5281 | Stealing Facebook Access Tokens with a Double Submit |
CSRF
OAuth |
Meta / Facebook |
Jack Whitton (@fin1te) |
Bug Bounty | 2013-04-13 | 2023-06-13 |
5194 | How I Hacked [Oculus] OAuth +Ebay +IBM |
Unrestricted file upload
XSS |
Meta / Facebook
Ebay
IBM
AnswerHub |
Abdullah Hussam (@Abdulahhusam) |
Bug Bounty | 2016-02-12 | 2023-06-13 |
5159 | Stealing Facebook access_tokens using CSRF in device login flow |
CSRF
OAuth
Information disclosure |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2016-07-19 | 2023-06-13 |
5141 | Internet Explorer has a URL problem |
OAuth
RPO
XSS |
GitHub
Google |
File Descriptor (@filedescriptor) |
Bug Bounty | 2016-09-06 | 2023-06-13 |
5138 | Bug Bounty : Account Takeover Vulnerability POC |
OAuth
Account takeover
XSS |
NA |
Rakesh Mane (@RakeshMane10) |
Bug Bounty | 2016-09-16 | 2023-06-13 |
5055 | Authentication bypass on Airbnb via OAuth tokens theft |
OAuth
Login CSRF
Open redirect
Authentication bypass |
Airbnb |
Arne Swinnen (@ArneSwinnen) |
Bug Bounty | 2017-06-22 | 2023-06-13 |
5031 | Stealing Access Token of One-drive Integration By Chaining CSRF Vulnerability |
OAuth
CSRF |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-07-18 | 2023-06-13 |
4992 | Stealing 0Auth Token (MITM) |
OAuth |
NA |
Arbaz Hussain (@ArbazKiraak) |
Bug Bounty | 2017-09-01 | 2023-06-13 |
4866 | Bug bounty left over (and rant) Part III (Google and Twitter) |
OAuth
Authentication flaw
Information disclosure |
Google
Twitter |
Antonio Sanso (@asanso) |
Bug Bounty | 2018-02-06 | 2023-06-13 |
4678 | Finding hidden gems vol. 1: forging OAuth tokens using discovered client id and client secret |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2018-07-23 | 2023-06-13 |
4555 | Applying a small bypass to steal Facebook Session tokens in Uber |
XSS
CSP bypass
OAuth |
Uber |
Samuel (@saamux) |
Bug Bounty | 2018-10-02 | 2023-06-13 |
4495 | Full Account Takeover via Referer Header (OAuth token Steal, Open Redirect Vulnerability Chaining) |
Open redirect
Token leak
Account takeover |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2018-11-03 | 2023-06-13 |
4422 | Microsoft Account Takeover Vulnerability Affecting 400 Million Users |
Subdomain takeover
OAuth |
Meta / Facebook |
Aviva Zacks |
Bug Bounty | 2018-12-11 | 2023-06-13 |
4416 | #BugBounty — “User Account Takeover-I just need your email id to login into your shopping portal account” |
OAuth
Authentication bypass
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-12-13 | 2023-06-13 |
4413 | $3k Bug Bounty - Twitter%27s OAuth Mistakes |
OAuth |
Twitter |
Terence Eden (@edent) |
Bug Bounty | 2018-12-14 | 2023-06-13 |
4359 | Oauth Misconfiguration lead to complete account takeover |
CSRF
OAuth
Account takeover |
NA |
Jackson kv (@Jacksonkv22) |
Bug Bounty | 2019-01-20 | 2023-06-13 |
4337 | Chaining Tricky OAuth Exploitation To Stored XSS |
Stored XSS
OAuth |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-01-27 | 2023-06-13 |
4052 | OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect |
Open redirect
Token leak
Account takeover |
Airbnb |
Evgeniy Yakovchuk (@h1_sp1d3r) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4012 | Story about Facebook Oauth Account Takeover |
Account takeover
OAuth |
iLOTTE |
Zerb0a |
Bug Bounty | 2019-07-26 | 2023-06-13 |
3973 | BookMyShow account takeover using social login |
OAuth
Account takeover |
BookMyShow |
Sukhmeet Singh (@MadGuyyy) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3909 | Bug or Feature? GitHub Adventure #001 |
OAuth
Open redirect |
NA |
Dominik Opyd (@oad_earth) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3906 | [Case Study] OAuth Misconfiguration leads to Account Takeover |
OAuth
Account takeover |
NA |
Gaurang Bhatnagar (@0xgaurang) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3850 | Bypassing GitHub%27s OAuth flow |
OAuth
Authorization bypass |
GitHub |
Teddy Katz (@not_aardvark) |
Bug Bounty | 2019-11-05 | 2023-06-13 |
3810 | Finding a security bug in Discord and what it taught me |
OAuth |
Discord |
Tristan Farkas (@TristanAtFarkas) |
Bug Bounty | 2019-11-24 | 2023-06-13 |
3774 | Abusing feature to steal your tokens |
OAuth |
NA |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2019-12-17 | 2023-06-13 |