HackerOne
9.8K subscribers
633 photos
30 videos
76 files
2.69K links
Community : @Sec0x01
@Bug0x
Admin : @Offensive
Download Telegram
Vulnerabilities in 5G

1) A protocol vulnerability in 4G and 5G specification that allows the fake base station to steal information about the device and mount identification attacks
2) Implementation vulnerability in cellular network operator equipment that can be exploited during a device registration phase
3) A protocol vulnerability that affects the battery life of low-powered devices
https://infosec.sintef.no/en/informasjonssikkerhet/2019/08/new-vulnerabilities-in-5g-security-architecture-countermeasures/
Instagram Added to Facebook Data-Abuse Bounty Program

Social media giant also launches invitation-only bug bounty program for 'Checkout on Instagram'.

Instagram users aware of a third-party application developer misusing their personal data can now report the activity to the company and potentially earn a reward for it.

Facebook, which owns Instagram, on Monday expanded its Data Abuse Bounty program to Instagram in a continuing effort to crack down on application developers and other third parties that are misusing user data on the company's social media platforms.
https://www.darkreading.com/vulnerabilities---threats/instagram-added-to-facebook-data-abuse-bounty-program/d/d-id/1335569
Exfiltration through FTP using OOB XXE

Upload accepts .xlsx files --> Unzip sample .xlsx file -> add payload in workbook.xml/[Content_Types].xml after xml declaration --> DTD file send data via ftp://remote-ip/%data --> run ftp server using xxe-ftp-server.rb --> /etc/passwd

Via: https://twitter.com/_ayoubfathi_/status/1164536885244583941
Price For Mobile Exploits
Forwarded from P0SCon
Abstracts are received. After evaluating the abstracts and arranging travel and resistance, the details of speakers will be announced.

P0SCon2019

📆 12 Oct 2019

Register for P0SCon2019:

🇮🇷 ::Iranian Citizens::
https://evnd.co/w3uRC

🇺🇳::Non-Iranian Citizens::
Contact: p0scon@uut.ac.ir


http://poscon.ir

@P0SCon
What happens if we use our brain's 100% capacity
https://twitter.com/cyanpiny/status/1175030939891712000