Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
3822How I could delete Facebook Ask for Recommendations post’s place objects in comments IDOR Meta / Facebook Raja Sudhakar (@Rajasudhakar) Bug Bounty2019-11-202023-06-13
3815Stories Of IDOR-Part 2 IDOR NA Shivbihari Pandey (@ninja_pandit_) Bug Bounty2019-11-212023-06-13
3814IDOR via Websockets IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-11-232023-06-13
3799HTTP Request Smuggling + IDOR HTTP request smuggling IDOR NA hipotermia (@_hipotermia_) Bug Bounty2019-12-052023-06-13
3776Inf0rM@tion Disclosure via IDOR IDOR NA Pratyush Anjan Sarangi Bug Bounty2019-12-162023-06-13
3763GraphQL IDOR leads to information disclosure IDOR NA Eshan Singh (@R0X4R) Bug Bounty2019-12-242023-06-13
3761Airbnb : Steal Earning of Airbnb hosts by Adding Bank Account/Payment Method (IDOR) IDOR Airbnb Vijay Kumar (@IndoAppSec) Bug Bounty2019-12-242023-06-13
3747Exploiting a Self Stored XSS with an IDOR Self-XSS Stored XSS IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-12-312023-06-13
3743Story of an IDOR via HTTP IDOR NA Shuaib Oladigbolu (@_sawzeeyy) Bug Bounty2019-12-312023-06-13
3711A Less Known Attack Vector, Second Order IDOR Attacks IDOR NA Ozgur Alp (@ozgur_bbh) Bug Bounty2020-01-222023-06-13
3706Accidental IDOR that Deleted Admin Account. IDOR NA Sayaan Alam (@ehsayaan) Bug Bounty2020-01-252023-06-13
3699Adding anyone including non-friend and blocked people as co-host in personal event! IDOR Meta / Facebook Binit Ghimire (@WHOISbinit) Bug Bounty2020-01-282023-06-13
3690Easily leaking passenger information on an Airline IDOR NA Zseano (@zseano) Bug Bounty2020-02-042023-06-13
3675IDOR leads to Data leakage and Profile Update IDOR Bruteforce NA vict0ni (@vict0ni) Bug Bounty2020-02-072023-06-13
3669A Simple IDOR to Account Takeover IDOR Account takeover NA Swapnil Maurya (@swapmaurya20) Bug Bounty2020-02-112023-06-13
3585Stealing Videos From VLC IDOR Internet Bug Bounty Dhiraj (@RandomDhiraj) Bug Bounty2020-03-262023-06-13
3554Listing all registered email addresses on Google’s Crisis Map thanks to IDOR and incremental IDs IDOR Google Thomas Orlita (@ThomasOrlita) Bug Bounty2020-04-072023-06-13
3552How i Unlocked the blocked accounts? Password reset HTTP parameter pollution IDOR NA Maria Zulfiqar Bug Bounty2020-04-112023-06-13
3541How was i able to find privilege escalation. IDOR Authorization flaw NA Akshar Tank (@Akshar__tank) Bug Bounty2020-04-182023-06-13
3513Hacking Razer Pay Ewallet App IDOR Razer Richard Tan (@sambal0x) Bug Bounty2020-04-302023-06-13
3480Chained Bugs [ Account TakeOver ] IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-162023-06-13
3477One Param => $10k IDOR XSS Account takeover NA Bilal Khan (@bilalmerokhel) Bug Bounty2020-05-172023-06-13
3472My first 10k bdt bounty from an e-commerce site IDOR NA Md Saikat Bug Bounty2020-05-182023-06-13
3459How Source code reading helped me find an IDOR IDOR Information disclosure NA Sanjay Verdu (@codersanjay) Bug Bounty2020-05-222023-06-13
3456Chaining an IDOR with a business-logic error to achieve critical impact IDOR Logic flaw NA Julien Cretel (@jub0bs) Bug Bounty2020-05-262023-06-13