5287 | My Experience with the PayPal Bug Bounty Programme |
CSRF |
Paypal |
Jack Whitton (@fin1te) |
Bug Bounty | 2012-10-12 | 2023-06-13 |
5285 | Persistent XSS on myworld.ebay.com |
XSS |
Ebay |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-01-27 | 2023-06-13 |
5284 | Framing, Part 1: Click-Jacking Etsy |
Clickjacking |
Etsy |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-02-05 | 2023-06-13 |
5281 | Stealing Facebook Access Tokens with a Double Submit |
CSRF
OAuth |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-04-13 | 2023-06-13 |
5279 | Overwriting Banner Images on Etsy |
Authorization flaw |
Etsy |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-05-21 | 2023-06-13 |
5278 | Hijacking a Facebook Account with SMS |
Authorization flaw
Account takeover |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-06-26 | 2023-06-13 |
5271 | Removing Covers Images on Friendship Pages, on Facebook |
Authorization flaw |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-09-25 | 2023-06-13 |
5268 | Content Types and XSS: Facebook Studio |
XSS |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-10-21 | 2023-06-13 |
5264 | Instagram%27s One-Click Privacy Switch |
CSRF |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-10-31 | 2023-06-13 |
5260 | Abusing CORS for an XSS on Flickr |
XSS |
Flickr |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-12-12 | 2023-06-13 |
5215 | Bypassing Google Authentication on Periscope%27s Administration Panel |
Authentication bypass |
Google |
Jack Whitton (@fin1te) |
Bug Bounty | 2015-07-20 | 2023-06-13 |
5198 | An XSS on Facebook via PNGs & Wonky Content Types |
XSS |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-01-27 | 2023-06-13 |
5189 | Uber Bug Bounty: Turning Self-XSS into Good-XSS |
XSS |
Uber |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-03-22 | 2023-06-13 |
5186 | Obtaining Login Tokens for an Outlook, Office or Azure Account |
CSRF |
Microsoft |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-04-03 | 2023-06-13 |
5153 | Messenger.com Site-Wide CSRF |
CSRF |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2016-07-26 | 2023-06-13 |