2489 | Bypassing 2FA using OpenID Misconfiguration |
MFA bypass
Authentication flaw |
NA |
Youstin (@iustinBB) |
Bug Bounty | 2021-06-11 | 2023-06-13 |
2461 | How I Found A Vulnerability To Hack iCloud Accounts and How Apple Reacted To It |
Account takeover
MFA bypass
Rate limiting bypass
Race condition |
Apple |
Laxman Muthiyah (@laxmanmuthiyah) |
Bug Bounty | 2021-06-19 | 2023-06-13 |
2272 | Bypassing 2-Factor Authentication for Facebook Business Manager (Bounty: 1000 USD) |
MFA bypass |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2021-08-31 | 2023-06-13 |
2029 | Bypassing Box’s Time-based One-Time Password MFA |
OTP bypass
MFA bypass |
Box |
Tal Peleg |
Bug Bounty | 2021-12-02 | 2023-06-13 |
1983 | How I earned $$$ by bypassing 2FA |
MFA bypass
Forced browsing |
NA |
Mohamed Taha (@Mohamed12742780) |
Bug Bounty | 2021-12-21 | 2023-06-13 |
1933 | 2FA bypass by reading the documentation |
MFA bypass |
NA |
tomorrowisnew (@tomorrowisnew_) |
Bug Bounty | 2022-01-09 | 2023-06-13 |
1910 | Mixed Messages: Busting Box’s MFA Methods |
OTP bypass
MFA bypass |
Box |
Tal Peleg |
Bug Bounty | 2022-01-18 | 2023-06-13 |
1876 | 2fa Bypass by changing Request method |
MFA bypass |
NA |
Arth Bajpai (@arth_bajpai) |
Bug Bounty | 2022-01-30 | 2023-06-13 |
1825 | A tale of 0-Click Account Takeover and 2FA Bypass. |
Account takeover
Password reset
MFA bypass |
NA |
Firas Fatnassi (@Fatnass1F1ras) |
Bug Bounty | 2022-02-12 | 2023-06-13 |
1792 | How I could’ve bypassed the 2FA security of Instagram once again? |
MFA bypass
Logic flaw |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2022-02-21 | 2023-06-13 |
1630 | Threat Evasion for aws:multifactorAuthPresent condition using Cloudshell |
MFA bypass |
AWS |
Falcnix (@falcnix) |
Bug Bounty | 2022-04-13 | 2023-06-13 |
1602 | How I Bypassed 2FA while Resetting Password |
MFA bypass
Password reset |
NA |
Sufiyan Gouri (@gouri_sufyan) |
Bug Bounty | 2022-04-23 | 2023-06-13 |
1592 | 2FA Secret value disclosure leads to 2FA Bypass - Bug Bounty Writeup |
MFA bypass
Information disclosure |
NA |
Aditya Singh / rook1337 (@imrook1337) |
Bug Bounty | 2022-04-28 | 2023-06-13 |
1531 | 2FA Bypass on private bug bounty program due to CSRF token misconfiguration |
MFA bypass |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1530 | 2FA Bypass on private bug bounty program due to improper caching mechanism |
MFA bypass |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-05-22 | 2023-06-13 |
1507 | Abusing Facebook’s feature for a permanent account confusion(logic vulnerability) |
MFA bypass
DoS
Logic flaw |
Meta / Facebook |
Liv |
Bug Bounty | 2022-05-31 | 2023-06-13 |
1466 | 2FA Bypass via Basic Authentication on private bug bounty program |
MFA bypass |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-06-14 | 2023-06-13 |
1390 | Account Takeover via Response Manipulation |
Authentication bypass
Account takeover
MFA bypass
HTTP response manipulation |
NA |
BUG HUNTER |
Bug Bounty | 2022-07-08 | 2023-06-13 |
1271 | 2FA Bypass via Google Identity & OAuth Login |
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-08-07 | 2023-06-13 |
1214 | 2FA Bypass Do Re Mi |
MFA bypass |
NA |
Ashlyn Lau (@ashlyn_lau) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1153 | mfa bypass in private program, the abdulsec way |
MFA bypass |
NA |
abdulsec (@moodiAbdoul) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1004 | My First And Second Bugs Are — 2FA Bypass |
MFA bypass
HTTP response manipulation
Information disclosure |
NA |
Jai Niresh J |
Bug Bounty | 2022-10-03 | 2023-06-13 |
885 | 2FA Bypass due to information disclosure & Improper access control. |
DoS
MFA bypass |
NA |
Akash Hamal (@AkashHamal0x01) |
Bug Bounty | 2022-10-31 | 2023-06-13 |
768 | Access Any Owner Account without Authentication (Auth bypass + 2FA bypass) |
Authentication bypass
MFA bypass
Account takeover |
NA |
Sharat Kaikolamthuruthil (@sharp488) |
Bug Bounty | 2022-11-27 | 2023-06-13 |
664 | 0 click Facebook Account Takeover and Two-Factor Authentication Bypass |
Authentication bypass
GraphQL
Account takeover
Android
MFA bypass |
Meta / Facebook |
abdellah yaala (@yaalaab) |
Bug Bounty | 2022-12-21 | 2023-06-13 |