1393 | How I find open redirect in Facebook |
Open redirect |
Brave Software |
Abhinav Kumar (@abhinavsecond) |
Bug Bounty | 2022-07-07 | 2023-06-13 |
1255 | Email Confirmation bypass at Instagram |
Email verification bypass
Logic flaw |
Meta / Facebook |
Avinash Kumar (@itsavinash_) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1164 | How I found reflected XSS on IDFC Bank with burp-suite Intruder |
Reflected XSS |
IDFC Bank |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1163 | Out-Of-Bond Remote code Execution(RCE) on De Nederlandsche Bank N.V. with burp-suite collaborator |
OS command injection
RCE |
De Nederlandsche Bank |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2022-08-28 | 2023-06-13 |
1037 | Blind XSS on Admin Portal Leads to Information Disclosure |
Blind XSS |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-09-24 | 2023-06-13 |
1006 | Using Default Credential to Admin Account Takeover |
Weak credentials |
NA |
Rohit Kumar (Rohit_443) |
Bug Bounty | 2022-10-02 | 2023-06-13 |
949 | Facebook SMS Captcha Was Vulnerable to CSRF Attack |
CSRF |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2022-10-17 | 2023-06-13 |
715 | Privilege Escalation to remove the owner from the organization |
Privilege escalation
Mass assignment |
NA |
Hemant Kumar |
Bug Bounty | 2022-12-09 | 2023-06-13 |
696 | How I Hacked A Company (My First Red Team Engagement 🚩)Permalink |
SQL injection |
NA |
Monish Kumar (@aidenpearce369) |
Bug Bounty | 2022-12-13 | 2023-06-13 |
467 | We Hacked GitHub for a Month: Here’s What We Found |
Pre-account takeover
Broken Access Control
Email verification bypass
Logic flaw |
GitHub |
Shivam Kumar Singh (@MrRajputHacker) |
Bug Bounty | 2023-02-11 | 2023-06-13 |
461 | Zip bomb attack |
Zip bomb
DoS
Unrestricted file upload |
NA |
Ramkumar Nadar |
Bug Bounty | 2023-02-12 | 2023-06-13 |
374 | How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability? |
Account takeover
Authentication bypass |
NA |
Vivek Kumar Yadav (@0xd3vil) |
Bug Bounty | 2023-03-01 | 2023-06-13 |
277 | How I got access to Essilor International company customer PII INFO by AWS metadata access through SSRF |
SSRF |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2023-03-21 | 2023-06-13 |