5013 | How i found massive information disclosure of 1500 famous people |
Information disclosure |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2017-07-31 | 2023-06-13 |
4940 | How to delete all company progress by one "rm" command in AWS s3 Buckets |
AWS misconfiguration |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2017-11-09 | 2023-06-13 |
4823 | How I hacked one cryptocurrency service |
Blind XSS
Reflected XSS
CSRF |
PayKassa |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2018-03-31 | 2023-06-13 |
4406 | Subdomain Takeover — New Level |
Subdomain takeover |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2018-12-17 | 2023-06-13 |
4200 | How I hacked Vending Machine |
Violation of secure design principles |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2019-04-15 | 2023-06-13 |
3981 | Two Easy RCE in Atlassian Products |
Credential stuffing |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3620 | Broke limited scope with a chain of bugs (tips for every rider CORS) |
CORS misconfiguration
RCE |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-03-09 | 2023-06-13 |
3426 | From CRLF to Account Takeover |
CRLF injection
HTTP response splitting
Reflected XSS
Account takeover |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2020-06-03 | 2023-06-13 |
2918 | $10,000 for a vulnerability that doesn’t exist |
Path traversal |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2411 | Credential stuffing in Bug bounty hunting |
Credential stuffing |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-07-14 | 2023-06-13 |
2064 | How I accidentally hacked many companies using N/A vulnerability in Atlassian Cloud |
Information disclosure
Authentication flaw |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
606 | Hacking Hackers for fun and profit |
Self-XSS
Blind XSS |
NA |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2023-01-09 | 2023-06-13 |