3648 | Mail.Ru Ext.B Scope Account Takeover [ $1500 ] |
Account takeover
OAuth |
Mail.ru |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-02-25 | 2023-06-13 |
3364 | How i hacked worldwide ZOOM users |
OAuth
Account takeover |
Zoom |
s3c (@s3c_krd) |
Bug Bounty | 2020-06-27 | 2023-06-13 |
3274 | Pre-Access to Victim’s Account via Facebook Signup |
OAuth
Account takeover |
NA |
Akshansh Jaiswal (@Akshanshjaiswl) |
Bug Bounty | 2020-07-28 | 2023-06-13 |
3251 | Vulnerability in new TouchID feature put iCloud accounts at risk of being breached |
OAuth
Account takeover |
Apple |
Thijs Alkemade (@xnyhps) |
Bug Bounty | 2020-08-03 | 2023-06-13 |
3173 | Never Give Up, The Story Behind a Dupe-To-Triaged |
XSS
OAuth
Account takeover |
NA |
Alan Brian (@soyelmago) |
Bug Bounty | 2020-09-06 | 2023-06-13 |
3131 | 5 Ways to do Account Takeover in a Single Website |
Account takeover
Lack of rate limiting
OTP bypass
IDOR
OAuth
JWT |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3062 | An often overlooked Oauth misconfiguration. |
OAuth |
NA |
VipItHunter (@VipItHunter1) |
Bug Bounty | 2020-11-01 | 2023-06-13 |
3059 | CVE-2020-13294 |
Authentication flaw
OpenID Connect
OAuth |
GitLab |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2020-11-01 | 2023-06-13 |
3052 | Story of a Pre-Account Takeover |
Account takeover
OAuth |
NA |
Kushal Dhakal (@dhakal0kushal) |
Bug Bounty | 2020-11-06 | 2023-06-13 |
3014 | Bypassing the Redirect filters with 7 ways |
Open redirect
OAuth |
NA |
ElMahdi Mrhassel (@ElMrhassel) |
Bug Bounty | 2020-11-19 | 2023-06-13 |
3003 | Pre-Account Takeover using OAuth Misconfiguration |
OAuth |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2814 | OAuth Misconfiguration Leads to Full Account takeover |
OAuth
Clickjacking
CSRF
Account takeover |
NA |
Yasser Mohammed (@boomneroli) |
Bug Bounty | 2021-02-13 | 2023-06-13 |
2701 | OAuth Misconfiguration found in small time-window of attack |
OAuth |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-03-20 | 2023-06-13 |
2616 | Got Nice catch by Google |
OAuth
Open redirect
CSRF |
Google |
Parth Desani (@DesaniParth) |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2592 | Facebook account takeover due to unsafe redirects after the OAuth flow |
OAuth
Open redirect
Account takeover |
Meta / Facebook |
Youssef Sammouda (@samm0uda) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2523 | How I hacked a Target again and again… |
OAuth
Account takeover
XSS
Broken Access Control |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2021-05-27 | 2023-06-13 |
2383 | Mattermost Server v5.32 > v5.36 Reflected XSS in OAuth flow |
Reflected XSS
OAuth |
Mattermost |
zi0Black (@zi0Black) |
Bug Bounty | 2021-07-26 | 2023-06-13 |
2375 | Information Disclosure to Account Takeover |
Information disclosure
OAuth
Account takeover
Authentication bypass |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-07-28 | 2023-06-13 |
2372 | How I could have hacked your medium account by phishing your FB, Twitter & Google credentials. |
Open redirect
OAuth |
Medium |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-07-29 | 2023-06-13 |
2290 | Oauth client secret leak and possible IDOR leading to PII Disclosure |
IDOR
OAuth
Information disclosure |
NA |
Monke (@pmofcats) |
Bug Bounty | 2021-08-26 | 2023-06-13 |
2219 | This is why you shouldn’t trust your Federated Identity Provider |
OAuth
Account takeover
Authentication bypass |
NA |
Soufiane Habti (@wld_basha) |
Bug Bounty | 2021-09-15 | 2023-06-13 |
2098 | Insufficient Redirect URI validation: The risk of allowing to dynamically add arbitrary query parameters and fragments to the redirect_uri |
OAuth
Prototype pollution |
GitHub
Microsoft
StackExchange |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2021-11-06 | 2023-06-13 |
2063 | Exploiting OAuth: Journey to Account Takeover |
Account takeover
OAuth
XSS
Weak CSP
CSRF |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2021-11-19 | 2023-06-13 |
1958 | Bypassing Identity-Aware Proxy - Google Cloud Vulnerability |
Authorization flaw
Token leak
OAuth |
Google |
SebLu |
Bug Bounty | 2021-12-30 | 2023-06-13 |