366 | Traveling with OAuth - Account Takeover on Booking.com |
OAuth
Account takeover
Authentication bypass
Open redirect |
Booking.com
KAYAK |
Aviad Carmel (@AviadCarmel) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
336 | [Account Takeover] Don’t Send a Message to anyone Before Reading This [External Audit] |
HTTP response manipulation
Authentication bypass
Account takeover |
NA |
Vipul Sahu |
Bug Bounty | 2023-03-07 | 2023-06-13 |
335 | Unauthorized access to Codespace secrets in GitHub |
Logic flaw
Broken Access Control
Account takeover |
GitHub |
Ophion Security (@OphionSecurity) |
Bug Bounty | 2023-03-07 | 2023-06-13 |
333 | The story of becoming a Super Admin |
Hardcoded credentials
Account takeover
Information disclosure |
NA |
Ömer Kepenek (@omer_kepenek) |
Bug Bounty | 2023-03-08 | 2023-06-13 |
324 | Clipchamp ( Microsoft Office Product) - Google IAP Authorization bypass allowed access to Internal Environment Leading to Zero Interaction Account takeover |
Authorization bypass
JWT
Account takeover |
Microsoft (ClipChamp) |
Vikas Anil Sharma (@vikzsharma) |
Bug Bounty | 2023-03-10 | 2023-06-13 |
318 | CVE-2022-36413 Unauthorized Reset Password of Zoho ManageEngine ADSelfService Plus |
Password reset
OTP bruteforce
Account takeover
Authentication bypass |
Zoho (ManageEngine) |
Sky |
Bug Bounty | 2023-03-10 | 2023-06-13 |
317 | Account Takeover: An Epic Bug Bounty Story |
Account takeover
Self-XSS
Pre-account takeover |
NA |
Jaydev Ahire |
Bug Bounty | 2023-03-11 | 2023-06-13 |
311 | How I Leak Other’s Access Token by Exploiting Evil Deeplink Flaw |
Insecure deeplink
Android
Account takeover |
NA |
Crisdeo Nuel Siahaan |
Bug Bounty | 2023-03-13 | 2023-06-13 |
295 | Bypassing Character Limit - XSS Using Spanned Payload |
XSS
Account takeover |
NA |
SMHTahsin33 (@SMHTahsin33) |
Bug Bounty | 2023-03-15 | 2023-06-13 |
294 | OAuth 2.0 Authentication Misconfiguration |
OAuth
Account takeover
Open redirect
Token leak |
NA |
Mohamed Lakhdar Metidji (@minometidjii) |
Bug Bounty | 2023-03-16 | 2023-06-13 |
290 | How I chained multiple High-impact vulnerabilities to create a critical one. |
Account takeover
IDOR
OTP bypass
HTTP response manipulation |
NA |
Vinay Jagetiya (@princej_76) |
Bug Bounty | 2023-03-17 | 2023-06-13 |
285 | Account Takeover with rate limit bypass |
Rate limiting bypass
Account takeover |
NA |
Shamim Ahamed (@itm4n) |
Bug Bounty | 2023-03-18 | 2023-06-13 |
272 | Story of a Beautiful Account Takeover. |
Account takeover
OTP bypass |
NA |
Ambush Neupane (@N_ambush) |
Bug Bounty | 2023-03-23 | 2023-06-13 |
255 | BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained |
Account takeover
Azure AD
Cloud
XSS
Privilege escalation |
Microsoft (Bing) |
Hillai Ben-Sasson (@hillai) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
253 | Hacking Admin Panel & Getting free subscription |
Exposed registration API
Privilege escalation
Account takeover |
NA |
Zeeshan Mustafa (@by6153) |
Bug Bounty | 2023-03-29 | 2023-06-13 |
235 | Simple Bugs 0x01: Password Changing to Account Takeover! |
Account takeover
CSRF |
NA |
Vitor Falcao (@egl_falcao) |
Bug Bounty | 2023-04-03 | 2023-06-13 |
229 | Post Account Takeover? Account Takeover of Internal Tesla Accounts |
Account takeover
SSO |
Tesla |
Evan Connelly (@Evan_Connelly) |
Bug Bounty | 2023-04-04 | 2023-06-13 |
216 | Steal authentication token with one-click on misconfigured WebView. |
Android
Webview
Account takeover |
NA |
Kerolos A. Saber (@0xWise) |
Bug Bounty | 2023-04-08 | 2023-06-13 |
215 | How I was able to change password of any corporate user |
Account takeover
Password reset
Authentication bypass |
NA |
CH3TAN |
Bug Bounty | 2023-04-09 | 2023-06-13 |
213 | Account Take Over (Via an API) |
Account takeover
Information disclosure
Broken Access Control
Cryptographic issues |
NA |
Thabiso Mokoena |
Bug Bounty | 2023-04-10 | 2023-06-13 |
191 | A Big company Admin Panel takeover $4500 |
Authentication bypass
40x bypass
Account takeover |
NA |
nanwn |
Bug Bounty | 2023-04-17 | 2023-06-13 |
177 | How I hacked hackers in Voorivex Hunt Event |
Cloudflare bypass
WAF bypass
Account takeover |
NA |
snoopy (@snoopy101101) |
Bug Bounty | 2023-04-19 | 2023-06-13 |
163 | How careless default credentials impact to massive account takeover |
Authentication bypass
Account takeover
Weak credentials |
NA |
M Maulana Abdullah |
Bug Bounty | 2023-04-22 | 2023-06-13 |
124 | Privilege Escalations through Integrations |
Privilege escalation
Amazon cognito misconfiguration
JWT
Account takeover |
NA |
Colin McQueen |
Bug Bounty | 2023-05-04 | 2023-06-13 |
85 | From GitHub To Account Takeover: Misconfigured Actions Place GCP & AWS Accounts At Risk |
Account takeover
Cloud
OpenID Connect
CI/CD |
NA |
Rezonate |
Bug Bounty | 2023-05-16 | 2023-06-13 |