5023 | How i was able to bypass strong xss protection in well known website. (imgur.com) |
XSS |
Imgur |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-07-21 | 2023-06-13 |
5007 | Insecure Direct Object Reference In Facebook Events |
IDOR |
Meta / Facebook |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-11 | 2023-06-13 |
5006 | Chain the vulnerabilities and take your report impact on the moon (CSRF to HTML INJECTION which results OPEN REDIRECT and could steal USER CREDENTIALS) |
CSRF
HTML injection |
Legal Robot |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-12 | 2023-06-13 |
4990 | Don’t just alert(1) , Because XSS is for fun…!! |
XSS |
Optimizely |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-02 | 2023-06-13 |
4985 | Bypassing Facebook Profile Picture Guard Security. |
Authorization flaw |
Meta / Facebook |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-09 | 2023-06-13 |
4981 | Chaining Self XSS with UI Redressing is Leading to Session Hijacking (PWN users like a boss) |
Self-XSS
Clickjacking |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-09-18 | 2023-06-13 |
4580 | Chain The Bugs to Pwn an Organisation ( LFI + Unrestricted File Upload = Remote Code Execution ) |
LFI
Unrestricted file upload
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4388 | Abusing ACL Permissions to Overwrite other User’s Uploaded Files/Videos on s3 Bucket |
Unrestricted file upload
Authorization flaw |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2018-12-30 | 2023-06-13 |
4257 | Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack. |
CSRF
Bruteforce |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4217 | Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers |
MiTM |
PortSwigger |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-04-06 | 2023-06-13 |
4194 | PDFReacter SSRF to ROOT Level Local File Read which led to RCE |
SSRF
RCE |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-04-18 | 2023-06-13 |