Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
4854How I hacked Tinder accounts using Facebook’s Account Kit and earned $6,250 in bounties Account takeover Authorization flaw Tinder Meta / Facebook Anand Prakash (@anandpraka_sh) Bug Bounty2018-02-202023-06-13
4841Facebook Bug Bounty Reports Authorization flaw Logic flaw Information disclosure Meta / Facebook Raushan Raj (@raushan_rajj) Bug Bounty2018-03-062023-06-13
4837How I hacked 74k users of a website. Authorization flaw NA Utkarsh Agrawal (@agrawalsmart7) Bug Bounty2018-03-112023-06-13
4819Facebook BugBounty: Intercept incoming friend requests of Victim add/accept to your facebook account Authorization flaw Meta / Facebook Family guy Bug Bounty2018-04-022023-06-13
4810Source Code Analysis in YSurvey — Luminate bug Authentication bypass Authorization flaw SQL injection Yahoo! / Verizon Media Rojan Rijal (@uraniumhacker) Bug Bounty2018-04-102023-06-13
4809How I broke into Google Issue Tracker Logic flaw Authorization flaw Google Abhishek Bundela (@abhibundela) Bug Bounty2018-04-102023-06-13
4805How I hacked companies related to the crypto currency and earned $60,000 Authorization flaw CSRF IDOR Stored XSS HTML injection okex.com livecoin.net Max (@0xw2w) Bug Bounty2018-04-142023-06-13
4792Bypassing the Current Password Protection at PayPal TechSupport Portal Authorization flaw Account takeover Paypal YoKo Kho (@YokoAcc) Bug Bounty2018-04-192023-06-13
4782Bypassing the Confirmation Email for Newsletter (bof.nl) Authorization flaw IDOR Bits of Freedom Mohammed Israil (@mdisrail2468) Bug Bounty2018-04-262023-06-13
4771Asus Control Center – An Information Disclosure and a database connection Clear-Text password leakage Vulnerability Authorization flaw Information disclosure Asus Mohamed A. Baset Bug Bounty2018-05-082023-06-13
4769How I used a simple Google query to mine passwords from dozens of public Trello boards Authorization flaw Information disclosure Trello Kushagra Pathak (@xKushagra) Bug Bounty2018-05-092023-06-13
4757AWS Security Flaw which can grant admin access! Authorization flaw Amazon Sharath AV Bug Bounty2018-05-222023-06-13
4717Using a GitHub app to escalate to an organization owner for a $10,000 bounty Authorization flaw IDOR GitHub Tanner Emek (@itscachemoney) Bug Bounty2018-06-202023-06-13
4708This popular Facebook app publicly exposed your data for years Information disclosure Authorization flaw Meta / Facebook Nametests.com Inti De Ceukelaire (@securinti) Bug Bounty2018-06-282023-06-13
4689Bypass Admin approval, Mute Member and Posting Permissions for Only admins in Facebook groups Authorization flaw Logic flaw Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-07-182023-06-13
4655Unauth meetings access Authorization flaw Logic flaw Google Rojan Rijal (@uraniumhacker) Bug Bounty2018-08-062023-06-13
4654FakesApp: A Vulnerability in WhatsApp Content spoofing Authorization flaw Privacy issue Meta / Facebook Dikla Barda Bug Bounty2018-08-072023-06-13
4643[Twitter Bug Bounty] Misconfigured JSON endpoint on ads.twitter.com lead to Access control issue and Information Disclosure of role privileged users. Authorization flaw Information disclosure Twitter Peerzada Fawaz Ahmad Qureshi Bug Bounty2018-08-102023-06-13
4638Distorted and Undeletable Posts in Facebook Group Authorization flaw Logic flaw Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-08-122023-06-13
4630https://www.updatelap.com/2018/08/privileged-escalation-in-facebook-rooms.html Authorization flaw Privilege escalation Meta / Facebook Jafar Abo Nada (@Jafar_Abo_Nada) Bug Bounty2018-08-182023-06-13
4610Facebook Bug Bounty! {Permission Bug} Authorization flaw Logic flaw Meta / Facebook Ali Tütüncü (@alicanact60) Bug Bounty2018-09-052023-06-13
4575Shopify Athena Bug Authorization flaw Information disclosure Shopify Rojan Rijal (@uraniumhacker) Bug Bounty2018-09-202023-06-13
4570Responsible disclosure: retrieving a user%27s private Facebook friends. Logic flaw Authorization flaw Information disclosure Meta / Facebook Riccardo Padovani (@rpadovani93) Bug Bounty2018-09-232023-06-13
4560Hacking the Subway Android app Logic flaw Authorization flaw Subway Wesley Gahr (@wesley_gahr) Bug Bounty2018-09-282023-06-13
4541Make any Unit in Facebook Groups Undeletable Logic flaw IDOR Authorization flaw Meta / Facebook Sarmad Hassan (@JubaBaghdad) Bug Bounty2018-10-092023-06-13