Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5281Stealing Facebook Access Tokens with a Double Submit CSRF OAuth Meta / Facebook Jack Whitton (@fin1te) Bug Bounty2013-04-132023-06-13
5254How I was able to track the location of any Tinder user. Information disclosure Tinder Max Veytsman (@mveytsman) Bug Bounty2014-02-192023-06-13
5217[Responsible disclosure] How I could have hacked 62.5 million Zomato Users IDOR Zomato Anand Prakash (@anandpraka_sh) Bug Bounty2015-06-042023-06-13
5179Facebook movies recommendation vulnerability – A bug capable of erasing all your important notifications! Logic flaw DoS Meta / Facebook Mohamed A. Baset Bug Bounty2016-05-052023-06-13
5169RunKeeper Stored XSS Vulnerability – Where worms are able to run too! Stored XSS CSRF RunKeeper Mohamed A. Baset Bug Bounty2016-06-062023-06-13
5141Internet Explorer has a URL problem OAuth RPO XSS GitHub Google File Descriptor (@filedescriptor) Bug Bounty2016-09-062023-06-13
5100How I was able to remove your Instagram Phone number Bruteforce Meta / Facebook Neeraj Sonaniya (@neeraj_sonaniya) Bug Bounty2017-02-202023-06-13
5035Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information IDOR Account takeover NA Zseano (@zseano) Bug Bounty2017-07-132023-06-13
5023How i was able to bypass strong xss protection in well known website. (imgur.com) XSS Imgur Armaan Pathan (@armaancrockroax) Bug Bounty2017-07-212023-06-13
5012Business Logic Vulnerabilities Series: How I became invisible and immune to blocking on Instagram! Logic flaw Meta / Facebook Ali Kabeel Bug Bounty2017-07-312023-06-13
5003Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] Authentication flaw Account takeover Yahoo! / Verizon Media Jack Cable (@jackhcable) Bug Bounty2017-08-152023-06-13
4965How I Was Able To View Private Tweets Of Any Private Twitter Account IDOR Twitter Cj Legacion (@LegacionCj) Bug Bounty2017-10-062023-06-13
4959How I was Able to see someone’s all private files with a single file share link through Atom feed & Never Give Up #togetherwehitharder HackerOne Information disclosure NA Yogendra Jaiswal (@vulnh0lic) Bug Bounty2017-10-132023-06-13
4949App Maker and Colaboratory: a stored Google XSS double-bill Stored XSS Google Yasin Soliman (@SecurityYasin) Bug Bounty2017-11-012023-06-13
4918How I Was Able To See The Bounty Balance Of Any Bug Bounty Program In HackerOne Logic flaw HackerOne Cj Legacion (@LegacionCj) Bug Bounty2017-12-062023-06-13
4915How I was able to takeover Facebook account Authentication bypass Meta / Facebook Ameer Hamza Bug Bounty2017-12-102023-06-13
4914Don%27t Trust the Host Header for Sending Password Reset Emails Password reset Account takeover Mavenlink Jack Cable (@jackhcable) Bug Bounty2017-12-132023-06-13
4898#BugBounty — How I was able to read chat of users in an Online travel portal IDOR NA Avinash Jain (@logicbomb_1) Bug Bounty2018-01-102023-06-13
4896#BugBounty — How I was able to delete anyone’s account in an Online Car Rental Company CSRF Parameter tampering NA Avinash Jain (@logicbomb_1) Bug Bounty2018-01-142023-06-13
4884#BugBounty @ Linkedln-How I was able to bypass Open Redirection Protection Open redirect LinkedIn Avinash Jain (@logicbomb_1) Bug Bounty2018-01-242023-06-13
4883Reflected XSS + Possible Server Side Template Injection in HubSpot CMS ( All Websites Uses HubSpot was affected ) Reflected XSS HubSpot Mohamed Haron (@m7mdharon) Bug Bounty2018-01-242023-06-13
4876How I was able to Download Any file from Web server! XSS IDOR NA hammadhassan924 Bug Bounty2018-01-272023-06-13
4875Getting access to prompt debug dialog and serialized tool on main website facebook.com Information disclosure Debug mode enabled Meta / Facebook Omar Espino (@omespino) Bug Bounty2018-01-312023-06-13
4874How I was able to Bypass XSS Protection on HackerOne’s Private Program XSS NA Jay Jani (@JayJani007) Bug Bounty2018-02-022023-06-13
4861#BugBounty — “How I was able to shop for free!”- Payment Price Manipulation Parameter tampering Payment tampering NA Avinash Jain (@logicbomb_1) Bug Bounty2018-02-112023-06-13