5189 | Uber Bug Bounty: Turning Self-XSS into Good-XSS |
XSS |
Uber |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-03-22 | 2023-06-13 |
5145 | Turning Self-XSS into Good XSS v2: Challenge Completed but Not Rewarded |
XSS |
Uber |
- |
Bug Bounty | 2016-08-29 | 2023-06-13 |
5092 | Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities |
XSS
CSP bypass |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-08 | 2023-06-13 |
4789 | Turning Self-XSS into non-Self Stored-XSS via Authorization Issue at “PayPal Tech-Support and Brand Central Portal |
Stored XSS |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-21 | 2023-06-13 |
4367 | Turning Self XSS to good XSS via access control |
Stored XSS
Self-XSS |
NA |
Yusuf Yazir (@Hacklad) |
Bug Bounty | 2019-01-13 | 2023-06-13 |
4230 | How I was able to turn self xss into reflected xss |
Reflected XSS |
NA |
Hein Thant Zin (@H3Lowr) |
Bug Bounty | 2019-03-31 | 2023-06-13 |
3892 | How a double-free bug in WhatsApp turns to RCE |
Memory corruption
RCE
Android |
Meta / Facebook |
Awakened |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3803 | How I turned Self XSS to Stored via CSRF |
Self-XSS
CSRF |
NA |
Abhishek Yadav (@abhishake100) |
Bug Bounty | 2019-11-29 | 2023-06-13 |
3559 | How a Simple CSRF Attack Turned into a P1 Level Bug |
CSRF
Account takeover |
NA |
Lady Secspeare (@bejuveria_) |
Bug Bounty | 2020-04-05 | 2023-06-13 |
3558 | How we abused Slack%27s TURN servers to gain access to internal services |
SSRF |
Slack |
Sandro Gauci (@sandrogauci) |
Bug Bounty | 2020-04-06 | 2023-06-13 |
3432 | How I leveraged an interesting CSRF vulnerability to turn self XSS into a persistent attack? |
Self-XSS
CSRF |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2020-06-01 | 2023-06-13 |
3012 | Turning Blind Error Based SQL Injection into Exploitable Boolean One |
SQL injection |
NA |
Ozgur Alp (@ozgur_bbh) |
Bug Bounty | 2020-11-21 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2713 | An unknown Linux secret that turned SSRF to OS Command injection |
SSRF
Command injection |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-03-17 | 2023-06-13 |
2567 | Simple logical Bug turned into a bounty |
Logic flaw |
Meta / Facebook |
Sndp Giri |
Bug Bounty | 2021-05-10 | 2023-06-13 |
2535 | How I turned 0000 into $600: Phone Verification Bypass |
OTP bypass |
NA |
Shrirang Diwakar |
Bug Bounty | 2021-05-21 | 2023-06-13 |
2528 | Chaining XSS with authentication issues to turn it into full account takeover |
XSS
Account takeover |
NA |
N1GHTMAR3 (@n1ghtmar3_2421) |
Bug Bounty | 2021-05-24 | 2023-06-13 |
2427 | CVE-2021-22555: Turning x00x00 into 10000$ |
Memory corruption
Local Privilege Escalation |
Google |
Andy Nguyen (@theflow0) |
Bug Bounty | 2021-07-07 | 2023-06-13 |
1971 | Turning bad SSRF to good SSRF: Websphere Portal |
SSRF |
HCL Technologies |
Shubham Shah (@infosec_au) |
Bug Bounty | 2021-12-26 | 2023-06-13 |
1670 | How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables |
Memory corruption
Local Privilege Escalation |
Linux Kernel Organization |
David Bouman (@pqlqpql) |
Bug Bounty | 2022-04-02 | 2023-06-13 |
1654 | The Bug That Kept On Giving :: PaymentBypass :: Eposed Return Url |
Payment bypass
Logic flaw |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1623 | Multiple Vulnerabilities in Cisco Expressway |
Memory leak
Exposed administrative interface
STUN
TURN |
Cisco |
Christian Mehlmauer (@firefart) |
Bug Bounty | 2022-04-14 | 2023-06-13 |
1124 | Turning cookie based XSS into account takeover |
XSS
Account takeover |
Terrahost |
Bartłomiej Bergier (@_bergee_) |
Bug Bounty | 2022-09-06 | 2023-06-13 |
1121 | How to turn security research into profit: a CL.0 case study |
HTTP request smuggling
Desync attack |
NA |
James Kettle (@albinowax) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1068 | Turning Your Computer Into a GPS Tracker With Apple Maps |
Privacy issue
Information disclosure |
Apple |
Ron Masas (@RonMasas) |
Bug Bounty | 2022-09-18 | 2023-06-13 |