4886 | File Disclosure via .DS_Store file (macOS) |
Directory listing |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-01-23 | 2023-06-13 |
4875 | Getting access to prompt debug dialog and serialized tool on main website facebook.com |
Information disclosure
Debug mode enabled |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-01-31 | 2023-06-13 |
4873 | Internal IPs disclosure |
Information disclosure |
Nokia |
Omar Espino (@omespino) |
Bug Bounty | 2018-02-02 | 2023-06-13 |
4852 | POODLE SSLv3 bug on multiple twitter smtp servers |
Cryptographic issues |
Twitter |
Omar Espino (@omespino) |
Bug Bounty | 2018-02-21 | 2023-06-13 |
4692 | WRITE UP – TELEGRAM BUG BOUNTY – WHATSAPP N/A [“Blind” XSS Stored iOS in messengers twins, who really care about your security?] |
Blind XSS |
Meta / Facebook |
Omar Espino (@omespino) |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4605 | Write-up - Love story, from closed as informative to $3,500 USD, XSS stored in Yahoo! iOS MaiL app |
Stored XSS |
Yahoo! / Verizon Media |
Omar Espino (@omespino) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4251 | Write up – $1,000 usd in 5 minutes, xss stored in outlook.com (ios browsers) |
Stored XSS |
Microsoft |
Omar Espino (@omespino) |
Bug Bounty | 2019-03-14 | 2023-06-13 |
4145 | WRITE UP – GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS in “springboard.google.com” – $13,337 USD |
LFI |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2019-05-21 | 2023-06-13 |
3952 | Private bug bounty $$,$$$ USD: “RCE as root on Marathon-Mesos instance” |
RCE |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2019-08-27 | 2023-06-13 |
3124 | Write Up – Google Bug Bounty: XSS To Cloud Shell Instance Takeover (Rce As Root) – $5,000 USD |
XSS
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
2957 | Write Up: Google VRP N/A – Sandboxed Rce As Root On Apigee API Proxies |
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-12-19 | 2023-06-13 |
2730 | Write Up – Google VRP N/A: SSRF Bypass With Quadzero In Google Cloud Monitoring |
SSRF |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-03-08 | 2023-06-13 |
2147 | Write Up – Google VRP N/A: Arbitrary Local File Read (Macos) Via <a> Tag And Null Byte (%00) In Google Earth Pro Desktop App |
Local File Read |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-10-14 | 2023-06-13 |
2114 | Write Up – XSS Stored In api.media.atlassian.com Via Doc File (iOS) |
Stored XSS |
Atlassian |
Omar Espino (@omespino) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2088 | Write Up – Google VRP Bug Bounty: /etc/environment Local Variables Exfiltrated On Linux Google Earth Pro Desktop App – $1,337 USD |
XSS |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2069 | Write Up – Apple N/A: PII Information, Full Contact List, Main Phone No. And Main Icloud Email Extracted; Bug Patched: Arbitrary Local File Read Via Zip File And Symlinks On Ios Files App. |
Arbitrary file read |
Apple |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2027 | Write Up – XSS Stored In files.slack.com Via XML/SVG File (iOS) – $1,000 USD |
XSS |
Slack |
Omar Espino (@omespino) |
Bug Bounty | 2021-12-03 | 2023-06-13 |
1912 | Write Up – Private Bug Bounty: Firebase Database Exposed By Misconfiguration – $2,000 USD |
Android
Insecure Firebase database |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-01-17 | 2023-06-13 |
1853 | Write Up – Private Bug Bounty: RCE In EC2 Instance Via SSH With Private Key Exposed On Public Github Repository – $xx,000 USD |
Information disclosure |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-03 | 2023-06-13 |
1789 | Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing |
Android
Bruteforce
Authentication bypass |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-22 | 2023-06-13 |
1674 | Write Up – Finapi (Open Banking API) Oauth Credentials Exposed In Plain Text In Android App |
Hardcoded credentials
Android |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-04-01 | 2023-06-13 |