5275 | How I found my way into Instagram%27s Ganglia, and a bug with Facebook likes. |
Reflected XSS
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2013-07-23 | 2023-06-13 |
5272 | Delete any Photo from Facebook by Exploiting Support Dashboard - $12,500 Bug |
IDOR |
Meta / Facebook |
Arul Kumar (@ArulVaiyapuri) |
Bug Bounty | 2013-09-01 | 2023-06-13 |
5242 | Popping a shell on the Oculus developer portal |
SQL injection
CSRF
RCE
IDOR |
Meta / Facebook |
Bitquark (@bitquark) |
Bug Bounty | 2014-08-31 | 2023-06-13 |
5226 | vimeo IDOR ( buying pro membership & ondemand videos for 0.1$ ) |
IDOR |
Vimeo |
N B Sri Harsha (@nbsriharsha) |
Bug Bounty | 2015-01-16 | 2023-06-13 |
5217 | [Responsible disclosure] How I could have hacked 62.5 million Zomato Users |
IDOR |
Zomato |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2015-06-04 | 2023-06-13 |
5216 | The easiest bug bounties I have ever won |
IDOR |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2015-07-13 | 2023-06-13 |
5201 | Leaking API keys in Bing Maps Portal |
IDOR |
Microsoft |
Sai Krishna Kothapalli (@kmskrishna) |
Bug Bounty | 2015-12-31 | 2023-06-13 |
5188 | How I Could Compromise 4% (Locked) Instagram Accounts |
IDOR
DoS
Authorization flaw |
Meta / Facebook |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2016-03-27 | 2023-06-13 |
5163 | Uber Hacking: How we found out who you are, where you are and where you went |
Bruteforce
Information disclosure
Logic flaw
IDOR |
Uber |
Vitor “r0t” Oliveira (@r0t1v) |
Bug Bounty | 2016-06-24 | 2023-06-13 |
5117 | IDOR in Facebook%27s Acquisition (Parse) |
IDOR |
Meta / Facebook |
Venkatesh Sivakumar (@pranavvenkats) |
Bug Bounty | 2016-12-11 | 2023-06-13 |
5112 | How I could have compromised any account on one of the biggest startup based in California |
Account takeover
IDOR
Password reset |
NA |
Prateek Tiwari (@prateek_0490) |
Bug Bounty | 2017-01-28 | 2023-06-13 |
5096 | One company: 262 bugs, 100% acceptance, 2.57 priority, millions of user details saved. |
Stored XSS
Blind XSS
CSRF
Account takeover
IDOR |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-02-25 | 2023-06-13 |
5082 | Airbnb – Web to App Phone Notification IDOR to view Everyone’s Airbnb Messages |
IDOR |
Airbnb |
Brett Buerhaus (@bbuerhaus) |
Bug Bounty | 2017-03-31 | 2023-06-13 |
5056 | How I hacked 23.900.000 tumblr domains at once :) |
IDOR |
Automattic |
Ak1T4 (@akita_zen) |
Bug Bounty | 2017-06-19 | 2023-06-13 |
5039 | How a simple IDOR become a $4K User Impersonation vulnerability |
IDOR |
NA |
Shahmeer Amir (@Shahmeer_Amir) |
Bug Bounty | 2017-07-08 | 2023-06-13 |
5035 | Hey UserID x, what’s your secret token? Broken API enables me to leak/modify any users personal information |
IDOR
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2017-07-13 | 2023-06-13 |
5032 | IDOR While Connecting Social Account in Hackster.io |
IDOR |
Hackster.io |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
5007 | Insecure Direct Object Reference In Facebook Events |
IDOR |
Meta / Facebook |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2017-08-11 | 2023-06-13 |
4997 | Improper Storage of Private Project’s Files |
IDOR |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4996 | Developer Luminate IDOR |
IDOR |
Yahoo! / Verizon Media |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2017-08-30 | 2023-06-13 |
4989 | IDOR on HackerOne Hacker Review “What Program Say” |
IDOR |
HackerOne |
Japz Divino (@japzdivino) |
Bug Bounty | 2017-09-02 | 2023-06-13 |
4976 | All About Hackerone Private Program Terapeak |
IDOR
Reflected XSS |
Terapeak |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-20 | 2023-06-13 |
4972 | IDOR – Execute JavaScript into anyone account |
IDOR
Stored XSS |
Terapeak |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2017-09-21 | 2023-06-13 |
4965 | How I Was Able To View Private Tweets Of Any Private Twitter Account |
IDOR |
Twitter |
Cj Legacion (@LegacionCj) |
Bug Bounty | 2017-10-06 | 2023-06-13 |
4954 | Taking over every Ad on OLX (automated), an IDOR story |
IDOR |
OLX |
Roderick Schaefer (@kciredor_) |
Bug Bounty | 2017-10-18 | 2023-06-13 |