4896 | #BugBounty — How I was able to delete anyone’s account in an Online Car Rental Company |
CSRF
Parameter tampering |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-14 | 2023-06-13 |
4895 | Hacking Facebook accounts using CSRF in Oculus-Facebook integration |
CSRF |
Meta / Facebook |
Josip Franjkovic (@josipfranjkovic) |
Bug Bounty | 2018-01-15 | 2023-06-13 |
4893 | #BugBounty — AWS S3 added to my “Bucket” list! |
AWS misconfiguration |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-16 | 2023-06-13 |
4884 | #BugBounty @ Linkedln-How I was able to bypass Open Redirection Protection |
Open redirect |
LinkedIn |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-01-24 | 2023-06-13 |
4882 | No RCE? Then SSH to the box! |
LFI
Path traversal
RCE |
NA |
Jasmin Laundry (@JR0ch17) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4881 | [Yahoo Bug Bounty] Unauthorized Access to Unisphere Management Server Debugging Facility on https://bf1-uaddbcx-002.data.bf1.yahoo.com/Debug/ |
Authorization flaw |
Yahoo! / Verizon Media |
Peerzada Fawaz Ahmad Qureshi |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4880 | Full Account Takeover through CORS with connection Sockets |
CORS misconfiguration
Account takeover |
NA |
Samuel (@saamux) |
Bug Bounty | 2018-01-25 | 2023-06-13 |
4877 | How I got 22000$ worth ethereum |
Blind XSS |
NA |
Shubham Gupta (@hackerspider1) |
Bug Bounty | 2018-01-26 | 2023-06-13 |
4876 | How I was able to Download Any file from Web server! |
XSS
IDOR |
NA |
hammadhassan924 |
Bug Bounty | 2018-01-27 | 2023-06-13 |
4874 | How I was able to Bypass XSS Protection on HackerOne’s Private Program |
XSS |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-02-02 | 2023-06-13 |
4872 | Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1) |
IDOR |
NA |
Mohammed Abdul Raheem (@mohdaltaf163) |
Bug Bounty | 2018-02-03 | 2023-06-13 |
4871 | #BugBounty — "I don%27t need your current password to login into your account" - How could I completely takeover any user%27s account in an online classified ads company. |
Authentication bypass |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-03 | 2023-06-13 |
4868 | SQL injection with load file and into outfile |
SQL injection |
NA |
NoGe (@p4c3n0g3) |
Bug Bounty | 2018-02-05 | 2023-06-13 |
4862 | Oracle Cross Site Scripting Vulnerability -Adesh Kolte |
Reflected XSS |
Oracle |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2018-02-10 | 2023-06-13 |
4861 | #BugBounty — “How I was able to shop for free!”- Payment Price Manipulation |
Parameter tampering
Payment tampering |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-11 | 2023-06-13 |
4860 | An analysis of logic flaws in web-of-trust services |
Logic flaw |
Keybase |
EdOverflow (@EdOverflow) |
Bug Bounty | 2018-02-13 | 2023-06-13 |
4859 | $7.5k Google services mix-up |
Logic flaw |
Google |
Ezequiel Pereira (@epereiralopez) |
Bug Bounty | 2018-02-14 | 2023-06-13 |
4857 | #BugBounty — Exploiting CRLF Injection can lands into a nice bounty |
CRLF injection |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-17 | 2023-06-13 |
4856 | Exploiting CORS Miss configuration using XSS |
CORS misconfiguration |
NA |
Noman Shaikh (@nomanali181) |
Bug Bounty | 2018-02-18 | 2023-06-13 |
4847 | #BugBounty — API keys leakage, Source code disclosure in India’s largest e-commerce health care company. |
Path traversal |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4846 | How i Hacked into a bugcrowd. public program |
RCE |
NA |
Vishnuraj |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4845 | Re-dressing Instagram – Leaking Application Tokens via Instagram ClickJacking Vulnerability! |
Clickjacking |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4844 | The 2.5mins or 2.5k$ hawk-eye bug – A Facebook Pages Admins Disclosure Vulnerability! |
Information disclosure |
Meta / Facebook |
Mohamed A. Baset |
Bug Bounty | 2018-02-25 | 2023-06-13 |
4842 | #BugBounty — How I could book cab using your wallet money in India’s largest auto transportation company! |
OTP bypass |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2018-03-05 | 2023-06-13 |
4837 | How I hacked 74k users of a website. |
Authorization flaw |
NA |
Utkarsh Agrawal (@agrawalsmart7) |
Bug Bounty | 2018-03-11 | 2023-06-13 |