5170 | InstaBrute: Two Ways to Brute-force Instagram Account Credentials |
Bruteforce
Username enumeration |
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-05-19 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5100 | How I was able to remove your Instagram Phone number |
Bruteforce |
Meta / Facebook |
Neeraj Sonaniya (@neeraj_sonaniya) |
Bug Bounty | 2017-02-20 | 2023-06-13 |
4998 | Bypassing Rate Limit Protection by spoofing originating IP |
Bruteforce |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4966 | How I could have mass uploaded from every Flickr account! |
Bruteforce |
Flickr |
Jazzy (@ret2got) |
Bug Bounty | 2017-10-05 | 2023-06-13 |
4887 | Internshala Bug in Internshala Student Partner |
Bruteforce |
Internshala |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-01-20 | 2023-06-13 |
4864 | I figured out a way to hack any of Facebook’s 2 billion accounts, and they paid me a $15,000 bounty for it |
Bruteforce
Account takeover |
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-09 | 2023-06-13 |
4721 | [Responsible disclosure] How I could have booked movie tickets through other user accounts |
Password reset
Account takeover
Bruteforce
OTP bypass |
AGS Cinemas |
Bharathvaj Ganesan |
Bug Bounty | 2018-06-18 | 2023-06-13 |
4693 | Attacking PostgreSQL Database |
Bruteforce
Weak credentials |
NA |
Vishnuraj |
Bug Bounty | 2018-07-16 | 2023-06-13 |
4606 | Simple Login Brute Force / Current Password Requirement Bypass |
IDOR
Account takeover
Bruteforce |
NA |
Mandeep Jadon (@1337tr0lls) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4549 | GoogleMeetRoulette: Joining random meetings |
Bruteforce
Logic flaw |
Google |
Martin Vigo (@martin_vigo) |
Bug Bounty | 2018-10-04 | 2023-06-13 |
4425 | Token Brute-Force to Account Take-over to Privilege Escalation to Organization Take-Over |
Account takeover
Privilege escalation
Bruteforce |
NA |
Plenum (@plenumlab) |
Bug Bounty | 2018-12-10 | 2023-06-13 |
4333 | Protonmail XSS — Stored |
Stored XSS
Bruteforce |
ProtonMail |
Chand Singh (@Chand_42) |
Bug Bounty | 2019-01-29 | 2023-06-13 |
4268 | Fixed : Brute-force Instagram account’s passwords |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4257 | Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack. |
CSRF
Bruteforce |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4213 | How I got a trip to amsterdam through bug bounty |
Bruteforce |
NA |
Ninad Mathpati (@ninad_mathpati) |
Bug Bounty | 2019-04-07 | 2023-06-13 |
4133 | How did I bypass a Custom Brute Force protection and why that solution is not a good idea? |
Bruteforce
Authentication flaw |
NA |
dortz |
Bug Bounty | 2019-05-25 | 2023-06-13 |
3816 | Disable Any Unconfirmed Account in Facebook |
Bruteforce |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-11-21 | 2023-06-13 |
3675 | IDOR leads to Data leakage and Profile Update |
IDOR
Bruteforce |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2020-02-07 | 2023-06-13 |
3610 | How I got access to critical data of a Company in no time ? |
Information disclosure
Lack of rate limiting
Bruteforce |
NA |
Kaustubh Kale |
Bug Bounty | 2020-03-12 | 2023-06-13 |
3577 | OTP Bruteforce- Account Takeover |
OTP bruteforce
Account takeover |
NA |
Ranjit Kumar |
Bug Bounty | 2020-03-29 | 2023-06-13 |
3551 | Hacking a Telecommunication company(MTN) |
OTP bypass
Bruteforce |
MTN Group |
Afolic |
Bug Bounty | 2020-04-13 | 2023-06-13 |
3398 | Account Takeover via OTP Bruteforce (Apigee API) |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2020-06-13 | 2023-06-13 |
3385 | How I managed to Escalate privilege as admin |
Lack of rate limiting
Bruteforce
Weak credentials |
NA |
Abisheik Magesh (@AbisheikMagesh) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3375 | Bypass 2FA like a Boss |
Lack of rate limiting
Bruteforce |
NA |
Seqrity (@seQrity) |
Bug Bounty | 2020-06-20 | 2023-06-13 |