2493 | Author spoofing in Google Colaboratory |
Logic flaw |
Google |
Zohar Shachar |
Bug Bounty | 2021-06-09 | 2023-06-13 |
2174 | A short story of Content Spoofing to HTML Injection in Apple using Dangling Markup Injection |
HTML injection
Dangling Markup Injection |
Apple |
Rishu Ranjan (@tweetit_rrj) |
Bug Bounty | 2021-10-03 | 2023-06-13 |
1977 | MS Teams: 1 feature, 4 vulnerabilities |
SSRF
Information disclosure
DoS
Spoofing |
Microsoft |
Fabian Bräunlein |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1938 | Authorization bypass — Gmail |
Spoofing |
Google |
7𝖍3𝖍4𝖈kv157 (@7h3h4ckv157) |
Bug Bounty | 2022-01-06 | 2023-06-13 |
1842 | Google Security Misconfiguration Leads to Account Takeover ! |
Logic flaw
Spoofing |
Google |
Harsh Banshpal |
Bug Bounty | 2022-02-08 | 2023-06-13 |
1831 | Microsoft Team’s Unpatched URL Spoofing Vulnerability |
URL spoofing |
Microsoft |
Priyank Raval |
Bug Bounty | 2022-02-09 | 2023-06-13 |
1678 | A Large-scale and Longitudinal Measurement Study of DKIM Deployment |
Email spoofing
Phishing |
Google
Mailchimp
Sendgrid
Salesforce |
Chuhan Wang |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1675 | Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpoint |
Endpoint spoofing |
Microsoft |
Gijs Hollestelle |
Bug Bounty | 2022-04-01 | 2023-06-13 |
1662 | Spoof as another Facebook user to report an impostor account |
Spoofing |
Meta / Facebook |
Syd Ricafort (@devsyd11) |
Bug Bounty | 2022-04-05 | 2023-06-13 |
1587 | Page Admin Disclosure when Posting a Reel |
Spoofing |
Meta / Facebook |
Syd Ricafort (@devsyd11) |
Bug Bounty | 2022-04-30 | 2023-06-13 |
1559 | Spoofing SaaS Vanity URLs for Social Engineering Attacks |
URL spoofing |
Box
Zoom
Google |
Tal Peleg |
Bug Bounty | 2022-05-11 | 2023-06-13 |
1525 | Spoofing Microsoft 365 Like It’s 1995 |
Spoofing
Phishing |
Microsoft |
Steve Borosh (@424f424f) |
Bug Bounty | 2022-05-24 | 2023-06-13 |
1318 | Mail Server Misconfiguration leads to sending a fax from anyone’s account on HelloFax (Dropbox BBP) for a bounty of $4,913 |
Email spoofing |
Dropbox |
Sayaan Alam (@ehsayaan) |
Bug Bounty | 2022-07-25 | 2023-06-13 |
1308 | CVE-2022-31813: Forwarding Addresses Is Hard |
Host header injection
DoS
IP address spoofing |
Internet Bug Bounty (Apache HTTPD) |
Gaetan Ferry (@_mabote_) |
Bug Bounty | 2022-07-26 | 2023-06-13 |
1303 | SSD Advisory – Apple Safari IDN URL Spoofing |
URL spoofing |
Apple |
Dohyun Lee (@l33d0hyun) |
Bug Bounty | 2022-07-27 | 2023-06-13 |
1147 | Abusing Microsoft Teams Direct Routing |
Spoofing
Fraud attack |
AudioCodes Ltd. |
Moritz Abrell (@moritz_abrell) |
Bug Bounty | 2022-09-01 | 2023-06-13 |
909 | Support supports a Hacker |
Social engineering
Spoofing
Authorization flaw
Account takeover |
NA |
mechboy (@mechboy_) |
Bug Bounty | 2022-10-25 | 2023-06-13 |
798 | Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs |
GraphQL
Security misconfiguration |
Meta / Facebook |
David Schütz (@xdavidhu) |
Bug Bounty | 2022-11-21 | 2023-06-13 |
784 | From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942) |
Authentication bypass
Kerberos
RCE
Privilege escalation
Security code review |
Intel |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2022-11-23 | 2023-06-13 |
758 | VoIP Spoofing (Intigriti) 1,250€ |
VoIP
Spoofing |
NA |
0xJin (@0xJin) |
Bug Bounty | 2022-11-29 | 2023-06-13 |
543 | Exploiting a Critical Spoofing Vulnerability in Windows CryptoAPI |
Windows
Cryptographic issues |
Microsoft |
Tomer Peled |
Bug Bounty | 2023-01-25 | 2023-06-13 |
408 | Exploit Airlines that use T-Mobile for Free WiFi |
Wifi
Payment bypass
MAC address spoofing
Missing authentication |
T-Mobile |
cylect.io (@cylect_io) |
Bug Bounty | 2023-02-23 | 2023-06-13 |
298 | IP spoofing and SQL injection in Textcube |
SQL injection
IP spoofing
HTTP header attack
Security code review |
Textcube |
Sjoerd Langkemper |
Bug Bounty | 2023-03-15 | 2023-06-13 |
186 | Impersonating Other Players with UDP Spoofing in Mirror |
Game hacking
UDP spoofing
Reverse engineering |
Unity (Mirror) |
IncludeSec (@IncludeSecurity) |
Bug Bounty | 2023-04-18 | 2023-06-13 |
157 | New high-severity vulnerability (CVE-2023-29552) discovered in the Service Location Protocol (SLP) |
DoS
UDP spoofing |
Service Location Protocol (SLP) |
Pedro Umbelino |
Bug Bounty | 2023-04-25 | 2023-06-13 |