Open in app

Sign in

Write

Sign in

Lokesh Kumar
Lokesh Kumar

1.1K followers

Home

About

Facebook SMS Captcha Was Vulnerable to CSRF Attack

This post is about an bug that I found on Meta (aka Facebook) which allows to make any Endpoint as POST request in SMS Captcha flow which…

Oct 17, 2022
2
Facebook SMS Captcha Was Vulnerable to CSRF Attack
Facebook SMS Captcha Was Vulnerable to CSRF Attack
Oct 17, 2022
2

Contact Point Deanonymization Vulnerability in Meta

This post is about an bug that I found on Meta (aka Facebook) which used to find a linked Primary email address of a account using mobile…

Apr 28, 2022
2
Contact Point Deanonymization Vulnerability in Meta
Contact Point Deanonymization Vulnerability in Meta
Apr 28, 2022
2

Confirming any new Email Address bug in Facebook (Part-4)

This post is about an bug that I found on Facebook which used to Confirming any email address in new Facebook account by using IP and…

Aug 17, 2021
1
Confirming any new Email Address bug in Facebook (Part-4)
Confirming any new Email Address bug in Facebook (Part-4)
Aug 17, 2021
1

How to Rotate IP ADDRESS For Each Request in Burp Suite

This post is about to explain how to rotate IP address for each request using Burp Suite.

Aug 17, 2021
2
How to Rotate IP ADDRESS For Each Request in Burp Suite
How to Rotate IP ADDRESS For Each Request in Burp Suite
Aug 17, 2021
2

Delete Any Photos In Facebook

This post is about an bug that I found on Facebook which used to delete any publicly visible photos by editing the series feature

Nov 3, 2020
1
Delete Any Photos In Facebook
Delete Any Photos In Facebook
Nov 3, 2020
1

Reveal the page admin that uploaded a video on the page in comment section

This post is about an bug that I found on Facebook which used to disclose the page role person’s User ID when posted a video on comment…

Nov 2, 2020
Reveal the page admin that uploaded a video on the page in comment section
Reveal the page admin that uploaded a video on the page in comment section
Nov 2, 2020

Disable Any Unconfirmed Account in Facebook

This post is about an bug that i found on Facebook which used to Disable any new unconfirmed account in Facebook by using IP Rotation…

Nov 21, 2019
1
Disable Any Unconfirmed Account in Facebook
Disable Any Unconfirmed Account in Facebook
Nov 21, 2019
1

CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook

This post is about an bug that i found on Facebook which used to verify any new Gmail and G-Suite account with minimal Victim’s…

Jul 16, 2019
1
CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook
CSRF Email Confirmation Vulnerability for Gmail & G-Suite in Facebook
Jul 16, 2019
1

Bypass OAuth nonce and steal oculus response code

This post is about an bug that i found on Facebook Oculus Application OAuth which could have been used to bypass nonce and steal…

Nov 7, 2017
1
Bypass OAuth nonce and steal oculus response code
Bypass OAuth nonce and steal oculus response code
Nov 7, 2017
1

Stealing Facebook MailChimp Application OAuth 2.0 Access Token

This post is about an bug that i found on Facebook MailChimp Application OAuth 2.0 which could have been used to steal Access_token. and…

Nov 7, 2017
1
Nov 7, 2017
1
Lokesh Kumar

Lokesh Kumar

1.1K followers

Web Security Researcher

Following
  • Cyber Security Write-ups

    Cyber Security Write-ups

  • h4x0r_dz

    h4x0r_dz

  • Samm0uda

    Samm0uda

  • Shahmeer Amir

    Shahmeer Amir

See all (41)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech