5195 | A Hilarious ESET Broken Authentication Vulnerability (one click free purchase) |
Authentication flaw
SQL injection |
ESET |
Mohamed A. Baset |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5136 | Vine Re-auth Bypass [Twitter Bug Bounty] |
Authentication flaw |
Twitter |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-09-21 | 2023-06-13 |
5003 | Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] |
Authentication flaw
Account takeover |
Yahoo! / Verizon Media |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-08-15 | 2023-06-13 |
4866 | Bug bounty left over (and rant) Part III (Google and Twitter) |
OAuth
Authentication flaw
Information disclosure |
Google
Twitter |
Antonio Sanso (@asanso) |
Bug Bounty | 2018-02-06 | 2023-06-13 |
4502 | Bypass HackerOne 2FA requirement and reporter blacklist |
Logic flaw
MFA bypass
Authentication flaw |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2018-10-31 | 2023-06-13 |
4341 | How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc) |
Logic flaw
Authentication flaw |
Google
Microsoft
Meta / Facebook |
Luke Berner |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4285 | Swiss_E-Voting_Publications |
XSS
XXE
RCE
Missing authentication
Authentication flaw
Hardcoded credentials |
Swiss E-Voting |
setuid0 (@_setuid0_) |
Bug Bounty | 2019-02-21 | 2023-06-13 |
4133 | How did I bypass a Custom Brute Force protection and why that solution is not a good idea? |
Bruteforce
Authentication flaw |
NA |
dortz |
Bug Bounty | 2019-05-25 | 2023-06-13 |
3871 | [ BUG BOUNTY ] Flaw in Authentication ( Hall of Fame Google ) |
Authentication flaw |
Google |
Danang Tri Atmaja (@danangtriatmj) |
Bug Bounty | 2019-10-21 | 2023-06-13 |
3473 | How Netgear meshed(*) up WiFi for Business |
Weak crypto
Authentication flaw |
Netgear |
Thorsten Schröder |
Bug Bounty | 2020-05-18 | 2023-06-13 |
3193 | Account Takeover For The Win 🏆 |
Account takeover
Authentication flaw
Password reset |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-08-24 | 2023-06-13 |
3144 | How I earned $500 from Google - Flaw in Authentication |
Authentication flaw |
Google |
Hemant Patidar (@HemantSolo) |
Bug Bounty | 2020-09-20 | 2023-06-13 |
3059 | CVE-2020-13294 |
Authentication flaw
OpenID Connect
OAuth |
GitLab |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2020-11-01 | 2023-06-13 |
2861 | Weird functionality leads to Account Takeover (Millions of Users affected) |
Account takeover
Authentication flaw |
NA |
Sahil Mehra (@nullr3x) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2839 | Microsoft Remote Desktop Web Access Authentication Timing Attack |
Timing attack
Authentication flaw |
Microsoft |
Matt Dunn |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2828 | Duplicate Registration - The Twinning Twins |
Account takeover
Authentication flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2766 | Account Takeover - Smoking with null’ |
Account takeover
Authentication flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-02-26 | 2023-06-13 |
2653 | Auth Issues |
Authentication flaw
Logic flaw |
Google |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2021-04-09 | 2023-06-13 |
2499 | Shopify Multipass Misconfiguration |
Authentication flaw
Logic flaw |
NA |
Ahmed A. Sherif |
Bug Bounty | 2021-06-05 | 2023-06-13 |
2489 | Bypassing 2FA using OpenID Misconfiguration |
MFA bypass
Authentication flaw |
NA |
Youstin (@iustinBB) |
Bug Bounty | 2021-06-11 | 2023-06-13 |
2119 | Agent 007: Pre-Auth Takeover of Build Pipelines in GoCD |
Broken authentication
Authentication flaw |
GoCD |
Sonar (@SonarSource) |
Bug Bounty | 2021-10-27 | 2023-06-13 |
2075 | Full account takeover through referral code. |
Authentication flaw
Account takeover |
Shipt |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2064 | How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud |
Information disclosure
Authentication flaw |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
1990 | Flickr Account Takeover |
Account takeover
Authentication flaw |
Flickr |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2021-12-18 | 2023-06-13 |
1696 | Bug Bounty Adventures: A NodeBB 0-day |
CSRF
Account takeover
SSO
Authentication flaw |
Opera |
Marouane Mouhtadi (@Mar0_0uane) |
Bug Bounty | 2022-03-25 | 2023-06-13 |