 Security Features

    Introduction: Modern Web Applications nowadays are relaying on a lot of technologies where typical web applications vulnerabilities are hard to find (eg. Clickjacking is an ABC security bug) but bug hunters are always the best! Yammer is a freemium enterprise social networking service used for private communication within organizations. Access to a Yammer network is […]

When your privacy disclosure is a "feature" not a "bug" - Badoo & HotorNot failure!

Your privacy on the internet is the biggest concern ever and when it comes to “Dating websites” and “Social Networks” it means more and more! Let me tell you a story of two websites that don’t respect yours and putting it on danger…

Fiverr.com Full Accounts Takeover - A Vulnerability Puts $50 Million Company At Risk

Fiverr.com, a global online marketplace which provides a platform for people to sell their services for five dollars per job, is vulnerable to a critical web application vulnerability that puts its millions of users at risk. Fiverr raised $30 million in a third round of institutional funding to continue supporting the new version of its […]

Facebook Vulnerability - a “Cute Bug” that reveals the “likes” of deleted posts regardless of their privacy settings

Hi Folks, My name is Mohamed Abdel Aty, an Egyptian Web Developer & Bug Hunter, Today I would like to share with you a “cute” bug I found while doing some bug hunting in Facebook. Testing different sub-domains is a common procedure in bug hunting , while searching the domain “mbasic.facebook.com” I noticed this link

FirefoxOS Find My Device Service Clickjacking Bug results in Changing PINs, Wiping and Locking Phones!

Introduction: Physical devices connected with web applications made everything easy to be managed. Screen size, availability, usage etc… is what pushing everyone to manage their devices through their desktops/laptops! On the other hand such advantages poses a threat if these web applications contains security issues! For example android devices can be managed through “Google Device Manager”,  iOS devices […]

Facebook movies recommendation vulnerability - A bug capable of erasing all your important notifications!

Hi Folks, Facebook is the largest social network ever known on the internet, People are using Facebook for contacting friends, Family and sometimes for Work! When it comes to Work that means an important notifications from your company’s page, work account, work admins, business accounts, etc…

WhatsApp Clickjacking Vulnerability - Yet another web client failure!

Hi Folks, I know it’s a little bit lame to mention 2 clickjacking vulnerabilities in row but that what bug hunters always do exposing the largest companies security failures, (Previously was Telegram) this time is the gigantic well-known 19 billion dollar messenger WhatsApp.

Official Telegram Web Client ClickJacking Vulnerability - When crypto is strong and client is weak

    [*] Introduction: Modern Web Applications nowadays are relaying on a lot of technologies where typical web applications vulnerabilities are hard to find (eg. Clickjacking is an ABC security bug) but bug hunters are always the best!

Web Application Security on Fire - PHP Developers Cheat Sheet version (Slides from UNAM Mexico talk)

  Hey! Building a website? Or already built a one? Think twice before going public and let us protect your business!

VoIP Security Analysis with Asterisk

Adopting new technologies such as VoIP by small, medium and large companies, isn’t only  about the benefit representing a decrease in costs, is about an risk increase exposure too, which can be reflected in the payment of  large sums of money , because (national or international) calls made by people outside the company.

Facebook API 2.x Bypassed!

This is the write up of my last Facebook Report, How I was able to bypass the permissions approvals system in the 2.x Facebook API Versions in 2 different ways. FIRST Flow : +++Flow discussion:

Previous page Next page

Translate this blog