4446 | IRCTC β Millions of Passenger Details left at huge risk! |
Information disclosure
Lack of rate limiting |
IRCTC |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-11-28 | 2023-06-13 |
4281 | Bug Bounty 101βββAlways Check The Source Code |
Lack of rate limiting
Information disclosure |
NA |
Spazzy |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4177 | [sidefx][Poc] user enumeration & no rate limeted in send message function |
Username enumeration
Lack of rate limiting |
SideFX |
Abdelhak Kharroubi |
Bug Bounty | 2019-04-26 | 2023-06-13 |
4034 | Facebook Informative Bug From Triaged |
Lack of rate limiting |
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
3994 | No Rate limiting eligible for bounty ? |
Lack of rate limiting |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2019-08-03 | 2023-06-13 |
3934 | Oculus identity verification bypass through brute-force |
OTP bypass
Lack of rate limiting |
Meta / Facebook |
karthik kumar reddy (@karthiksunny007) |
Bug Bounty | 2019-09-09 | 2023-06-13 |
3846 | BugBounty: How I Cracked 2FA (Two-Factor Authentication) with Simple Factor Brute-force !!! π |
MFA bypass
Lack of rate limiting |
NA |
Akash Agrawal (@akashmagrawal) |
Bug Bounty | 2019-11-08 | 2023-06-13 |
3726 | No Rate Limit - 2K Bounty |
Lack of rate limiting |
Yahoo! / Verizon Media |
Shrey Shah (@ShreySh43332033) |
Bug Bounty | 2020-01-12 | 2023-06-13 |
3723 | How I discovered an interesting account takeover flaw? |
Account takeover
Password reset
Lack of rate limiting |
NA |
Akash Methani (@0xAkash) |
Bug Bounty | 2020-01-14 | 2023-06-13 |
3610 | How I got access to critical data of a Company in no time ? |
Information disclosure
Lack of rate limiting
Bruteforce |
NA |
Kaustubh Kale |
Bug Bounty | 2020-03-12 | 2023-06-13 |
3398 | Account Takeover via OTP Bruteforce (Apigee API) |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2020-06-13 | 2023-06-13 |
3385 | How I managed to Escalate privilege as admin |
Lack of rate limiting
Bruteforce
Weak credentials |
NA |
Abisheik Magesh (@AbisheikMagesh) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3375 | Bypass 2FA like a Boss |
Lack of rate limiting
Bruteforce |
NA |
Seqrity (@seQrity) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3298 | Android pin bypass with rate limiting |
Lack of rate limiting
Authentication bypass |
NA |
Baluz (@t3chman) |
Bug Bounty | 2020-07-18 | 2023-06-13 |
3293 | Chaining rate limiting for account lockout |
Lack of rate limiting |
NA |
Sandip Oli |
Bug Bounty | 2020-07-19 | 2023-06-13 |
3280 | How I bypassed 2fa in a 3 years old private program! |
MFA bypass
Bruteforce
Lack of rate limiting |
NA |
Shivangx01b (@shivangx01b) |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3267 | Zoom Security Exploit β Cracking private meeting passwords |
CSRF
Lack of rate limiting |
Zoom |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3132 | Chains on Chains: Chaining multiple low-level vulns into a Critical. |
Blind XSS
CSP bypass
Lack of rate limiting
Exposed JWT generation endpoint
JWT |
NA |
Daniel Marte (@Masonhck3571) |
Bug Bounty | 2020-09-26 | 2023-06-13 |
3131 | 5 Ways to do Account Takeover in a Single Website |
Account takeover
Lack of rate limiting
OTP bypass
IDOR
OAuth
JWT |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3072 | Story of an interesting bug. |
Lack of rate limiting
DoS |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-10-28 | 2023-06-13 |
2995 | Chaining vulnerabilities lead to account takeover |
Account takeover
Password reset
Open redirect
Lack of rate limiting |
NA |
Ahmed (@ahzsec) |
Bug Bounty | 2020-12-01 | 2023-06-13 |
2922 | Finding bugs on Chess.com |
Lack of rate limiting
Bruteforce
CSRF |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2866 | BMW Bug Bounty β Account Verification Bypass writeup |
OTP bypass
Bruteforce
Lack of rate limiting |
BMW |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-01-26 | 2023-06-13 |