2095 | Bypass Chrome Ad-Heavy detection mechanism |
Browser hacking |
Google (Chrome) |
0x0021h (@0x0021h) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2094 | Becoming A Super Admin In Someone Elses Gsuite Organization And Taking It Over |
IDOR |
Google |
Cam (@secretlyhidden1) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2093 | 400$ Bounty again using Google Dorks |
Directory listing
Information disclosure |
NA |
Haris M (@hrsm321) |
Bug Bounty | 2021-11-09 | 2023-06-13 |
2092 | Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond |
HTTP Header Smuggling
HTTP Request Smuggling |
NA |
Daniel Thatcher (@_danielthatcher) |
Bug Bounty | 2021-11-10 | 2023-06-13 |
2091 | ChaosDB Explained: Azure%27s Cosmos DB Vulnerability Walkthrough |
Cross-tenant vulnerability
Account takeover
Privilege escalation |
Microsoft |
Nir Ohfeld (@nirohfeld) |
Bug Bounty | 2021-11-10 | 2023-06-13 |
2089 | Unrestricted File Upload Leads to SSRF and RCE |
ImageTragick
Unrestricted file upload
SSRF
RCE |
NA |
Muhammad Adel (@ItsFadinG_) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2088 | Write Up – Google VRP Bug Bounty: /etc/environment Local Variables Exfiltrated On Linux Google Earth Pro Desktop App – $1,337 USD |
XSS |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2087 | Simple SSRF Allows Access To Internal Assets |
SSRF |
NA |
Sam Paredes (@caffeinevulns) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2086 | From URL dumps digging to IDOR , BAC, Massive Phishing in Udemy |
Broken Access Control
Information disclosure
IDOR
HTML injection |
Udemy |
Mostafa Mamdoh |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2085 | chaining improper authentication to idor and no rate limit for mass account takeover |
Account takeover
Lack of rate limiting
CSRF
IDOR |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2084 | How I got $200 in 30 Seconds. |
Information disclosure |
NA |
Yash__ HackZ (@HackzYash) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2083 | Privilege Escalation, worth of €300 |
Broken Access Control
IDOR
Privilege escalation |
NA |
Hemant Kumar |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2082 | Never leave this tip while you hunting Broken Access Control |
Broken Access Control |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2081 | Impact of an Insecure Deep Link |
Insecure deeplink |
CafeBazaar |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2080 | Exploiting CSP in Webkit to Break Authentication & Authorization |
Information disclosure
CSP leak
Account takeover |
Apple |
Sachin Thakuri (@sachinnthakuri) |
Bug Bounty | 2021-11-13 | 2023-06-13 |
2079 | Broken Link Hijacking — 404 Google Play Store— xxx$ Bounty |
Broken link hijacking |
NA |
Proviesec (@proviesec) |
Bug Bounty | 2021-11-14 | 2023-06-13 |
2078 | How I Found P1 bug Due to Sensitive data exposure And Earn $$$$ |
Information disclosure |
NA |
Piyush shukla (@PiyushShukla__) |
Bug Bounty | 2021-11-15 | 2023-06-13 |
2077 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-15 | 2023-06-13 |
2076 | T-Reqs: HTTP Request Smuggling with Differential Fuzzing |
HTTP Request Smuggling |
NA |
Bahruz Jabiyev (@BahruzJabiyev) |
Bug Bounty | 2021-11-15 | 2023-06-13 |
2075 | Full account takeover through referral code. |
Authentication flaw
Account takeover |
Shipt |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2074 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS
Logic flaw |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2073 | Diving into Open-source LMS Codebases |
Insecure file upload
Insecure deserialization
RCE
CSRF
SQL injection
Reflected XSS |
Moodle
Chamilo LMS |
Poh Jia Hao (@Chocologicall) |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2072 | Finding Zero-Day Vulnerabilities in the Supply Chain |
CSTI
Signature bypass |
Adaxes |
Roni Carta (@0xLupin) |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2071 | Keybase App Vulnerability: Incomplete Cleanup of Messages In Keybase for Android/iOS, CVE-2021-34421 |
Information disclosure |
Keybase |
Olivia O’Hara (@oliviaohara) |
Bug Bounty | 2021-11-17 | 2023-06-13 |
2070 | The tale of CVE-2021–34479 (VSCode XSS) |
XSS
CSP bypass |
Microsoft |
Daniel Santos (@bananabr) |
Bug Bounty | 2021-11-17 | 2023-06-13 |