2148 | 500$ Bug: Sensitive Data Exposure to Broken Access Control leads, How I able to take over any account of India’s Biggest College Ever.👨💻 |
OTP bypass
Account takeover
Password reset |
NA |
Gowtham_Naidu (@NaiduPonnana) |
Bug Bounty | 2021-10-13 | 2023-06-13 |
2139 | A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection |
SQL injection
WAF bypass |
AWS |
Marc Olivier Bergeron |
Bug Bounty | 2021-10-19 | 2023-06-13 |
2133 | Moodle - Stored XSS and blind SSRF possible via feedback answer text |
Stored XSS
SSRF |
Moodle |
rekter0 (@rekter0) |
Bug Bounty | 2021-10-22 | 2023-06-13 |
2127 | How I was able to revoke your Instagram 2FA |
Bruteforce
Rate limiting bypass |
Meta / Facebook |
Dhiyaneshwaran (@DhiyaneshDK) |
Bug Bounty | 2021-10-23 | 2023-06-13 |
2112 | How I was able to access a properly Configured S3 Bucket |
Leaked AWS keys
Information disclosure |
NA |
Pawan Chhabria (@heybenchmarkkk) |
Bug Bounty | 2021-10-28 | 2023-06-13 |
2111 | One misconfiguration to rule them all |
Information disclosure
Debug mode enabled |
NA |
Sushant Soni (@sushantsoni5392) |
Bug Bounty | 2021-10-29 | 2023-06-13 |
2110 | How I found Command Injection via Obsolete PHPThumb |
OS command injection
RCE |
NA |
Sushant Kamble |
Bug Bounty | 2021-10-30 | 2023-06-13 |
2109 | This is how i was able to Permanently Crash all Mapillary users within minutes |
Application-level DoS |
Meta / Facebook |
Abhishek Pathak (@pathleax) |
Bug Bounty | 2021-10-31 | 2023-06-13 |
2088 | Write Up – Google VRP Bug Bounty: /etc/environment Local Variables Exfiltrated On Linux Google Earth Pro Desktop App – $1,337 USD |
XSS |
Google |
Omar Espino (@omespino) |
Bug Bounty | 2021-11-11 | 2023-06-13 |
2077 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-15 | 2023-06-13 |
2074 | DOS attack in Yahoo, How i was able to deny new users from service? |
DoS
Logic flaw |
Yahoo! / Verizon Media |
Mostafa Mamdoh |
Bug Bounty | 2021-11-16 | 2023-06-13 |
2058 | GoSecure Investigates Abusing Windows Server Update Services (WSUS) to Enable NTLM Relaying Attacks |
Local Privilege Escalation |
Microsoft |
Romain Carnus |
Bug Bounty | 2021-11-22 | 2023-06-13 |
2023 | This is how i was able to See and Delete your Private Facebook Portal photos |
IDOR |
Meta / Facebook |
Abhishek Pathak (@pathleax) |
Bug Bounty | 2021-12-04 | 2023-06-13 |
2018 | How I was able to change Reddit acquired Dubsmash%27s music library sound tracks%27 titles |
IDOR |
Reddit |
Sandeep Hodkasia (@sandeephodkasia) |
Bug Bounty | 2021-12-07 | 2023-06-13 |
1987 | How I was able to reveal page admin of almost any page on Facebook |
IDOR |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2021-12-20 | 2023-06-13 |
1978 | How I was able to bypass WAF and find the origin IP and a few sensitive files |
WAF bypass |
NA |
Jan Muhammad Zaidi (@hasanakajan) |
Bug Bounty | 2021-12-22 | 2023-06-13 |
1960 | How I Am Able To Crash Anyone’s Mozilla Firefox Browser By Sending An Email |
DoS |
Mozilla |
Sam |
Bug Bounty | 2021-12-30 | 2023-06-13 |
1954 | Fixing the Unfixable: Story of a Google Cloud SSRF |
SSRF |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-12-31 | 2023-06-13 |
1948 | Story of YouTube’s Unfixable Ads Bypass |
Logic flaw |
Google |
MrMax4o4 |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1947 | How i was able to bypass a Pin code Protection |
Authorization flaw |
NA |
Kerolos sameh (@xko2xx) |
Bug Bounty | 2022-01-03 | 2023-06-13 |
1937 | How I was able to spoof any Instagram username on Instagram shop |
IDOR |
Meta / Facebook |
Nawaf Alkhaldi (@nvmeeet) |
Bug Bounty | 2022-01-06 | 2023-06-13 |
1900 | How I was able to find multiple vulnerabilities of a Symfony Web Framework web application |
Debug mode enabled
Information disclosure |
NA |
Abid Ahmad (@RootIntrud3r) |
Bug Bounty | 2022-01-23 | 2023-06-13 |
1894 | How I was able to take over accounts in websites deal with Github as an SSO provider |
Bruteforce
Lack of rate limiting
SSO
Email verification bypass
Account takeover |
NA |
Khaled Mohamed |
Bug Bounty | 2022-01-25 | 2023-06-13 |
1871 | Missing rate-limiting. How I was able to add any unowned phone number to my Facebook account? (Bounty: 5000 USD) |
OTP bruteforce
Lack of rate limiting |
Meta / Facebook |
Shubham Bhamare (@theshubh77) |
Bug Bounty | 2022-01-31 | 2023-06-13 |
1868 | How I approached Dependency Confusion! |
Dependency confusion |
NA |
Aditya Soni (@hetroublemakr) |
Bug Bounty | 2022-02-01 | 2023-06-13 |