4766 | How I was able to get subscription of $120/year For Free |
Payment bypass |
WeTransfer |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2018-05-18 | 2023-06-13 |
4603 | Bypassing Hotstar Premium with DOM manipulation and some JavaScript |
Logic flaw
Payment bypass |
Hotstar |
OpSecX (@OpSecX) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4537 | Payment bypass |
Payment bypass
Logic flaw |
NA |
Pratik Yadav (@PratikY9967) |
Bug Bounty | 2018-10-09 | 2023-06-13 |
3263 | New features means new bugs |
Logic flaw
Authorization flaw
Payment bypass |
NA |
Zseano (@zseano) |
Bug Bounty | 2020-07-30 | 2023-06-13 |
2473 | Part-1 Dive into Zoom Applications |
CSRF
Payment bypass
Logic flaw
Account takeover
Privilege escalation |
Zoom |
Rakesh Thodupunoori (@rakesh_3895) |
Bug Bounty | 2021-06-16 | 2023-06-13 |
1778 | Hacking Subscription Plans for free service. |
Payment bypass
OTP bypass |
NA |
Muhammad Khizer Javed (@khizer_javed47) |
Bug Bounty | 2022-02-27 | 2023-06-13 |
1654 | The Bug That Kept On Giving :: PaymentBypass :: Eposed Return Url |
Payment bypass
Logic flaw |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1599 | Unlock any blur text/picture without membership/subscription on Scribd.com |By Neuchi |
Payment bypass
Logic flaw |
Scribd.com |
Neil Neuchi |
Bug Bounty | 2022-04-25 | 2023-06-13 |
1579 | Business Logic Errors - Art of Testing Cards |
Payment bypass
Logic flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2022-05-04 | 2023-06-13 |
1547 | Vulnerability in Huawei%27s AppGallery can download paid apps for free |
Payment bypass
Logic flaw |
Huawei |
Dylan Roussel (@evowizz) |
Bug Bounty | 2022-05-18 | 2023-06-13 |
1492 | Exploiting Amazon active vulnerability |
Payment bypass
Logic flaw |
Amazon |
Benjamin Walter |
Bug Bounty | 2022-06-08 | 2023-06-13 |
1484 | How to download eBooks from Google Play Store without paying for them |
Payment bypass
Logic flaw |
Google |
Yess (@Yess_2021xD) |
Bug Bounty | 2022-06-09 | 2023-06-13 |
1414 | [BugBounty] how do I get a premium tier account without paying a penny |
Mass assignment
Payment bypass |
NA |
Marzuki (@aizack_ma) |
Bug Bounty | 2022-06-29 | 2023-06-13 |
1348 | Hacking Facebook Invoice: How I could’ve bought anything for Free from Facebook Business Pages |
Payment bypass |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2022-07-18 | 2023-06-13 |
1240 | Researching Xiaomi’s TEE to get to Chinese money |
Payment bypass
Android
Memory corruption |
Xiaomi |
Slava Makkaveev |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1096 | How I found 3 rare security bug in a day |
Session expiration issue
Payment bypass
Lack of rate limiting |
NA |
zer0d |
Bug Bounty | 2022-09-10 | 2023-06-13 |
1018 | A vulnerability on Patreon, and their elusive bounty program. |
Payment bypass
Weak crypto |
Patreon |
Datura Mater (@DaturaMater) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
986 | Vulnerabilities in Online Payment Systems |
Payment bypass
Payment tampering
Logic flaw |
NA |
Claudio Moran |
Bug Bounty | 2022-10-08 | 2023-06-13 |
683 | The Bug That Kept On Giving :: PaymentBypass :: Response Manipulation |
Payment bypass
Logic flaw |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2022-12-16 | 2023-06-13 |
631 | Bypass Premium Account Payment (GetPocket) |
Payment bypass |
Mozilla (GetPocket) |
querylab |
Bug Bounty | 2023-01-01 | 2023-06-13 |
612 | The Bug That Kept On Giving :: PaymentBypass :: QR CODE |
Payment bypass |
NA |
g30rgy th3 d4rk (@Crypt0g30rgy) |
Bug Bounty | 2023-01-07 | 2023-06-13 |
483 | Bypassing API Restrictions for Fun and Profit |
Payment bypass
Logic flaw |
NA |
Arnav Tripathy |
Bug Bounty | 2023-02-07 | 2023-06-13 |
408 | Exploit Airlines that use T-Mobile for Free WiFi |
Wifi
Payment bypass
MAC address spoofing
Missing authentication |
T-Mobile |
cylect.io (@cylect_io) |
Bug Bounty | 2023-02-23 | 2023-06-13 |
362 | How I Earned $$$ for Excessive Data Exposure Through Directory Traversal Leads to Product Price Manipulation |
Path traversal
Information disclosure
Payment bypass |
NA |
Mohamed Shibil |
Bug Bounty | 2023-03-03 | 2023-06-13 |
361 | Upgrade plan from Free to Paid via Response Manipulation |
Payment bypass
HTTP response manipulation |
NA |
Ibrahim Radi (@ibraradi9) |
Bug Bounty | 2023-03-03 | 2023-06-13 |