4864 | I figured out a way to hack any of Facebook’s 2 billion accounts, and they paid me a $15,000 bounty for it |
Bruteforce
Account takeover |
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-09 | 2023-06-13 |
4863 | Stored XSS on Snapchat |
Stored XSS |
Snapchat |
Mrityunjoy (@mitunjoy11) |
Bug Bounty | 2018-02-09 | 2023-06-13 |
4862 | Oracle Cross Site Scripting Vulnerability -Adesh Kolte |
Reflected XSS |
Oracle |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-02-10 | 2023-06-13 |
4861 | #BugBounty — “How I was able to shop for free!”- Payment Price Manipulation |
Parameter tampering
Payment tampering |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-11 | 2023-06-13 |
4860 | An analysis of logic flaws in web-of-trust services |
Logic flaw |
Keybase |
EdOverflow (@EdOverflow) |
Bug Bounty | 2018-02-13 | 2023-06-13 |
4859 | $7.5k Google services mix-up |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-02-14 | 2023-06-13 |
4858 | How I was able to remotely crash any android user’s instagram app and was paid a mere 500$ for it. |
Android
DoS |
Meta / Facebook |
Waleed Ahmed |
Bug Bounty | 2018-02-15 | 2023-06-13 |
4857 | #BugBounty — Exploiting CRLF Injection can lands into a nice bounty |
CRLF injection |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-17 | 2023-06-13 |
4856 | Exploiting CORS Miss configuration using XSS |
CORS misconfiguration |
NA |
Noman Shaikh (@nomanali181) |
Bug Bounty | 2018-02-18 | 2023-06-13 |
4854 | How I hacked Tinder accounts using Facebook’s Account Kit and earned $6,250 in bounties |
Account takeover
Authorization flaw |
Tinder
Meta / Facebook |
Anand Prakash (@anandpraka_sh) |
Bug Bounty | 2018-02-20 | 2023-06-13 |
4853 | [RCE] Remote Code Execution in Wordpress iOS Application (version 9.3) |
RCE
iOS |
WordPress |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2018-02-21 | 2023-06-13 |
4852 | POODLE SSLv3 bug on multiple twitter smtp servers |
Cryptographic issues |
Twitter |
Omar Espino (@omespino) |
Bug Bounty | 2018-02-21 | 2023-06-13 |
4851 | Modifying any Ad Space and Placement |
IDOR |
Meta / Facebook |
Joshua Regio |
Bug Bounty | 2018-02-22 | 2023-06-13 |
4850 | The Fuzz…The Bug..The Action – A Race Condition bug in Facebook Chat Groups leads to spy on conversations! |
Race condition |
Meta / Facebook |
Seif Elsallamy (@seifelsallamy) |
Bug Bounty | 2018-02-23 | 2023-06-13 |
4849 | Bypassing Google’s authentication to access their Internal Admin panels |
Authentication bypass |
Google |
Vishnu Prasad P G (@vishnuprasadnta) |
Bug Bounty | 2018-02-24 | 2023-06-13 |
4848 | How I was able to delete any image in Facebook community question forum |
IDOR |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-02-24 | 2023-06-13 |
4847 | #BugBounty — API keys leakage, Source code disclosure in India’s largest e-commerce health care company. |
Path traversal |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4846 | How i Hacked into a bugcrowd. public program |
RCE |
NA |
Vishnuraj |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4845 | Re-dressing Instagram – Leaking Application Tokens via Instagram ClickJacking Vulnerability! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4844 | The 2.5mins or 2.5k$ hawk-eye bug – A Facebook Pages Admins Disclosure Vulnerability! |
Information disclosure |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4843 | How I found A Surprising XSS Vulnerability on Oracle NetSuite ? |
XSS |
Oracle |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-03-02 | 2023-06-13 |
4842 | #BugBounty — How I could book cab using your wallet money in India’s largest auto transportation company! |
OTP bypass |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-05 | 2023-06-13 |
4841 | Facebook Bug Bounty Reports |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-03-06 | 2023-06-13 |
4840 | Clickjackings in Google worth 12644.7$ |
Clickjacking |
Google |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-03-06 | 2023-06-13 |
4839 | Stored XSS, and SSRF in Google using the Dataset Publishing Language |
Stored XSS
SSRF |
Google |
Craig Arendt (@signalchaos) |
Bug Bounty | 2018-03-07 | 2023-06-13 |