3303 | The 3 Day Account Takeover |
Logic flaw
Password reset
Account takeover
Bruteforce
Lack of rate limiting |
NA |
Mr. Beast (@__mr_beast__) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3280 | How I bypassed 2fa in a 3 years old private program! |
MFA bypass
Bruteforce
Lack of rate limiting |
NA |
Shivangx01b (@shivangx01b) |
Bug Bounty | 2020-07-26 | 2023-06-13 |
2922 | Finding bugs on Chess.com |
Lack of rate limiting
Bruteforce
CSRF |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2866 | BMW Bug Bounty – Account Verification Bypass writeup |
OTP bypass
Bruteforce
Lack of rate limiting |
BMW |
Pethuraj (@Pethuraj) |
Bug Bounty | 2021-01-26 | 2023-06-13 |
2849 | An unexpected bug |
Bruteforce |
NA |
Nitin yadav (@Nitinydv14) |
Bug Bounty | 2021-01-31 | 2023-06-13 |
2745 | How I Might Have Hacked Any Microsoft Account |
Account takeover
Password reset
Bruteforce
MFA bypass |
Microsoft |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-03-02 | 2023-06-13 |
2699 | OTP brute-force via rate limit bypass |
Bruteforce
Lack of rate limiting
OTP bypass |
NA |
Bilal Muqeet (@blmqt) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2591 | Password reset code brute-force vulnerability in AWS Cognito |
Password reset
Bruteforce
Rate limiting bypass
Account takeover |
AWS |
Pentagrid (@pentagridsec) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2424 | Facebook Email/phone disclosure using Binary search |
Password reset
Information disclosure
Bruteforce |
Meta / Facebook |
Rikesh Baniya / NotRickyy (@rikeshbaniya) |
Bug Bounty | 2021-07-09 | 2023-06-13 |
2225 | 10 golden minutes for taking over a Chess.com account |
Lack of rate limiting
Bruteforce
Session expiration issue |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2127 | How I was able to revoke your Instagram 2FA |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Dhiyaneshwaran (@DhiyaneshDK) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2024 | How I managed to hack User accounts of a billion-dollar sport platform |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2021-12-04 | 2023-06-13 |
1966 | Bounty Evaluation GitHub = $15,000 US Dollars | Rate Limit |
Bruteforce
Email verification bypass
Account takeover |
GitHub |
Taniya Agarwal |
Bug Bounty | 2021-12-28 | 2023-06-13 |
1894 | How I was able to take over accounts in websites deal with Github as an SSO provider |
Bruteforce
Lack of rate limiting
SSO
Email verification bypass
Account takeover |
NA |
Khaled Mohamed |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1871 | Missing rate-limiting. How I was able to add any unowned phone number to my Facebook account? (Bounty: 5000 USD) |
OTP bruteforce
Lack of rate limiting |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2022-01-31 | 2023-06-13 |
1863 | No Rate Limiting on OTP sending |
Bruteforce
Lack of rate limiting |
NA |
nOOb_mAsTeR |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1789 | Write Up – Android Application Screen Lock Bypass Via ADB Brute Forcing |
Android
Bruteforce
Authentication bypass |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2022-02-22 | 2023-06-13 |
1442 | Exploiting vulnerabilities in iOS Application |
IDOR
Bruteforce
Lack of rate limiting
Account takeover
iOS |
NA |
Raj Singh Chauhan (@raj_singh_ch) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1391 | PII Disclosure of Apple Users ($10k) |
IDOR
Lack of rate limiting
Bruteforce
Information disclosure |
Apple |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1365 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
RCE
Arbitrary Object Instantiation
Bruteforce
LDAP injection |
NA |
Arseniy Sharoglazov (@_mohemiv) |
Bug Bounty | 2022-07-14 | 2023-06-13 |
1234 | An Unusual Tale of Email Verification Bypass |
Email verification bypass
Bruteforce
Rate limiting bypass |
NA |
Sagar Sajeev (@Sagar__Sajeev) |
Bug Bounty | 2022-08-13 | 2023-06-13 |
1028 | Discovering The Less-known Vulnerability In Oracle Peoplesoft |
TockenChpoken
Privilege escalation
Bruteforce
Cookie manipulation |
NA |
RE:HACK (@rehackxyz) |
Bug Bounty | 2022-09-26 | 2023-06-13 |
800 | My Account Takeover Writeup: $5000 |
Lack of rate limiting
Bruteforce |
NA |
MRD7 (@_mrd7_) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
540 | Ransacking your password reset tokens |
Account takeover
Password reset
Bruteforce |
Ransack library |
Lukas Euler |
Bug Bounty | 2023-01-26 | 2023-06-13 |