4012 | Story about Facebook Oauth Account Takeover |
Account takeover
OAuth |
iLOTTE |
Zerb0a |
Bug Bounty | 2019-07-26 | 2023-06-13 |
4011 | Solr Injection by abusing Local Parameters on Zomato.com |
Solr injection |
Zomato |
Ronak Patel (@ronak_9889) |
Bug Bounty | 2019-07-27 | 2023-06-13 |
4010 | Chaining Cache Poisoning To Stored XSS |
Web cache poisoning
Stored XSS |
NA |
Rohan aggarwal (@nahoragg) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4009 | Old GitHub Profile Takeover! |
Github account takeover |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-07-28 | 2023-06-13 |
4008 | Story of an IDOR via Email |
IDOR |
NA |
Shuaib Oladigbolu (@_sawzeeyy) |
Bug Bounty | 2019-07-29 | 2023-06-13 |
4007 | 1st Bounty Story | Rewarded 300$ (IDOR) |
IDOR |
NA |
Md Hridoy |
Bug Bounty | 2019-07-29 | 2023-06-13 |
4006 | SQL Injection in private-site.com/login.php |
SQL injection |
NA |
Mohamed Haron (@m7mdharon) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
4005 | Paypal bug $10K - All Secondary users account takeover leads to unauthorized money transfer from paypal business accounts |
IDOR |
Paypal |
Mohd haji (@mohdhaji24) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
4004 | Reposted [2019]: Hacking YouTube for #fun and #profit |
Authorization flaw |
Google |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
4003 | Reposted [2017]: LinkedIn Hacker’s Experience |
Stored XSS |
LinkedIn |
Alexandru Coltuneac (@dekeeu) |
Bug Bounty | 2019-07-30 | 2023-06-13 |
4002 | RCE in Ruby using Mustache Templates |
RCE |
NA |
Rhys Elsmore (@rhyselsmore) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
4001 | Bypassing CORS |
CORS misconfiguration |
NA |
Saad Ahmed (@XSaadAhmedX) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
3996 | One Misconfig (JIRA) to Leak Them All- Including NASA and Hundreds of Fortune 500 Companies! |
Information disclosure |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2019-08-02 | 2023-06-13 |
3995 | From Sub domain Takeover to Open-Redirect |
Subdomain takeover
Open redirect |
NA |
Anil Tom (mr_4nk) |
Bug Bounty | 2019-08-02 | 2023-06-13 |
3994 | No Rate limiting eligible for bounty ? |
Lack of rate limiting |
NA |
Smaran Chand (@smaranchand) |
Bug Bounty | 2019-08-03 | 2023-06-13 |
3993 | How I Found XSS By Searching In Shodan |
Reflected XSS |
NA |
D1vy4n5hu 5hukl4 (@justm0rph3u5) |
Bug Bounty | 2019-08-04 | 2023-06-13 |
3992 | Leveraging AngularJS-based XSS to Privilege Escalation |
XSS
Privilege escalation |
NA |
Shawar Khan (@ShawarkOFFICIAL) |
Bug Bounty | 2019-08-04 | 2023-06-13 |
3991 | Stored XSS on LaporBug.id |
Stored XSS |
LaporBug.id |
rizal (@sayadarijawa) |
Bug Bounty | 2019-08-05 | 2023-06-13 |
3990 | BugBounty WriteUp — Creative thinking is our everything (Race Condition + Business Logic Error) |
Race condition
Logic flaw |
NA |
Oleksandr Opanasiuk (@Lekssik2) |
Bug Bounty | 2019-08-05 | 2023-06-13 |
3989 | Exploiting Out Of Band XXE using internal network and php wrappers |
XXE |
NA |
Mahmoud Gamal (@Zombiehelp54) |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3988 | self XSS to stored XSS [ think out the box] |
Self-XSS
Stored XSS |
TIBCO |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3987 | CRLF injection allow => cookie injection in root domain & xss |
CRLF injection |
Bukalapak |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-06 | 2023-06-13 |
3986 | break and bypass verification email |
Open redirect
Email verification bypass
Weak crypto |
Bukalapak |
Abdelhak Kharroubi |
Bug Bounty | 2019-08-07 | 2023-06-13 |
3985 | LAN-Based Blind SSRF Attack Primitive for Windows Systems (switcheroo) |
SSRF |
Microsoft |
initstring (@init_string) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3984 | Writing my Medium blog to complete account takeover |
Stored XSS
Account takeover |
Medium |
Rotem Reiss (@rotem_reiss) |
Bug Bounty | 2019-08-09 | 2023-06-13 |