Reports/Writeups
- #226191 Android MailRu Email: Thirdparty can access private data files with small user interaction
- #258460 [Quora Android] Possible to steal arbitrary files from mobile device
- #283063 [IRCCloud Android] XSS in ImageViewerActivity
- #202425 Two-factor authentication bypass on Grab Android App
- #272044 Android - Access of some not exported content providers
- #328486 [Zomato Android/iOS] Theft of user session
- #288955 [IRCCloud Android] Theft of arbitrary files leading to token leakage
- #200427 Access of Android protected components via embedded intent
- #176065 [Android] HTML Injection in BatterySaveArticleRenderer WebView
- #289000 Vulnerable exported broadcast receiver
- #431002 Golden techniques to bypass host validations in Android apps
- #221558 Private Grab Messages on Android App can be accessed and cached by Search Engines
- #351555 Disclosure of all uploads to Cloudinary via hardcoded api secret in Android app
- #161710 Possible to steal any protected files on Android
- #189793 [Android] XSS via start ContentActivity
- #283058 [IRCCloud Android] Opening arbitrary URLs/XSS in SAMLAuthActivity
- #185862 Twitter for android is exposing user’s location to any installed android app
- #5314 Coinbase Android Application - Bitcoin Wallet Leaks OAuth Response Code
- #167481 Android - Possible to intercept broadcasts about uploaded files
- #97295 Multiple critical vulnerabilities in Odnoklassniki Android application
- #284346 Download attachments with traversal path into any sdcard directory (incomplete fix 106097)
'버그헌팅 > 방법론' 카테고리의 다른 글
Recon 테스트 (0) | 2019.12.12 |
---|---|
OAuth 버그바운티 (0) | 2019.09.23 |
JD-GUI 팁 (0) | 2019.04.03 |
URL SCHEME 버그바운티 (0) | 2019.03.26 |
안드로이드 정적분석 버그헌팅 검색어 모음 (0) | 2019.03.19 |