3208 | Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties |
Hardcoded API keys
Information disclosure |
Google |
Abss (@absshax) |
Bug Bounty | 2020-08-17 | 2023-06-13 |
3204 | How to contact Google SRE: Dropping a shell in cloud SQL |
SQL injection
Privilege escalation
Parameter injection
RCE |
Google |
wtm@offensi.com (@wtm_offensi) |
Bug Bounty | 2020-08-18 | 2023-06-13 |
3189 | Auth bypass: Leaking Google Cloud service accounts and projects |
Authentication bypass |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2020-08-26 | 2023-06-13 |
3179 | Cloud firewall management API SNAFU put 500k SonicWall customers at risk |
IDOR |
SonicWall |
Vangelis Stykas (@evstykas) |
Bug Bounty | 2020-09-02 | 2023-06-13 |
3147 | Cross-tenant Cloud Function compromise via storage bucket squatting |
Cross-tenant vulnerability |
Google |
Anthony Weems |
Bug Bounty | 2020-09-20 | 2023-06-13 |
3128 | Public Bucket Allowed Access to Images on Upcoming Google Cloud Blog Posts |
GCP bucket misconfiguration
Information disclosure
Cloud |
Google |
Thomas Orlita (@ThomasOrlita) |
Bug Bounty | 2020-09-29 | 2023-06-13 |
3124 | Write Up – Google Bug Bounty: XSS To Cloud Shell Instance Takeover (Rce As Root) – $5,000 USD |
XSS
RCE |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2020-10-01 | 2023-06-13 |
3108 | Kud I Enter Your Server? New Vulnerabilities in Microsoft Azure |
Privilege escalation
RCE
Cloud |
Microsoft |
Intezer |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3043 | 31k$ SSRF in Google Cloud Monitoring led to metadata exposure |
SSRF |
Google |
David Nechuta (@david_nechuta) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3004 | SD-PWN Part 4 — VMware VeloCloud — The Last Takeover |
RCE
Authentication bypass
Default credentials
SQL injection
Path traversal
LFI |
VMware |
Realmode Labs (@RealmodeLabs) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2923 | Nick%27s infrequently updated blog |
WAF bypass
IP spoofing |
Cloudflare |
Nick Booher |
Bug Bounty | 2021-01-06 | 2023-06-13 |
2902 | Making Clouds Rain :: Remote Code Execution in Microsoft Office 365 |
RCE |
Microsoft |
Steven Seeley (@steventseeley) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2860 | How We Escaped Docker in Azure Functions |
Privilege escalation
Cloud |
Microsoft |
Intezer |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2807 | Stored XSS in icloud.com — $5000 |
Stored XSS |
NA |
Vishal Bharad |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2800 | I Own your Cloud Shell: Taking over “Azure Cloud Shell” Kubernetes Cluster Through Unsecured Kubelet API 30,000$ Bounty |
Privilege escalation
RCE |
Microsoft |
Chen Cohen (@chencococococo) |
Bug Bounty | 2021-02-15 | 2023-06-13 |
2796 | Dropping a shell in Google’s Cloud SQL (the speckle-umbrella story) |
Configuration file injection
RCE |
Google |
Imre Rad (@ImreRad) |
Bug Bounty | 2021-02-16 | 2023-06-13 |
2730 | Write Up – Google VRP N/A: SSRF Bypass With Quadzero In Google Cloud Monitoring |
SSRF |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-03-08 | 2023-06-13 |
2688 | How to bypass CloudFlare bot protection ? |
Logic flaw |
Cloudflare |
jychp (@jychp_fr) |
Bug Bounty | 2021-03-27 | 2023-06-13 |
2659 | Cloud Based Storage Misconfigurations -> Critical Bounties |
Cloud storage misconfiguration |
NA |
Mikey (@mikey96_bh) |
Bug Bounty | 2021-04-05 | 2023-06-13 |
2641 | How I got 9000 USD by hacking into iCloud |
XSS |
Apple |
Alexandre Fernandes (@fernale) |
Bug Bounty | 2021-04-15 | 2023-06-13 |
2640 | Allow arbitrary URLs, expect arbitrary code execution |
RCE |
Nextcloud
Telegram
VLC |
Fabian Bräunlein |
Bug Bounty | 2021-04-15 | 2023-06-13 |
2485 | [Google VRP] Privilege escalation on https://dialogflow.cloud.google.com |
Authorization flaw
Logic flaw |
Google |
lalka (@0x01alka) |
Bug Bounty | 2021-06-13 | 2023-06-13 |
2483 | An exciting journey to find SSRF , Bypass Cloudflare , and extract AWS metadata ! |
SSRF |
NA |
hosein vita (@HoseinVita) |
Bug Bounty | 2021-06-13 | 2023-06-13 |
2461 | How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It |
Account takeover
MFA bypass
Rate limiting bypass
Race condition |
Apple |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-06-19 | 2023-06-13 |