4060 | Story of a stored xss to full account takeover vulnerability(N/A to accepted) |
Stored XSS |
NA |
Jatin Aesthetic (@techyfreakk) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4059 | Account Takeover Using CSRF(json-based) |
CSRF
Account takeover |
NA |
shub rathore (@shub66452) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4052 | OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect |
Open redirect
Token leak
Account takeover |
Airbnb |
Evgeniy Yakovchuk (@h1_sp1d3r) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4051 | Tale of account takeover — Sensitive info Disclosure + Broken Access Control |
IDOR
Account takeover |
NA |
Md Saqib (@sakyb7) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4046 | Account takeover on Airbnb acquisition | An Unusual Bug Part-2 🐛 |
IDOR
Account takeover |
Airbnb |
PRince CHaddha (@princechaddha) |
Bug Bounty | 2019-07-13 | 2023-06-13 |
4032 | Account Takeover Vulnerability :) |
Password reset
Account takeover |
NA |
Sumit Jain (@sumit_cfe) |
Bug Bounty | 2019-07-17 | 2023-06-13 |
4018 | XX to XXX in one day |
Account takeover
Parameter tampering |
WePay |
Baibhav Anand (@SpongeBhav) |
Bug Bounty | 2019-07-23 | 2023-06-13 |
4016 | How I found the most critical bug in live bug bounty event? |
Password reset
Account takeover |
NA |
Lakshay (@inn0c3ntd3v1L) |
Bug Bounty | 2019-07-24 | 2023-06-13 |
4014 | Full Account Takeover via Changing Email And Password of any User through API Parameters |
IDOR
Password reset
Account takeover |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2019-07-26 | 2023-06-13 |
4012 | Story about Facebook Oauth Account Takeover |
Account takeover
OAuth |
iLOTTE |
Zerb0a |
Bug Bounty | 2019-07-26 | 2023-06-13 |
4009 | Old GitHub Profile Takeover! |
Github account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4005 | Paypal bug $10K - All Secondary users account takeover leads to unauthorized money transfer from paypal business accounts |
IDOR |
Paypal |
Mohd haji (@mohdhaji24) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
3984 | Writing my Medium blog to complete account takeover |
Stored XSS
Account takeover |
Medium |
Rotem Reiss (@rotem_reiss) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3973 | BookMyShow account takeover using social login |
OAuth
Account takeover |
BookMyShow |
Sukhmeet Singh (@MadGuyyy) |
Bug Bounty | 2019-08-15 | 2023-06-13 |
3957 | From Github Recon To Account Takeover |
Information disclosure
Account takeover |
NA |
Dipak kumar Das (@d1pakdas) |
Bug Bounty | 2019-08-24 | 2023-06-13 |
3954 | How I Hacked Instagram Again |
Password reset
Account takeover |
Meta / Facebook |
Laxman Muthiyah (@LaxmanMuthiyah) |
Bug Bounty | 2019-08-26 | 2023-06-13 |
3941 | Readme.com Account Takeover |
Password reset |
Readme.com |
Ankush Goel (@0xankush) |
Bug Bounty | 2019-09-05 | 2023-06-13 |
3918 | How I found a simple and weird Account takeover bug |
Account takeover
Missing authentication |
NA |
Bijan Murmu (@0xBijan) |
Bug Bounty | 2019-09-14 | 2023-06-13 |
3906 | [Case Study] OAuth Misconfiguration leads to Account Takeover |
OAuth
Account takeover |
NA |
Gaurang Bhatnagar (@0xgaurang) |
Bug Bounty | 2019-09-21 | 2023-06-13 |
3889 | How I made 1000$ with AT&T Bug Bounty(H1) |
CSRF
Account takeover |
AT&T |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3859 | XSS to Account Takeover |
XSS
CSRF |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3848 | How I Hacked Dutch Government in 5 Minutes? Twitter Account Takeover |
Broken link hijacking |
Dutch Government |
Numan ÖZDEMİR (@numanozdemircom) |
Bug Bounty | 2019-11-06 | 2023-06-13 |
3835 | Chains on Chains!! Chaining several IDOR’s into Account Takeover(PART ONE) |
IDOR |
NA |
Daniel Marte (@DanielM59720745) |
Bug Bounty | 2019-11-15 | 2023-06-13 |
3813 | Exploiting padding oracles with fixed IVs |
Padding oracle attack
Account takeover |
NA |
Teddy Katz (@not_aardvark) |
Bug Bounty | 2019-11-23 | 2023-06-13 |
3812 | The AccountTakeOver Killing Chain |
Account takeover
CSRF
Self-XSS |
NA |
أنس روبي (@xhzeem) |
Bug Bounty | 2019-11-23 | 2023-06-13 |