4095 | Using Burp Suite match and replace settings to escalate your user privileges and find hidden features |
Client-side enforcement of server-side security |
New Relic |
Jon Bottarini (@jon_bottarini) |
Bug Bounty | 2019-06-17 | 2023-06-13 |
4085 | About a Sucuri RCE...and How Not to Handle Bug Bounty Reports |
RCE |
Sucuri |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2019-06-20 | 2023-06-13 |
4077 | F5 Networks Endpoint Inspector – Browser-to-RCE? |
RCE |
F5 |
Dave U. Ramdon |
Bug Bounty | 2019-06-26 | 2023-06-13 |
4070 | Nuget/Squirrel uncontrolled endpoints leads to arbitrary code execution |
RCE |
Microsoft |
Reegun J (@reegun21) |
Bug Bounty | 2019-06-28 | 2023-06-13 |
4049 | Story of my Biggest Bounty ever : Command Execution on Jenkins |
RCE
Exposed Jenkins instance |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2019-07-11 | 2023-06-13 |
4002 | RCE in Ruby using Mustache Templates |
RCE |
NA |
Rhys Elsmore (@rhyselsmore) |
Bug Bounty | 2019-08-01 | 2023-06-13 |
3981 | Two Easy RCE in Atlassian Products |
Credential stuffing |
Atlassian |
Valeriy Shevchenko (@Krevetk0Valeriy) |
Bug Bounty | 2019-08-09 | 2023-06-13 |
3952 | Private bug bounty $$,$$$ USD: “RCE as root on Marathon-Mesos instance” |
RCE |
NA |
Omar Espino (@omespino) |
Bug Bounty | 2019-08-27 | 2023-06-13 |
3944 | RCE using Path Traversal |
RCE
Path traversal |
NA |
inc0gbyt3 (@incogbyte) |
Bug Bounty | 2019-09-02 | 2023-06-13 |
3942 | Exposed Jenkins to RCE on 8 Adobe Experience Managers |
RCE
Exposed Jenkins instance |
NA |
Corben Leo (@hacker_) |
Bug Bounty | 2019-09-04 | 2023-06-13 |
3934 | Oculus identity verification bypass through brute-force |
OTP bypass
Lack of rate limiting |
Meta / Facebook |
karthik kumar reddy (@karthiksunny007) |
Bug Bounty | 2019-09-09 | 2023-06-13 |
3925 | Exploiting File Uploads Pt. 2 – A Tale of a $3k worth RCE. |
Unrestricted file upload
RCE |
NA |
HackerOn2Wheels (@HackerOn2Wheels) |
Bug Bounty | 2019-09-13 | 2023-06-13 |
3920 | Race Condition that could Result to RCE - (A story with an App that temporary stored an uploaded file within 2 seconds before moving it to Amazon S3) |
Race condition
RCE
Unrestricted file upload |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2019-09-14 | 2023-06-13 |
3915 | RCE with Flask Jinja Template Injection |
SSTI
RCE |
NA |
AkShAy KaTkAr (@AkShAy KaTkAr) |
Bug Bounty | 2019-09-17 | 2023-06-13 |
3905 | [Bug Bounty] Exploiting Cookie Based XSS by Finding RCE |
Information disclosure
SQL injection
Authentication bypass
Unrestricted file upload
RCE
XSS |
NA |
Tomi (@noobe_io) |
Bug Bounty | 2019-09-22 | 2023-06-13 |
3893 | How to get RCE on AEM instance without Java knowledge |
RCE |
NA |
byq (@ByQwert) |
Bug Bounty | 2019-10-01 | 2023-06-13 |
3892 | How a double-free bug in WhatsApp turns to RCE |
Memory corruption
RCE
Android |
Meta / Facebook |
Awakened |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3888 | From Multiple IDORs leading to Code Execution on a different Host Container |
IDOR
RCE |
NA |
Rahul (@Rahul_R95) |
Bug Bounty | 2019-10-04 | 2023-06-13 |
3887 | How “Recon” helped Samsung protect their production repositories of SamsungTv, eCommerce / eStores |
Information disclosure |
Samsung |
Prateek Tiwari |
Bug Bounty | 2019-10-05 | 2023-06-13 |
3878 | How I found RCE But Got Duplicated |
Unrestricted file upload
RCE |
NA |
Smile Hacker |
Bug Bounty | 2019-10-15 | 2023-06-13 |
3874 | Hunting for bounties antihack.me case study |
RCE
XSS
Logic flaw
Information disclosure |
AntiHack.me |
0xSha (@0xsha) |
Bug Bounty | 2019-10-20 | 2023-06-13 |
3861 | How I hacked 50+ Companies in 6 hrs |
SSTI
RCE |
NA |
Vignesh C (@pwn_r00t) |
Bug Bounty | 2019-10-29 | 2023-06-13 |
3846 | BugBounty: How I Cracked 2FA (Two-Factor Authentication) with Simple Factor Brute-force !!! 😎 |
MFA bypass
Lack of rate limiting |
NA |
Akash Agrawal (@akashmagrawal) |
Bug Bounty | 2019-11-08 | 2023-06-13 |
3816 | Disable Any Unconfirmed Account in Facebook |
Bruteforce |
Meta / Facebook |
Lokesh Kumar (@lokeshdlk77) |
Bug Bounty | 2019-11-21 | 2023-06-13 |
3802 | My first RCE: a tale of good ideas and good friends |
RCE
ImageTragick |
NA |
rez0 (@rez0__) |
Bug Bounty | 2019-11-29 | 2023-06-13 |