5234 | Google Bug Bounty: Nice Catch on Google Cloud Platform Live |
Reflected XSS |
Google |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2014-11-20 | 2023-06-13 |
5206 | Cloudflare WAF XSS |
XSS |
Cloudflare |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2015-11-16 | 2023-06-13 |
5118 | The Orphaned Internet – Taking Over 120K Domains via a DNS Vulnerability in AWS, Google Cloud, Rackspace and Digital Ocean |
Domain takeover |
Google
Amazon
Rackspace
DigitalOcean |
Matthew Bryant (@IAmMandatory) |
Bug Bounty | 2016-12-05 | 2023-06-13 |
4963 | Subdomain Takeover Through Expired Cloudfront Distribution | live.lamborghini.co |
Subdomain takeover |
Lamborghini |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2017-10-10 | 2023-06-13 |
4707 | Unauthenticated Command Injection Vulnerability in VMware NSX SD-WAN by VeloCloud |
OS command injection
RCE |
VMware |
Brian Sullivan |
Bug Bounty | 2018-06-29 | 2023-06-13 |
4673 | How I found XSS on Amazon? |
XSS |
Amazon (CloudFront) |
Coding_Karma (@karma_coded) |
Bug Bounty | 2018-07-26 | 2023-06-13 |
4644 | Practical Web Cache Poisoning |
Web cache poisoning |
Mozilla
HubSpot
Cloudflare
Binary.com
Amazon (CloudFront) |
James Kettle (@albinowax) |
Bug Bounty | 2018-08-09 | 2023-06-13 |
4545 | Bypassing Web Cache Poisoning Countermeasures |
Web cache poisoning |
Cloudflare |
James Kettle (@albinowax) |
Bug Bounty | 2018-10-05 | 2023-06-13 |
4480 | [DOM based XSS] Or why you should not rely on Cloudflare too much |
DOM XSS |
NA |
KatsuragiCSL (@ZuuitterE) |
Bug Bounty | 2018-11-13 | 2023-06-13 |
4421 | How i was able to pwned application by Bypassing Cloudflare WAF |
WAF bypass |
NA |
gujjuboy10x00 (@vis_hacker) |
Bug Bounty | 2018-12-12 | 2023-06-13 |
4341 | How I abused 2FA to maintain persistence after a password change (Google, Microsoft, Instagram, Cloudflare, etc) |
Logic flaw
Authentication flaw |
Google
Microsoft
Meta / Facebook |
Luke Berner |
Bug Bounty | 2019-01-25 | 2023-06-13 |
4329 | $7.5k Google Cloud Platform organization issue |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2019-01-30 | 2023-06-13 |
4183 | Getting access to Zendesk’s Google Cloud and Artifactory from GitHub dotfile repos |
Information disclosure |
Zendesk |
Ruby Nealon (@_ruby) |
Bug Bounty | 2019-04-23 | 2023-06-13 |
4180 | The journey of Web Cache + Firewall Bypass to SSRF to AWS credentials compromise! |
LFI
SSRF
WAF bypass
Cloudflare bypass |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-04-25 | 2023-06-13 |
4160 | Subdomain takeover [Awarded $200] |
Subdomain takeover |
ownCloud |
Friendly (@SkeletorKeys) |
Bug Bounty | 2019-05-07 | 2023-06-13 |
3946 | Google Cloud Blog platform vulnerability |
XSS |
Google |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-09-01 | 2023-06-13 |
3869 | CPDoS: Cache Poisoned Denial of Service |
DoS
Web cache poisoning |
Microsoft
Amazon
Akamai
Cloudflare
Yahoo! / Verizon Media
Play Framework |
Hoai Viet Nguyen (@hvnguyen86) |
Bug Bounty | 2019-10-22 | 2023-06-13 |
3779 | 4 Google Cloud Shell bugs explained |
RCE |
Google |
wtm@offensi.com (@wtm_offensi) |
Bug Bounty | 2019-12-16 | 2023-06-13 |
3772 | [Google VRP] SSRF in Google Cloud Platform StackDriver |
SSRF |
Google |
Ron Chan (@ngalongc) |
Bug Bounty | 2019-12-19 | 2023-06-13 |
3750 | How I made $7500 from My First Bug Bounty Found on Google Cloud Platform |
Logic flaw |
Google |
James Grunewald |
Bug Bounty | 2019-12-29 | 2023-06-13 |
3725 | In Cloud we “Trust”: Wrong Kubernetes implementation by Google Cloud Platform & Microsoft Azure affecting customers |
Old components with known vulnerabilities |
Microsoft
Google |
Chen Cohen (@chencococococo) |
Bug Bounty | 2020-01-12 | 2023-06-13 |
3462 | RCE in Google Cloud Deployment Manager |
SSRF
RCE |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2020-05-21 | 2023-06-13 |
3424 | Privilege Escalation in Google Cloud Platform%27s OS Login |
Privilege escalation |
Google |
Chris Moberly (@init_string) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3422 | Three Privilege Escalation Bugs in Google Cloud Platform’s OS Login |
Local Privilege Escalation
Cloud |
Google |
initstring (@init_string) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3251 | Vulnerability in new TouchID feature put iCloud accounts at risk of being breached |
OAuth
Account takeover |
Apple |
Thijs Alkemade (@xnyhps) |
Bug Bounty | 2020-08-03 | 2023-06-13 |