2331 | Taking Over Employee Accounts by Managers with Zero Employee Interaction |
HTML injection |
NA |
Chaitanya Rajhans (@Chaitanya_024) |
Bug Bounty | 2021-08-12 | 2023-06-13 |
2330 | Blind SSRF in URL Validator |
Blind SSRF |
NA |
Yash Kandekar (@Neutron__) |
Bug Bounty | 2021-08-12 | 2023-06-13 |
2329 | How I found read/write access to the personal data of 3 million users of an E-commerce website? |
IDOR |
NA |
Prashant Singh / SecGeek_one0one |
Bug Bounty | 2021-08-13 | 2023-06-13 |
2328 | How we was able to takeover whole organization via Privilege Escalation |
Privilege escalation
Authorization flaw |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-13 | 2023-06-13 |
2327 | Facebook Bug:Invite user to Like a Page even after they decline the Page Like Invite |
Logic flaw |
Meta / Facebook |
Circle Ninja (@circleninja) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2326 | Bypass Google Captcha+Parameter Pollution Leads to send email to any user on behalf of “Organization” with any desired content |
HTTP parameter pollution
Captcha bypass |
NA |
viral bhatt (@viralbhatt100) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2325 | Finding multiple SSRF with aws metadata access on A BANK system |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2324 | Simple HTML Injection to $250 |
Account takeover
Mass assignment |
NA |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2021-08-14 | 2023-06-13 |
2323 | 1st Bug Bounty WriteUp: Open Redirect To XSS on Login Page |
Open redirect
XSS |
NA |
Nassim Chami (@nvccim) |
Bug Bounty | 2021-08-15 | 2023-06-13 |
2322 | Second Order Subdomain Takeovers – They DO Exist! |
Subdomain takeover
Broken link hijacking |
Microsoft |
Alun Jones (@ftp_alun) |
Bug Bounty | 2021-08-15 | 2023-06-13 |
2321 | Why u should use burp to test Path Traversal Vulnerability and also get RXSS |
Path traversal
XSS
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2320 | A Bug%27s Life: CVE-2021-21225 |
Browser hacking |
Google |
Brendon Tiszka (@btiszka) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2319 | CVE-2021-22929 – Brave Browser 1.27 and below permanently logs the server connection time for all v2 tor domains to ~/.config/BraveSoftware /Brave-Browser/tor/data/tor.log |
Privacy issue
Information disclosure |
Brave Software |
sickcodes (@sickcodes) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2318 | Two weeks of securing Samsung devices: Part 2 |
Arbitrary file write
Arbitrary file read
Vulnerable Android content provider
Android |
Samsung |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2317 | Dangling DNS: Announcekit |
Subdomain takeover |
NA |
Mohamed Elbadry (@_melbadry9) |
Bug Bounty | 2021-08-16 | 2023-06-13 |
2316 | Confirming any new Email Address bug in Facebook (Part-4) |
Rate limiting bypass |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2021-08-17 | 2023-06-13 |
2315 | How to Hack Apple ID |
XSS
Account takeover |
Apple |
Zemnmez (@zemnmez) |
Bug Bounty | 2021-08-17 | 2023-06-13 |
2314 | A New Attack Surface on MS Exchange Part 1 - ProxyLogon! |
RCE
Privilege escalation |
Microsoft |
Orange Tsai (@orange_8361) |
Bug Bounty | 2021-08-18 | 2023-06-13 |
2313 | Account Takeover via Access Token Leakage |
IDOR
Information disclosure
Account takeover |
NA |
Tuhin Bose (@tuhin1729_) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2312 | Disclose WhatsApp Number of Instagram Accounts Despite Setting Set to be Hidden |
Information disclosure
Logic flaw |
Meta / Facebook |
Naveen (@NaveenHax) |
Bug Bounty | 2021-08-19 | 2023-06-13 |
2311 | How I got RCE In The World Largest Russian Company |
RCE |
Mail.ru |
Sicksec (@OriginalSicksec) |
Bug Bounty | 2021-08-20 | 2023-06-13 |
2310 | How I found my first Subdomain Takeover vulnerability |
Subdomain takeover
CSRF |
NA |
Monish Basaniwal |
Bug Bounty | 2021-08-20 | 2023-06-13 |
2309 | Playing With s3 Leaks |
AWS misconfiguration |
NA |
Aswin Thambi Panikulangara (@r0074g3n7) |
Bug Bounty | 2021-08-21 | 2023-06-13 |
2308 | How I was able to get 1000$ bounty from a ds-store file? |
Information disclosure
Debugging enabled |
NA |
Khaled Mohamed (@0xElkomy) |
Bug Bounty | 2021-08-21 | 2023-06-13 |
2307 | MonkeyType.com Stored Cross-Site Scripting |
Stored XSS
Authentication bypass
IDOR |
MonkeyType.com |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2021-08-22 | 2023-06-13 |