<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>bugbounty on Christian Niel Angel</title>
    <link>https://ctulhu.me/tags/bugbounty/</link>
    <description>Recent content in bugbounty on Christian Niel Angel</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <copyright>© 2024 Christian Niel Angel</copyright>
    <lastBuildDate>Sun, 14 May 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://ctulhu.me/tags/bugbounty/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Full Passcode bypass on Nextcloud App iOS</title>
      <link>https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/</link>
      <pubDate>Sun, 14 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/</guid>
      <description>It&amp;rsquo;s possible to fully access the user&amp;rsquo;s nextcloud files on Nextcloud App iOS by using the Files app on iPhone. Proof of Concept: # Download the nextcloud iOS app Login your account set a passcode Open the files app then go to &amp;gt; Browse Under the locations pick nextcloud click turn on References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/full-passcode-bypass-on-nextcloud-app-ios/featured.png" />
    </item>
    
    <item>
      <title>Ability to read any emails through IDOR on Nextcloud Mail</title>
      <link>https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/</link>
      <pubDate>Fri, 12 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/</guid>
      <description> An attacker can access the mail box by ID getting the subjects and the first characters of the emails. References # https://hackerone.com/reports/1784681 https://nvd.nist.gov/vuln/detail/CVE-2023-25160 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m45f-r5gh-h6cx </description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/ability-to-read-any-emails-through-idor-on-nextcloud-mail/featured.png" />
    </item>
    
    <item>
      <title>Messages can still be seen on conversation after expiring when cron is misconfigured</title>
      <link>https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/</guid>
      <description>Nextcloud talk has a feature called Message Expiration, Chat messages can be expired after a certain time. In order for messages to be removed from the database, the cron jobs need to be executed.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/messages-can-still-be-seen-on-conversation-after-expiring-when-cron-is-misconfigured/featured.png" />
    </item>
    
    <item>
      <title>Ability to control the filename when uploading a logo or favicon on theming</title>
      <link>https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/</link>
      <pubDate>Mon, 10 Apr 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/</guid>
      <description>When uploading a logo or favicon the filename can be controlled by attacker since the key can be modified which serves as the filename. Proof of Concept: # go to http://localhost/settings/admin/theming upload a logo or favicon intercept the request using burp modify the key References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/ability-to-control-the-filename-when-uploading-a-logo-or-favicon-on-theming/featured.png" />
    </item>
    
    <item>
      <title>Passcode bypass on Talk Android app</title>
      <link>https://ctulhu.me/security/passcode-bypass-on-talk-android-app/</link>
      <pubDate>Thu, 05 Jan 2023 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/passcode-bypass-on-talk-android-app/</guid>
      <description>It is possible to bypass the passcode protection in nextcloud android talk by clicking the notification of a message. Proof of Concept: # Create two users Using User A login it to the web interface while User B on Talk App Android Using User B setup the passcode protection in settings Using User A send a message to User B Wait for the notification and click it References # https://hackerone.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/passcode-bypass-on-talk-android-app/featured.png" />
    </item>
    
    <item>
      <title>File and Chat disclosure by calling the device while its in locked state</title>
      <link>https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/</link>
      <pubDate>Wed, 09 Mar 2022 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/</guid>
      <description>Talk app allows access to sensitive chat messages on lockscreen during a call Summary # An attacker with physical access can gain access to the chat messages and files of the user by calling the victim phone while its in locked state.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/file-and-chat-disclosure-by-calling-the-device-while-its-in-locked-state/featured.png" />
    </item>
    
    <item>
      <title>Nextcloud Talk ObjectId in share location can be set to open arbitrary URL or Deeplinks</title>
      <link>https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/</link>
      <pubDate>Tue, 08 Mar 2022 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/</guid>
      <description>It is possible to control the geolocation preview in the Nextcloud Talk app to point to a domain or deeplink which results to open-redirect. Summary # The nextcloud Talk app allows a User to share their location via app.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/nextcloud-talk-objectid-in-share-location-can-be-set-to-open-arbitrary-url-or-deeplinks/featured.png" />
    </item>
    
    <item>
      <title>Sophos Secure Workspace App Password Bypass using Race Condition</title>
      <link>https://ctulhu.me/security/sophos-secure-workspace-app-password-bypass-using-race-condition/</link>
      <pubDate>Sat, 30 Oct 2021 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/sophos-secure-workspace-app-password-bypass-using-race-condition/</guid>
      <description>A race condition in Sophos Secure Workspace (Android) version 9.7.3081 that bypassed the App Password. An Activity is an application component that provides a UI for users to interact with.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/sophos-secure-workspace-app-password-bypass-using-race-condition/featured.png" />
    </item>
    
    <item>
      <title>Breaking the Doors: Paypal 2-Factor Bypass</title>
      <link>https://ctulhu.me/security/breaking-the-doors-paypal-2-factor-bypass/</link>
      <pubDate>Wed, 02 Dec 2020 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/breaking-the-doors-paypal-2-factor-bypass/</guid>
      <description>Two-Factor Authentication bypass on Paypal Hi! It’s been a while since my last write up. I hope you’ll like this one. Take care and be safe!
Two-factor authentication is an extra layer of security for your Paypal Account designed to ensure that you’re the only person who can access your account, even if someone knows your password.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/breaking-the-doors-paypal-2-factor-bypass/featured.png" />
    </item>
    
    <item>
      <title>Non-Verified User can Submit Report,View Disclosed Reports | Secuna bug bounty</title>
      <link>https://ctulhu.me/security/non-verified-user-can-submit-reportview-disclosed-reports-secuna-bug-bounty/</link>
      <pubDate>Thu, 13 Feb 2020 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/non-verified-user-can-submit-reportview-disclosed-reports-secuna-bug-bounty/</guid>
      <description>I was able to find a bug that lets me submit report,edit profile and view disclosed reports in secuna while using a rejected or non-verified account. Details # Currently i have 2 accounts at secuna.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/non-verified-user-can-submit-reportview-disclosed-reports-secuna-bug-bounty/featured.png" />
    </item>
    
    <item>
      <title>Insufficient Rate Limitting on Facebook Fundraisers</title>
      <link>https://ctulhu.me/security/insufficient-rate-limitting-on-facebook-fundraisers/</link>
      <pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate>
      
      <guid>https://ctulhu.me/security/insufficient-rate-limitting-on-facebook-fundraisers/</guid>
      <description>Facebook Fundraisers Lacks Rate Limiting Protection. Malicious actors can bruteforce this by sending different random credit or debit card numbers. Summary
Facebook Fundraisers Lacks Rate Limiting Protection. Malicious actors can bruteforce this by sending different random credit or debit card numbers.</description>
      <media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://ctulhu.me/security/insufficient-rate-limitting-on-facebook-fundraisers/featured.png" />
    </item>
    
  </channel>
</rss>
