writeups.xyz writeups.xyz / Sarmad Hassan (@JubaBaghdad)

Title Vulnerabilities Programs Authors
Add comment on a private Oculus Developer support
Break saved option for other users in facebook – From N/A to valid bug
Disclose Instagram Personal Private Archived posts when switching to Professional account through creative hub
Disclose latest stream video asset earnings for any gaming streamer page
Disclose private mockups for other users in facebook Creative Hub
How I found a simple bug in Facebook events without any Test
Persistent Distorted Posts Issue and Unremovable Content in Facebook Group
Send messages through notification to facebook & workplace users without getting blocked
Sign up for Brand Collabs Manager on behalf of other page admins – Privilege Escalation
How I found RXSS in Facebook, Twitter and Google training academy
Unauthorized Disclosure of Video Thumbnails in Facebook Workplace
Adding Descriptions to Instagram Posts on Behalf of Other Users
Disclose private attachments in Facebook Messenger Infrastructure
Disclose private attachments in Facebook Messenger Infrastructure - 15,000$
How I found a simple bug in Facebook without any Test
Add comment on a private Oculus Developer bug report
Add description to Instagram Posts on behalf of other users - 6500$
Make any Unit in Facebook Groups Undeletable
Distorted and Undeletable Posts in Facebook Group
Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups
Disclose Private Video Thumbnail from Facebook WorkPlace
How I was able to delete any image in Facebook community question forum