research

NOKIA HOF – INTERNAL IPS DISCLOSURE

IntroductionHi everyone this is a write up about how do I got into the Nokia security Program Hall of Fame, so here we go: This blogpost appeared first in the book Bug Bounty Write Ups Collection Note: this bug has been reported in about 10 companies and only Nokia accepted it as a valid report […]

FACEBOOK N/A – FILE DISCLOSURE VIA .DS_STORE FILE (MACOS)

IntroductionHi everyone, this is another Facebook Whitehat Report write up (Facebook marked the report as N/A, but some another programs accept this bug as a valid bug bounty, per ex. Twitter so this might be can be useful in some scenarios), well,  there you go: This blogpost appeared first in the book Bug Bounty Write […]

CTF ESET LATINOAMÉRICA CHALLENGE #36

IntroductionHello , here is my write up for the CTF “Desafio ESET #36: Juego de escape criptográfico” (ESET Challenge # 36: Cryptographic escape game) This blogpost appeared first in the book Bug Bounty Write Ups Collection CTF:https://www.welivesecurity.com/la-es/2017/12/26/desafio-eset-36/ CTF Solution (official):https://www.welivesecurity.com/la-es/2018/01/12/solucion-desafio-eset-36/ Rules:1.- download the desafio36.zip file (mirror) md5=2b7a11892638179573f7b17c4b74911a2.- unzip the file3.- start looking for clues and find the […]