3115 | 90 days, 16 bugs, and an Azure Sphere Challenge |
Local privilege escalation
RCE
DoS
Information disclosure |
Microsoft |
Cisco Talos |
Bug Bounty | 2020-10-06 | 2023-06-13 |
3072 | Story of an interesting bug. |
Lack of rate limiting
DoS |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-10-28 | 2023-06-13 |
2951 | Cookie Tossing to RCE on Google Cloud JupyterLab |
Self-XSS
DoS
CSRF
RCE |
Google |
s1r1us (@s1r1u5_) |
Bug Bounty | 2020-12-23 | 2023-06-13 |
2944 | Regular expression injection, a code review low hanging fruit |
ReDoS |
NA |
Dominic (@dee__see) |
Bug Bounty | 2020-12-27 | 2023-06-13 |
2939 | Cache-Key Normalization - What could go wrong? |
Web cache poisoning
DoS |
NA |
Youstin (@iustinBB) |
Bug Bounty | 2020-12-29 | 2023-06-13 |
2934 | Facebook bug bounty (500 USD) : A blocked fundraiser organizer would be unable to view or remove themselves from the fundraiser. |
DoS
Logic flaw |
Meta / Facebook |
Vivek ps (@vivekps143) |
Bug Bounty | 2020-12-31 | 2023-06-13 |
2928 | Exploiting Max. Character Limitation |
Logic flaw
DoS |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-05 | 2023-06-13 |
2815 | [GITLAB] — Denial of service via “Login Panel” functionality. |
Application-level DoS |
GitLab |
Lyubomir Tsirkov (@lyubo_tsirkov) |
Bug Bounty | 2021-02-12 | 2023-06-13 |
2797 | Hunting for bugs in Telegram%27s animated stickers remote attack surface |
Memory corruption
DoS |
Telegram |
polict (@polict_) |
Bug Bounty | 2021-02-16 | 2023-06-13 |
2652 | Cookie poisoning leads to DoS and Privacy Violation |
DoS
SSRF |
CS Money |
Benjamin Walter |
Bug Bounty | 2021-04-09 | 2023-06-13 |
2615 | Telegram bug bounties: XSS, privacy issues, official bot exploitation and more… |
XSS
Authorization flaw
DoS |
NA |
Davide |
Bug Bounty | 2021-04-22 | 2023-06-13 |
2544 | DOS & Stored HTML Injection Bug Bounty Writeup |
DoS
HTML injection |
NA |
RiotSecurityTeam (@RiotSecTeam) |
Bug Bounty | 2021-05-19 | 2023-06-13 |
2519 | The beauty of chaining client-side bugs |
CRLF injection
XSS
CSP bypass
DoS
CSTI |
NA |
Master SEC (@MasterSEC_AR) |
Bug Bounty | 2021-05-29 | 2023-06-13 |
2475 | One-click DOS via Response Manipulation |
Logic flaw |
NA |
Akhil |
Bug Bounty | 2021-06-16 | 2023-06-13 |
2471 | Crashing your LinkedIn app with a connection request. |
Application-level DoS |
LinkedIn |
Renganathan (@IamRenganathan) |
Bug Bounty | 2021-06-17 | 2023-06-13 |
2453 | MSRC is confused! 😕 |
Dependency confusion |
Microsoft |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2021-06-24 | 2023-06-13 |
2419 | Pre-Denial Of Service (set-up 2FA on unverified account) |
Application-level DoS |
NA |
Vikash Maurya |
Bug Bounty | 2021-07-11 | 2023-06-13 |
2379 | Telegram Report: SSRF leads to DOS attack [Reports that didn%27t make it] |
SSRF
DoS |
Telegram |
Philippe Delteil (@PhilippeDelteil) |
Bug Bounty | 2021-07-27 | 2023-06-13 |
2369 | Google Bug Bounty: $500 worth client-side DoS on Google Keep |
Application-level DoS |
Google |
Tommaso De Ponti (@heytdep) |
Bug Bounty | 2021-07-30 | 2023-06-13 |
2332 | Weaponizing Middleboxes for TCP Reflected Amplification |
DoS |
Check Point
Cisco
F5
Fortinet
Juniper
Netscout
Palo Alto
SonicWall
Sucuri |
Kevin Bock |
Bug Bounty | 2021-08-12 | 2023-06-13 |
2263 | Breaking Application’s Logic to DOS Attack |
IDOR
DoS |
NA |
Abhijeet Singh (@abhiunix) |
Bug Bounty | 2021-09-02 | 2023-06-13 |
2155 | Hacking YouTube With MP4 |
Logic flaw
DoS |
Google |
KeyboardWarrior (@Keyb0ardWarr10r) |
Bug Bounty | 2021-10-11 | 2023-06-13 |
2109 | This is how i was able to Permanently Crash all Mapillary users within minutes |
Application-level DoS |
Meta / Facebook |
Abhishek Pathak (@pathleax) |
Bug Bounty | 2021-10-31 | 2023-06-13 |
2077 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-15 | 2023-06-13 |
2074 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS
Logic flaw |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |