5278 | Hijacking a Facebook Account with SMS |
Authorization flaw
Account takeover |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-06-26 | 2023-06-13 |
5269 | Facebook CSRF leading to full account takeover (fixed) |
CSRF
Account takeover |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-10-18 | 2023-06-13 |
5255 | How I hacked Github again. |
Open redirect
Account takeover
Information disclosure |
GitHub |
Egor Homakov (@homakov) |
Bug Bounty | 2014-02-07 | 2023-06-13 |
5164 | Medium Full Account Takeover By One Click |
XSS |
Medium |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-06-23 | 2023-06-13 |
5162 | TopCoder.com Vulnerabilities – A tail of site-wide bugs leads to accounts compromise & payments hijacking |
CSRF
Account takeover |
Topcoder.com |
Mohamed A. Baset |
Bug Bounty | 2016-06-28 | 2023-06-13 |
5138 | Bug Bounty : Account Takeover Vulnerability POC |
OAuth
Account takeover
XSS |
NA |
Rakesh Mane (@RakeshMane10) |
Bug Bounty | 2016-09-16 | 2023-06-13 |
5112 | How I could have compromised any account on one of the biggest startup based in California |
Account takeover
IDOR
Password reset |
NA |
Prateek Tiwari (@prateek_0490) |
Bug Bounty | 2017-01-28 | 2023-06-13 |
5096 | One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. |
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-02-25 | 2023-06-13 |
5060 | Let’s steal some tokens! |
CSRF
XSS
Account takeover |
Google
Shopify |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2017-06-11 | 2023-06-13 |
5036 | Fabric.io API permission apocalypse – Privilege Escalations |
Authorization flaw
Account takeover |
Twitter |
WeSecureApp (@wesecureapp) |
Bug Bounty | 2017-07-10 | 2023-06-13 |
5035 | Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information |
IDOR
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-07-13 | 2023-06-13 |
5003 | Password Not Provided - Compromising Any Flurry User%27s Account [Yahoo Bug Bounty] |
Authentication flaw
Account takeover |
Yahoo! / Verizon Media |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-08-15 | 2023-06-13 |
4932 | JWT Refresh Token Manipulation |
JWT
Authentication bypass
Account takeover |
NA |
Mikail Tunç (@emtunc) |
Bug Bounty | 2017-11-16 | 2023-06-13 |
4914 | Don%27t Trust the Host Header for Sending Password Reset Emails |
Password reset
Account takeover |
Mavenlink |
Jack Cable (@jackhcable) |
Bug Bounty | 2017-12-13 | 2023-06-13 |
4909 | Account Takeover Due to Misconfigured Login with Facebook/Google |
Account takeover
Authorization flaw |
Google
Meta / Facebook |
Bhavuk Jain (@bhavukjain1) |
Bug Bounty | 2017-12-20 | 2023-06-13 |
4880 | Full Account Takeover through CORS with connection Sockets |
CORS misconfiguration
Account takeover |
NA |
Samuel (@saamux) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4864 | I figured out a way to hack any of Facebook’s 2 billion accounts, and they paid me a $15,000 bounty for it |
Bruteforce
Account takeover |
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-09 | 2023-06-13 |
4854 | How I hacked Tinder accounts using Facebook’s Account Kit and earned $6,250 in bounties |
Account takeover
Authorization flaw |
Tinder
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-20 | 2023-06-13 |
4835 | #BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality |
Logic flaw
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4820 | My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) |
SQL injection
Authentication bypass
Account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2018-04-01 | 2023-06-13 |
4808 | Please email me your password |
Blind XSS
Blind SQL injection
SMTP injection
Account takeover |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-04-11 | 2023-06-13 |
4792 | Bypassing the Current Password Protection at PayPal TechSupport Portal |
Authorization flaw
Account takeover |
Paypal |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2018-04-19 | 2023-06-13 |
4763 | How i HACKED admin account via password reset IDOR function of one private currency exchanger site |
IDOR
Account takeover
Password reset |
NA |
Aayush Pokhrel (@aayushpok) |
Bug Bounty | 2018-05-19 | 2023-06-13 |
4755 | #BugBounty — "How I was able to hack any user account via password reset?" |
IDOR
Account takeover
Password reset |
NA |
Bikash Gupta (@BgxDoc) |
Bug Bounty | 2018-05-23 | 2023-06-13 |
4748 | Account Takeover and Blind XSS! Go Pro, get Bugs! |
IDOR
Stored XSS
Account takeover
Blind XSS |
NA |
Tabahi (@_tabahi) |
Bug Bounty | 2018-05-30 | 2023-06-13 |