4065 | How I escalated RFI into LFI |
RFI
LFI |
NA |
Hassan Khan Yusufzai (@Splint3r7) |
Bug Bounty | 2019-07-01 | 2023-06-13 |
4064 | Another Download Protection Bypass in Google Chrome – BIN files in Mac OS |
Browser hacking |
Google |
Nightwatch Cybersecurity (@nightwatchcyber) |
Bug Bounty | 2019-07-02 | 2023-06-13 |
4062 | Yeah! I got P2 in 1 minute - Stored XSS via Markdown Editor |
Stored XSS |
NA |
Schopath |
Bug Bounty | 2019-07-02 | 2023-06-13 |
4061 | Finding hidden gems vol. 4: Rakefile a.k.a. how to get AWS keys again |
Information disclosure |
NA |
Mateusz Olejarka (@molejarka) |
Bug Bounty | 2019-07-03 | 2023-06-13 |
4060 | Story of a stored xss to full account takeover vulnerability(N/A to accepted) |
Stored XSS |
NA |
Jatin Aesthetic (@techyfreakk) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4059 | Account Takeover Using CSRF(json-based) |
CSRF
Account takeover |
NA |
shub rathore (@shub66452) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4058 | Facebook Vulnerability: Unremovable Co-Host in facebook page events |
Logic flaw
DoS |
Meta / Facebook |
Ritish Kumar Singh |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4057 | This is how I managed to win $2000 through Facebook Bug Bounty |
Logic flaw |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2019-07-04 | 2023-06-13 |
4056 | Blind (time-based) SQLi - Bug Bounty |
SQL injection |
NA |
jspin (@jespinhara) |
Bug Bounty | 2019-07-05 | 2023-06-13 |
4055 | Cleartext password in LocalStorage (Writeup) |
Violation of secure design principles |
NA |
ruvlol |
Bug Bounty | 2019-07-07 | 2023-06-13 |
4054 | Information Disclosure via Misconfigured AWS to AWS Bucket Takeover |
AWS misconfiguration |
NA |
Pratyush Anjan Sarangi |
Bug Bounty | 2019-07-08 | 2023-06-13 |
4053 | A malicious editor of a page can support to a community action which can’t be unsupported by the admin! |
Authorization flaw |
Meta / Facebook |
mAshraf |
Bug Bounty | 2019-07-09 | 2023-06-13 |
4052 | OAuth authentication bypass on Airbnb acquisition using 1-char Open Redirect |
Open redirect
Token leak
Account takeover |
Airbnb |
Evgeniy Yakovchuk (@h1_sp1d3r) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4051 | Tale of account takeover — Sensitive info Disclosure + Broken Access Control |
IDOR
Account takeover |
NA |
Md Saqib (@sakyb7) |
Bug Bounty | 2019-07-10 | 2023-06-13 |
4050 | SQL Injection Bug Bounty POC! |
SQL injection |
NA |
Arif-ITSEC111 |
Bug Bounty | 2019-07-11 | 2023-06-13 |
4049 | Story of my Biggest Bounty ever : Command Execution on Jenkins |
RCE
Exposed Jenkins instance |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2019-07-11 | 2023-06-13 |
4048 | XSS on Google Custom Search Engine |
XSS |
Google |
KL Sreeram (@kl_sree) |
Bug Bounty | 2019-07-11 | 2023-06-13 |
4047 | Facebook Bug bounty page admin disclose bug {Facebook Android app} |
Information disclosure |
Meta / Facebook |
Yusuf Furkan (@h1_yusuf) |
Bug Bounty | 2019-07-12 | 2023-06-13 |
4046 | Account takeover on Airbnb acquisition | An Unusual Bug Part-2 🐛 |
IDOR
Account takeover |
Airbnb |
PRince CHaddha (@princechaddha) |
Bug Bounty | 2019-07-13 | 2023-06-13 |
4045 | Hacking intoTinder’s Premium Model |
Authorization flaw |
Tinder |
Sanskar Jethi (@sansyrox) |
Bug Bounty | 2019-07-14 | 2023-06-13 |
4044 | Cracking my windshield and earning $10,000 on the Tesla Bug Bounty Program |
Blind XSS |
Tesla |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-07-14 | 2023-06-13 |
4043 | How I Could Have Hacked Any Instagram Account |
Race condition
Rate limiting bypass |
Meta / Facebook |
Laxman Muthiyah (@LaxmanMuthiyah) |
Bug Bounty | 2019-07-14 | 2023-06-13 |
4042 | [TOKOPEDIA] Site-wide CSRF through GraphQL request |
CSRF |
Tokopedia |
Rafie Muhammad (@rafiem777) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
4041 | Facebook Bug : Sending messages as a page with jobmanager permission |
Authorization flaw
Privilege escalation |
Meta / Facebook |
Devansh batham (@devanshwolf) |
Bug Bounty | 2019-07-15 | 2023-06-13 |
4040 | 500$ bounty: Man in the Middle on Slack |
MiTM |
Slack |
Wiard van Rij / Sysrant (@RijWiard) |
Bug Bounty | 2019-07-15 | 2023-06-13 |