2864 | $500 For No Rate Limit On Forgot Password Page |
Lack of rate limiting
Password reset |
NA |
BBHC (@community_bug) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2778 | Is Math.random() Safe? from missing rate limit to bypass 2fa and possible sqli |
Race condition
Lack of rate limiting
OTP bypass
SQL injection |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-20 | 2023-06-13 |
2699 | OTP brute-force via rate limit bypass |
Bruteforce
Lack of rate limiting
OTP bypass |
NA |
Bilal Muqeet (@blmqt) |
Bug Bounty | 2021-03-21 | 2023-06-13 |
2225 | 10 golden minutes for taking over a Chess.com account |
Lack of rate limiting
Bruteforce
Session expiration issue |
Chess.com |
Seqrity (@seqrity9) |
Bug Bounty | 2021-09-14 | 2023-06-13 |
2208 | Unlimited report user in Instagram (Facebook) leads to abuse risk. |
Lack of rate limiting |
Meta / Facebook |
Mano Prasanth |
Bug Bounty | 2021-09-20 | 2023-06-13 |
2085 | chaining improper authentication to idor and no rate limit for mass account takeover |
Account takeover
Lack of rate limiting
CSRF
IDOR |
NA |
mohit (@mohit29295572) |
Bug Bounty | 2021-11-12 | 2023-06-13 |
2024 | How I managed to hack User accounts of a billion-dollar sport platform |
OTP bypass
Bruteforce
Lack of rate limiting |
NA |
Vishnuraj |
Bug Bounty | 2021-12-04 | 2023-06-13 |
1973 | Massive Users Account Takeovers(Chaining Vulnerabilities to IDOR)😲 |
Authentication bypass
IDOR
Lack of rate limiting |
NA |
Anurag__Verma |
Bug Bounty | 2021-12-25 | 2023-06-13 |
1894 | How I was able to take over accounts in websites deal with Github as an SSO provider |
Bruteforce
Lack of rate limiting
SSO
Email verification bypass
Account takeover |
NA |
Khaled Mohamed |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1871 | Missing rate-limiting. How I was able to add any unowned phone number to my Facebook account? (Bounty: 5000 USD) |
OTP bruteforce
Lack of rate limiting |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2022-01-31 | 2023-06-13 |
1863 | No Rate Limiting on OTP sending |
Bruteforce
Lack of rate limiting |
NA |
nOOb_mAsTeR |
Bug Bounty | 2022-02-02 | 2023-06-13 |
1843 | What I Found on Sony Vulnerability Disclosure Program |
Information disclosure
Lack of rate limiting
Open redirect
IDOR
XSS |
Sony |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-02-07 | 2023-06-13 |
1749 | Rate Limit Bypass at Readme.com |
Lack of rate limiting
Password reset |
Readme.com |
Girishbo |
Bug Bounty | 2022-03-11 | 2023-06-13 |
1586 | ATO without any interaction [aws cognito misconfiguration] |
Account takeover
Lack of rate limiting |
GitHub |
Shreyaskoli (@SPY8OY) |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1442 | Exploiting vulnerabilities in iOS Application |
IDOR
Bruteforce
Lack of rate limiting
Account takeover
iOS |
NA |
Raj Singh Chauhan (@raj_singh_ch) |
Bug Bounty | 2022-06-22 | 2023-06-13 |
1391 | PII Disclosure of Apple Users ($10k) |
IDOR
Lack of rate limiting
Bruteforce
Information disclosure |
Apple |
Ahmad Halabi (@Ahmad_Halabi_) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1362 | Exploiting Arbitrary Object Instantiations in PHP without Custom Classes |
Lack of rate limiting
Privilege escalation
IDOR
Account takeover |
NA |
Muhammad Talha / evilmango |
Bug Bounty | 2022-07-15 | 2023-06-13 |
1096 | How I found 3 rare security bug in a day |
Session expiration issue
Payment bypass
Lack of rate limiting |
NA |
zer0d |
Bug Bounty | 2022-09-10 | 2023-06-13 |
906 | GL.iNET GL-MT300N-V2 Router Vulnerabilities and Hardware Teardown |
OS command injection
Arbitrary file read
Information disclosure
Account takeover
Stored XSS
Lack of rate limiting
Weak credentials
Password policy bypass |
GL.iNet |
Olivier Laflamme (@olivier_boschko) |
Bug Bounty | 2022-10-26 | 2023-06-13 |
800 | My Account Takeover Writeup: $5000 |
Lack of rate limiting
Bruteforce |
NA |
MRD7 (@_mrd7_) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
727 | [BAC/IDOR] How my father credit card help me to find this access control issue |
IDOR
Lack of rate limiting |
NA |
Xcoder(Joy ahmed) (@xcoder074) |
Bug Bounty | 2022-12-05 | 2023-06-13 |
704 | How I became a millionaire in 3h | Fintech Bug Bounty — Part 1 |
IDOR
Lack of rate limiting
Logic flaw |
NA |
0x4KD (@0x4kd) |
Bug Bounty | 2022-12-12 | 2023-06-13 |
381 | My First Un-Expected $$$$ Digit Bounty for an Un-Expected Vulnerability |
Lack of rate limiting
Bruteforce |
NA |
Shobhit Mehta |
Bug Bounty | 2023-02-28 | 2023-06-13 |