3268 | The Noob Way Of Taking Over Accounts |
Authorization flaw
Account takeover
Homograph attack |
NA |
Mudassir Sharief |
Bug Bounty | 2020-07-29 | 2023-06-13 |
3255 | Multi-factor Auth Bypass with Password Reset Function |
MFA bypass
Password reset
Account takeover |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-08-02 | 2023-06-13 |
3252 | Account takeover in cups.mail.ru |
Logic flaw
Password reset
Account takeover |
Mail.ru |
kminthein / weev3 (@kyawminthein99) |
Bug Bounty | 2020-08-03 | 2023-06-13 |
3251 | Vulnerability in new TouchID feature put iCloud accounts at risk of being breached |
OAuth
Account takeover |
Apple |
Thijs Alkemade (@xnyhps) |
Bug Bounty | 2020-08-03 | 2023-06-13 |
3249 | How I was able to do Mass Account Takeover[Bug Bounty] |
Account takeover
Password reset |
NA |
Not Rickyy (@RickyyNot) |
Bug Bounty | 2020-08-05 | 2023-06-13 |
3240 | Exploiting JWT - Lack of Signature Verification |
Account takeover |
NA |
Aditya Dixit (@zombie007o) |
Bug Bounty | 2020-08-06 | 2023-06-13 |
3209 | Account Takeover Using Re-Register [ Bug Bounty ] |
Account takeover |
NA |
Myo Min Thu (@myominthu1337) |
Bug Bounty | 2020-08-17 | 2023-06-13 |
3193 | Account Takeover For The Win 🏆 |
Account takeover
Authentication flaw
Password reset |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-08-24 | 2023-06-13 |
3176 | Account Takeover via IDOR |
IDOR
Account takeover |
NA |
Roma Ramazanoff (@r0hack) |
Bug Bounty | 2020-09-04 | 2023-06-13 |
3173 | Never Give Up, The Story Behind a Dupe-To-Triaged |
XSS
OAuth
Account takeover |
NA |
Alan Brian (@soyelmago) |
Bug Bounty | 2020-09-06 | 2023-06-13 |
3160 | Account takeover by OTP bypass |
OTP bypass |
NA |
Bhavarth Kandoria |
Bug Bounty | 2020-09-13 | 2023-06-13 |
3152 | Privilege Escalation via Account Takeover on NodeBB Forum Software — Bug Bounty (512$) — CVE-2020–15149 |
IDOR
Account takeover |
NodeBB |
Muhammed Eren Uygun (@erenuyguun) |
Bug Bounty | 2020-09-19 | 2023-06-13 |
3136 | PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover |
IDOR
Information disclosure |
NA |
Pradeep Kumar (@Killer007p) |
Bug Bounty | 2020-09-25 | 2023-06-13 |
3131 | 5 Ways to do Account Takeover in a Single Website |
Account takeover
Lack of rate limiting
OTP bypass
IDOR
OAuth
JWT |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-09-27 | 2023-06-13 |
3129 | Taking down the SSO, Account Takeover in the Websites of Kolesa due to Insecure JSONP Call |
Account takeover |
NA |
Yashar Shahinzadeh (@YShahinzadeh) |
Bug Bounty | 2020-09-28 | 2023-06-13 |
3116 | Watch your requests! Open redirect to a complete account takeover |
Path traversal
Open redirect
SSRF
Account takeover |
NA |
Suraj Disoja (@ninetyn1ne_) |
Bug Bounty | 2020-10-05 | 2023-06-13 |
3112 | 6k$ Worth Account Takeover via IDOR in Starbucks Singapore |
IDOR
Account takeover |
Starbucks |
Kamil Onur Özkaleli (@ko2sec) |
Bug Bounty | 2020-10-07 | 2023-06-13 |
3107 | ATO via Host Header Poisoning |
Host header injection
Account takeover
Password reset |
NA |
Shivam Kamboj Dattana (@sechunt3r) |
Bug Bounty | 2020-10-08 | 2023-06-13 |
3101 | Unauthorized access to all the user’s account. |
Account takeover
Authentication bypass
JWT |
NA |
Rahul Naidu |
Bug Bounty | 2020-10-12 | 2023-06-13 |
3091 | GitHub Gist - Account takeover via open redirect - $10,000 Bounty |
Open redirect
Account takeover |
GitHub |
William Bowling / vakzz (@wcbowling) |
Bug Bounty | 2020-10-19 | 2023-06-13 |
3056 | From a 500 error to Django admin takeover |
Authorization bypass
Account takeover |
NA |
Shashank (@cyberboyIndia) |
Bug Bounty | 2020-11-03 | 2023-06-13 |
3052 | Story of a Pre-Account Takeover |
Account takeover
OAuth |
NA |
Kushal Dhakal (@dhakal0kushal) |
Bug Bounty | 2020-11-06 | 2023-06-13 |
3049 | How i could take over any Account on a USA Department of Defense Website due to a simple IDOR |
IDOR
Account takeover |
U.S. Dept Of Defense |
Gal Nagli (@naglinagli) |
Bug Bounty | 2020-11-07 | 2023-06-13 |
3045 | Chaining password reset link poisoning, IDOR, and information leakage to achieve account takeover at api.redacted.com |
HTTP header injection |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3032 | Theoretically Possible To Practical Account Takeover |
IDOR
Account takeover |
NA |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-11-14 | 2023-06-13 |