Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
5215Bypassing Google Authentication on Periscope%27s Administration Panel Authentication bypass Google Jack Whitton (@fin1te) Bug Bounty2015-07-202023-06-13
5120Authentication bypass on Ubiquity’s Single Sign-On via subdomain takeover Subdomain takeover Authentication bypass Ubiquity Networks Arne Swinnen (@ArneSwinnen) Bug Bounty2016-11-292023-06-13
5081Inspect Element leads to Stripe Account Lockout Authentication Bypass Authentication bypass Stripe Jon Bottarini (@jon_bottarini) Bug Bounty2017-04-032023-06-13
5079Tales of SugarCRM Security Horrors PHP Object Injection SQL injection Authentication bypass SugarCRM Egidio Romano / EgiX Bug Bounty2017-04-232023-06-13
5070Nokia Asha Series Lock Screen Bypass Authentication bypass Lock screen bypass Nokia Hammad Shamsi (@HammadShamsii) Bug Bounty2017-06-012023-06-13
5062From JS to another JS files lead to authentication bypass Authentication bypass NA yappare (@yappare) Bug Bounty2017-06-062023-06-13
5055Authentication bypass on Airbnb via OAuth tokens theft OAuth Login CSRF Open redirect Authentication bypass Airbnb Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-222023-06-13
5051Authentication bypass on Uber’s Single Sign-On via subdomain takeover Subdomain takeover Authentication bypass Uber Arne Swinnen (@ArneSwinnen) Bug Bounty2017-06-252023-06-13
5004Accidentally typo to bypass administration access Authentication bypass NA yappare (@yappare) Bug Bounty2017-08-132023-06-13
4952Slack SAML authentication bypass Authentication bypass Slack Antonio Sanso (@asanso) Bug Bounty2017-10-262023-06-13
4932JWT Refresh Token Manipulation JWT Authentication bypass Account takeover NA Mikail Tunç (@emtunc) Bug Bounty2017-11-162023-06-13
4915How I was able to takeover Facebook account Authentication bypass Meta / Facebook Ameer Hamza Bug Bounty2017-12-102023-06-13
4901"F**k you Thomas" - ToyTalk bug bounty writeup Authentication bypass HTML injection ToyTalk Jahmel Harris Bug Bounty2018-01-042023-06-13
4871#BugBounty — "I don%27t need your current password to login into your account" - How could I completely takeover any user%27s account in an online classified ads company. Authentication bypass NA Avinash Jain (@logicbomb_1) Bug Bounty2018-02-032023-06-13
4849Bypassing Google’s authentication to access their Internal Admin panels Authentication bypass Google Vishnu Prasad P G (@vishnuprasadnta) Bug Bounty2018-02-242023-06-13
4820My Best Small Report Bounty Report in Private Program ( Django REST framework Admin Login ByPass ) SQL injection Authentication bypass Account takeover NA Mohamed Haron (@m7mdharon) Bug Bounty2018-04-012023-06-13
4810Source Code Analysis in YSurvey — Luminate bug Authentication bypass Authorization flaw SQL injection Yahoo! / Verizon Media Rojan Rijal (@uraniumhacker) Bug Bounty2018-04-102023-06-13
4687Oracle WebLogic - Multiple SAML Vulnerabilities (CVE-2018-2998/CVE-2018-2933) SAML Authentication bypass Oracle (WebLogic) Denis Andzakovic Bug Bounty2018-07-182023-06-13
4641Adminer Script Results to Pwning Server?, Private Bug Bounty Program Authentication bypass NA Yashar Shahinzadeh (@YShahinzadeh) Bug Bounty2018-08-112023-06-13
4598ZOL Zimbabwe Authentication Bypass to XSS & SQLi Vulnerability – Bug Bounty POC XSS SQL injection ZOL Zimbabwe Muhammad Khizer Javed (@khizer_javed47) Bug Bounty2018-09-092023-06-13
4594Authentication Bypass Using SQL Injection AutoTrader Webmail – Bug Bounty POC SQL injection AutoTrader Muhammad Khizer Javed (@khizer_javed47) Bug Bounty2018-09-102023-06-13
4579Facebook $750 Reward for a Simple Bug Authentication bypass Logic flaw Meta / Facebook Aman Shahid (@amansmughal) Bug Bounty2018-09-182023-06-13
4577Bypassing Authentication Using Javascript Debugger. Authentication bypass NA Mohit Dabas (@mohitdabas08) Bug Bounty2018-09-182023-06-13
4536Symantec Messaging Gateway authentication bypass Authentication bypass Symantec Artem Kondratenko (@artkond) Bug Bounty2018-10-102023-06-13
4535Access to staging environment via User-Agent string Authentication bypass NA Yasser Gersy (@yassergersy) Bug Bounty2018-10-102023-06-13