4314 | Setting Up Gitrob and using it to find Leaking Repository of an Employee in a hackerone private program. |
Information disclosure |
NA |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2019-02-09 | 2023-06-13 |
4312 | Csrf Bypass Using Cross Frame Scripting |
CSRF |
NA |
Mr.Hacker (@mr_hacker0007) |
Bug Bounty | 2019-02-10 | 2023-06-13 |
4307 | Disclose private attachments in Facebook Messenger Infrastructure - 15,000$ |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2019-02-13 | 2023-06-13 |
4306 | [SSRF] Server Side Request Forgery in a private Program developers.example.com |
SSRF |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-14 | 2023-06-13 |
4302 | Subdomain Takeover via HubSpot |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-15 | 2023-06-13 |
4301 | Bypassing rate limit abusing misconfiguration rules |
Rate limiting bypass |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-02-15 | 2023-06-13 |
4299 | Subdomain Takeover via Wufoo Service in a Private Program |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-16 | 2023-06-13 |
4294 | 2 Subdomains Takeover via Unbounce in a Private Program |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-18 | 2023-06-13 |
4285 | Swiss_E-Voting_Publications |
XSS
XXE
RCE
Missing authentication
Authentication flaw
Hardcoded credentials |
Swiss E-Voting |
setuid0 (@_setuid0_) |
Bug Bounty | 2019-02-21 | 2023-06-13 |
4283 | Subdomain Misconfiguration lead to AWS S3 Buckets Reader |
Subdomain takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-02-22 | 2023-06-13 |
4282 | Download any organisation Data — S3 amazonaws Misconfiguration |
Authorization flaw |
NA |
Chand Singh (@Chand_42) |
Bug Bounty | 2019-02-22 | 2023-06-13 |
4281 | Bug Bounty 101 — Always Check The Source Code |
Lack of rate limiting
Information disclosure |
NA |
Spazzy |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4280 | Chain of hacks leading to Database Compromise! |
LFI
SSRF |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-02-23 | 2023-06-13 |
4278 | Web Cache Deception Attack leads to user info disclosure |
Web cache deception
Information disclosure |
NA |
Kunal pandey (@kunalp94) |
Bug Bounty | 2019-02-25 | 2023-06-13 |
4273 | Bypassing a restrictive JS sandbox |
JS sandbox breakout
RCE |
NA |
Licencia para Hackear |
Bug Bounty | 2019-03-01 | 2023-06-13 |
4270 | Auditing GitHub Repo Wikis for Fun and Profit |
Misconfigured Github wiki |
NA |
Smeege (@SmeegeSec) |
Bug Bounty | 2019-03-04 | 2023-06-13 |
4268 | Fixed : Brute-force Instagram account’s passwords |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Sameer Rao |
Bug Bounty | 2019-03-05 | 2023-06-13 |
4264 | Mapping Communication Between Facebook Accounts Using a Browser-Based Side Channel Attack |
Side-channel attack
Cross-Site Frame Leakage (CSFL) |
Meta / Facebook |
Ron Masas (@RonMasas) |
Bug Bounty | 2019-03-07 | 2023-06-13 |
4262 | Account Takeover Using Cross-Site WebSocket Hijacking (CSWH) |
Cross-Site WebSocket Hijacking (CSWH)
Account takeover |
NA |
Sharan Panegav (@PanegavSharan) |
Bug Bounty | 2019-03-09 | 2023-06-13 |
4261 | SQL injection for $50 bounty, but still worth reading!! |
SQL injection |
NA |
Ronaldo Messi |
Bug Bounty | 2019-03-10 | 2023-06-13 |
4258 | Escalating SSRF to RCE |
SSRF
RCE |
NA |
Youssef A. Mohamed (@GeneralEG64) |
Bug Bounty | 2019-03-25 | 2023-06-13 |
4257 | Brute Forcing User IDS via CSRF To Delete all Users with CSRF attack. |
CSRF
Bruteforce |
NA |
Armaan Pathan (@armaancrockroax) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4256 | How I found Blind XSS Vulnerability in redacted.com |
Blind XSS |
NA |
ssid (@newp_th) |
Bug Bounty | 2019-03-12 | 2023-06-13 |
4255 | Hack Your Form-New vector for Blind XSS |
Blind XSS
Stored XSS |
NA |
Youssef A. Mohamed (@GeneralEG64) |
Bug Bounty | 2019-03-13 | 2023-06-13 |
4250 | User Account Takeover [Password Change]— Nice Catch! |
Account takeover
Password reset |
NA |
Rohit kumar (@rohitcoder) |
Bug Bounty | 2019-03-14 | 2023-06-13 |