Neil Mark Ochea 馃暦

I just love exploring security vulnerabilities and hacking things.

Security Researcher @mobilehackinglab

DOM-Based JavaScript Execution in Xiaomi Browser Reader Mode via <title> HTML Injection (Android)

A DOM-based Cross-Site Scripting (XSS) vulnerability was discovered in Xiaomi Browser鈥檚 Read Mode due to insufficient sanitization of the HTML tag, allowing arbitrary HTML or JavaScript to be executed via innerHTML.

November 117, 161628 路 3 min 路 622 words 路 Me

Referrer Data Leakage in Facebook via Unvalidated data_uri Parameter

An open redirect vulnerability was discovered in Facebook鈥檚 Privacy Checkup endpoint due to the ?back_uri= parameter being processed without any security filtering, allowing attackers to redirect users to malicious website.

November 117, 16169 路 2 min 路 391 words 路 Me

Linkshim Bypassed in Facebook Push Notication via Double URL Encoding

A persistent open redirect vulnerability was discovered in Facebook鈥檚 Push Notification endpoint due to improper validation of the ?ref= parameter, allowing attackers to redirect users to malicious sites and potentially facilitate phishing attacks.

November 117, 161636 路 2 min 路 401 words 路 Me

Cross-Site Scripting in Opera Browser Reader Mode via Malicious <title> Tag (Android)

A reflected Cross-Site Scripting (XSS) vulnerability was discovered in Opera Browser for Android鈥檚 Reader Mode due to insufficient sanitization of the HTML tag, allowing attackers to execute arbitrary JavaScript, steal sensitive data, or inject malicious content

November 117, 161633 路 3 min 路 572 words 路 Me

Journey

November 117, 16161 路 0 min 路 0 words 路 Me