Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3077TikTok fixes privacy issue discovered by Check Point Research Information disclosure TikTok Eran Vaknin Bug Bounty2020-10-262023-06-13
3075The YouTube bug that allowed unlisted uploads to any channel IDOR Information disclosure Google Ryan Kovatch Bug Bounty2020-10-272023-06-13
3063How i got 7000$ in Bug-Bounty for my Critical Finding. Information disclosure NA Kishan Kumar / Noobie BoY (@hst_kishan) Bug Bounty2020-10-312023-06-13
3058Reveal the page admin that uploaded a video on the page in comment section Information disclosure Logic flaw Meta / Facebook Lokesh Kumar (@lokeshdlk77) Bug Bounty2020-11-022023-06-13
3054How I found a Tor vulnerability in Brave Browser, reported it, watched it get patched, got a CVE (CVE-2020-8276) and a small bounty, all in one working day Information disclosure Brave Software sickcodes (@sickcodes) Bug Bounty2020-11-052023-06-13
3038User’s private watched videos/saved videos exposed through a messenger call from a locked smartphone. Information disclosure Authorization flaw Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2020-11-132023-06-13
3037How a simple bug in Facebook Lite let me win my first bug bounty from Facebook Information disclosure Meta / Facebook Samip Aryal (@samiparyal_) Bug Bounty2020-11-132023-06-13
3035How I Found The Facebook Messenger Leaking Access Token Of Million Users Information disclosure Meta / Facebook Guhan Raja (@havocgwen) Bug Bounty2020-11-132023-06-13
3029Exploiting API with AuthToken Token leak Information disclosure NA Rafi Ahamed (Leonidas D. Ace) Bug Bounty2020-11-152023-06-13
3026Optimizing Hunting Results in VDP for use in Bug Bounty Programs - From Sensitive Information Disclosure to Accessing Hidden APIs which can be used to Retrieve Customer Data Information disclosure Broken access control IDOR SQL injection NA YoKo Kho (@YokoAcc) Bug Bounty2020-11-152023-06-13
3023Stealing User’s PII info by visiting API endpoint directly Information disclosure Logic flaw NA Kunal pandey (@kunalp94) Bug Bounty2020-11-162023-06-13
3018Server Side Misconfigurartion - A Funny Fix Information disclosure Basecamp Jerry Shah (@Jerry) Bug Bounty2020-11-182023-06-13
3005How images on Github will leak your private information Information disclosure GitHub fuomag9 (@fuomag9) Bug Bounty2020-11-242023-06-13
3000Bcrypt — Account TakeOver Due To Weak Encryption — #HR51KDB Information disclosure Account takeover NA DarkLotus (@darklotuskdb) Bug Bounty2020-11-292023-06-13
2993Hacking — Always check out the Images Information disclosure GitLab Jack Bug Bounty2020-12-022023-06-13
2991Leaking Browser URL/Protocol Handlers Information disclosure Google Microsoft Mozilla Tabahi (@_tabahi) Bug Bounty2020-12-032023-06-13
2988Leaking Credit card Activity in logs? Yes Sir! Information disclosure NA Rody Shahnazarian (@Komradz86) Bug Bounty2020-12-032023-06-13
2968Confirm an email address belonging to a specific user Information disclosure Meta / Facebook abdellah yaala (@yaalaab) Bug Bounty2020-12-122023-06-13
2963How I hacked IBM and got full access on many services? Information disclosure IBM Abdullah Mohamed (@3bodymo_) Bug Bounty2020-12-162023-06-13
2962D-Link: Multiple Security Vulnerabilities Leading to RCE RCE Authentication bypass Information disclosure D-Link Harold Zang Bug Bounty2020-12-172023-06-13
2958Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts Information disclosure Account takeover Authorization flaw Samsung Gal Nagli (@naglinagli) Bug Bounty2020-12-182023-06-13
2955Facebook bug Bounty -Finding the hidden members of the private events. Information disclosure Logic flaw Meta / Facebook Vivek ps (@vivekps143) Bug Bounty2020-12-202023-06-13
2954This is how I was able to view anyone’s private email and birthday on Instagram Information disclosure Logic flaw Meta / Facebook Saugat Pokharel (@saugatpk5) Bug Bounty2020-12-202023-06-13
2946Facebook page admin disclosure by "Message Seller" button (Bounty: 1500 USD) Information disclosure Meta / Facebook Shubham Bhamare (@theshubh77) Bug Bounty2020-12-262023-06-13
2941Facebook page admin disclosure by "Create doc" button (Bounty: 5000 USD) Information disclosure Meta / Facebook Shubham Bhamare (@theshubh77) Bug Bounty2020-12-282023-06-13