1989 | Yes, fun browser extensions can have vulnerabilities too! |
XSS
Browser extension hacking
postMessage |
Meow |
Wladimir Palant (@WPalant) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1988 | Stored XSS by bypassing signature |
XSS
Unrestricted file upload |
NA |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1987 | How I was able to reveal page admin of almost any page on Facebook |
IDOR |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1986 | RCE in Visual Studio Code%27s Remote WSL for Fun and Negative Profit |
RCE |
Microsoft |
Parsia Hackerman (@cryptogangsta) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1985 | Blackbox Cookie Testing — How I Cracked The Admin’s Cookie |
Authentication bypass |
NA |
Saeed Balquizi |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1984 | Bring Your Own SSRF – The Gateway Actuator |
SSRF
DoS |
NA |
Wyatt Dahlenburg (@wdahlenb) |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1983 | How I earned $$$ by bypassing 2FA |
MFA bypass
Forced browsing |
NA |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1982 | SSD Advisory – Rocket.Chat Client-side Remote Code Execution |
RCE
MacOS |
Rocket.Chat |
- |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1981 | How I found (P2) Broken Authentication with Zero Skill of Hacking |
Authentication bypass
Account takeover |
NA |
yoshi m lutfi (@yoshiahmadlutfi) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1980 | NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories |
Security misconfiguration
.git folder disclosure |
Microsoft |
Wiz (@wiz_io) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1979 | Sandbox escape + privilege escalation in StorePrivilegedTaskService |
Local Privilege Escalation
MacOS |
Apple |
Sector 7 (@sector7_nl) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1978 | How I was able to bypass WAF and find the origin IP and a few sensitive files |
WAF bypass |
NA |
Jan Muhammad Zaidi (@hasanakajan) |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1977 | MS Teams: 1 feature, 4 vulnerabilities |
SSRF
Information disclosure
DoS
Spoofing |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1976 | Cache Poisoning at Scale |
Web cache poisoning |
GitHub
GitLab
HackerOne
Shopify
Cloudflare |
Youstin (@iustinBB) |
Bug Bounty | 2021-12-23 | 2023-06-13 |
1975 | How I found (and fixed) a vulnerability in Python |
Web cache poisoning |
Python |
Adam Goldschmidt (@AdamGolds) |
Bug Bounty | 2021-12-24 | 2023-06-13 |
1974 | Information Disclosure leads to sensitive credential($$$) |
Information disclosure |
NA |
khan mamun (@mamunwhh) |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1973 | Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲 |
Authentication bypass
IDOR
Lack of rate limiting |
NA |
Anurag__Verma |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1972 | How I Saved Christmas for Google 🎄 |
Dependency confusion |
Google (Waze) |
0xdroopy (@NikhilK50866227) |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1971 | Turning bad SSRF to good SSRF: Websphere Portal |
SSRF |
HCL Technologies |
Shubham Shah (@infosec_au) |
Bug Bounty | 2021-12-26 | 2023-06-13 |
1970 | How I Bypassed Netflix Profile Lock? |
Logic flaw |
Netflix |
Krishnadev P Melevila (@Krishnadev_P_M) |
Bug Bounty | 2021-12-27 | 2023-06-13 |
1969 | XSS via file upload |
XSS
Unrestricted file upload |
NA |
Jay Sharma |
Bug Bounty | 2021-12-27 | 2023-06-13 |
1968 | Bi/ug Bounties and HyperV RCE Research |
RCE |
Microsoft Hyper-V |
Peter Hlavaty (@rezer0dai) |
Bug Bounty | 2021-12-27 | 2023-06-13 |
1967 | Common Nginx Misconfiguration leads to Path Traversal |
Path traversal |
NA |
MikeChan |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1966 | Bounty Evaluation GitHub = $15,000 US Dollars | Rate Limit |
Bruteforce
Email verification bypass
Account takeover |
GitHub |
Taniya Agarwal |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1965 | Full account takeover vulnerability in Minecraft |
Account takeover |
Minecraft |
Abdulrahman Makki (@AMakki1337) |
Bug Bounty | 2021-12-28 | 2023-06-13 |