4860 | An analysis of logic flaws in web-of-trust services |
Logic flaw |
Keybase |
EdOverflow (@EdOverflow) |
Bug Bounty | 2018-02-13 | 2023-06-13 |
4859 | $7.5k Google services mix-up |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-02-14 | 2023-06-13 |
4841 | Facebook Bug Bounty Reports |
Authorization flaw
Logic flaw
Information disclosure |
Meta / Facebook |
Raushan Raj (@raushan_rajj) |
Bug Bounty | 2018-03-06 | 2023-06-13 |
4835 | #BugBounty — “Let me reset your password and login into your account “-How I was able to Compromise any User Account via Reset Password Functionality |
Logic flaw
Password reset
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-14 | 2023-06-13 |
4828 | Misconfiguration of Demographics Privacy in a Page |
Logic flaw |
Meta / Facebook |
Mark Christian Deduyo |
Bug Bounty | 2018-03-26 | 2023-06-13 |
4826 | Google bug bounty for security exploit that influences search results |
Logic flaw |
Google |
Tom Anthony (@TomAnthonySEO) |
Bug Bounty | 2018-03-27 | 2023-06-13 |
4824 | How I Could Have Promoted Any Facebook Page For Free. |
Logic flaw |
Meta / Facebook |
Anees Khan (@AneesEthical) |
Bug Bounty | 2018-03-30 | 2023-06-13 |
4809 | How I broke into Google Issue Tracker |
Logic flaw
Authorization flaw |
Google |
Abhishek Bundela (@abhibundela) |
Bug Bounty | 2018-04-10 | 2023-06-13 |
4807 | Hijacking User’s Private Information access_token from Microsoft Office360 facebook App |
Logic flaw |
Microsoft |
Mohamed A. Baset |
Bug Bounty | 2018-04-13 | 2023-06-13 |
4802 | $5k Service dependencies |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-04-16 | 2023-06-13 |
4784 | The Unknown Hero-App Logic Bugs |
Logic flaw |
Canva |
Circle Ninja (@circleninja) |
Bug Bounty | 2018-04-25 | 2023-06-13 |
4776 | Stealing money from one account to another account |
Logic flaw |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2018-05-02 | 2023-06-13 |
4737 | Zero to Account Takeover: How I Impersonated’ Someone Else Using Auth0 |
Logic flaw |
Auth0 |
Daniel Svartman |
Bug Bounty | 2018-06-05 | 2023-06-13 |
4726 | How I got paid premium plan for free on many popular websites |
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-06-13 | 2023-06-13 |
4710 | How re-signing up for an account lead to account takeover |
Logic flaw
Account takeover |
NA |
Zseano (@zseano) |
Bug Bounty | 2018-06-26 | 2023-06-13 |
4690 | Hacking thousands of companies through their helpdesk |
Account takeover
DoS
Logic flaw |
NA |
Khaled Hassan |
Bug Bounty | 2018-07-17 | 2023-06-13 |
4689 | Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups |
Authorization flaw
Logic flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-07-18 | 2023-06-13 |
4658 | My First Swag Pack : A Logical Bug on Edmodo |
Logic flaw |
Edmodo |
Abartan Dhakal (@imhaxormad) |
Bug Bounty | 2018-08-05 | 2023-06-13 |
4655 | Unauth meetings access |
Authorization flaw
Logic flaw |
Google |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-08-06 | 2023-06-13 |
4638 | Distorted and Undeletable Posts in Facebook Group |
Authorization flaw
Logic flaw |
Meta / Facebook |
Sarmad Hassan (@JubaBaghdad) |
Bug Bounty | 2018-08-12 | 2023-06-13 |
4635 | Another "TicketTrick" story |
Ticket Trick
Logic flaw |
Uber |
Rojan Rijal (@uraniumhacker) |
Bug Bounty | 2018-08-14 | 2023-06-13 |
4610 | Facebook Bug Bounty! {Permission Bug} |
Authorization flaw
Logic flaw |
Meta / Facebook |
Ali Tütüncü (@alicanact60) |
Bug Bounty | 2018-09-05 | 2023-06-13 |
4603 | Bypassing Hotstar Premium with DOM manipulation and some JavaScript |
Logic flaw
Payment bypass |
Hotstar |
OpSecX (@OpSecX) |
Bug Bounty | 2018-09-07 | 2023-06-13 |
4579 | Facebook $750 Reward for a Simple Bug |
Authentication bypass
Logic flaw |
Meta / Facebook |
Aman Shahid (@amansmughal) |
Bug Bounty | 2018-09-18 | 2023-06-13 |
4573 | Bypassing Firebase authorization to create custom goo.gl subdomains |
Logic flaw
IDOR |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2018-09-21 | 2023-06-13 |