3081 | Accidental Observation to Critical IDOR |
IDOR |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-10-24 | 2023-06-13 |
3080 | My first bug on Google |
IDOR |
Google |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2020-10-25 | 2023-06-13 |
3075 | The YouTube bug that allowed unlisted uploads to any channel |
IDOR
Information disclosure |
Google |
Ryan Kovatch |
Bug Bounty | 2020-10-27 | 2023-06-13 |
3049 | How i could take over any Account on a USA Department of Defense Website due to a simple IDOR |
IDOR
Account takeover |
U.S. Dept Of Defense |
Gal Nagli (@naglinagli) |
Bug Bounty | 2020-11-07 | 2023-06-13 |
3045 | Chaining password reset link poisoning, IDOR, and information leakage to achieve account takeover at api.redacted.com |
HTTP header injection |
NA |
Jadek Mark (@mase289) |
Bug Bounty | 2020-11-10 | 2023-06-13 |
3032 | Theoretically Possible To Practical Account Takeover |
IDOR
Account takeover |
NA |
Mukul Lohar (@ironfisto) |
Bug Bounty | 2020-11-14 | 2023-06-13 |
3028 | Weak Cryptography to Account Takeover’s |
Cryptographic issues
Account takeover
IDOR |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3026 | Optimizing Hunting Results in VDP for use in Bug Bounty Programs - From Sensitive Information Disclosure to Accessing Hidden APIs which can be used to Retrieve Customer Data |
Information disclosure
Broken access control
IDOR
SQL injection |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3017 | GraphQL IDOR in Facebook streamer dashboard. |
IDOR
GraphQL |
Meta / Facebook |
Kailash (@Corrupted_brain) |
Bug Bounty | 2020-11-18 | 2023-06-13 |
2956 | Worth $1,500 IDOR (Access Unauthorize Data) |
IDOR |
NA |
Muhammad Asim Shahzad (@protector47) |
Bug Bounty | 2020-12-20 | 2023-06-13 |
2940 | Sensitive data leak using IDOR in integration service |
IDOR |
NA |
Ronak Patel (@ronak_9889) |
Bug Bounty | 2020-12-29 | 2023-06-13 |
2932 | API based IDOR to leaking Private IP address of 6000 businesses |
IDOR |
NA |
Rafi Ahamed (Leonidas D. Ace) |
Bug Bounty | 2021-01-01 | 2023-06-13 |
2913 | Create post on any Facebook page |
IDOR |
Meta / Facebook |
Pouya Darabi (@Pouyadarabi) |
Bug Bounty | 2021-01-08 | 2023-06-13 |
2907 | Stealing Your Private YouTube Videos, One Frame at a Time |
IDOR |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-01-11 | 2023-06-13 |
2904 | CSRF with IDOR - A Deadly Combo |
CSRF
IDOR |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-01-12 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2881 | [Bug Bounty] 600$ Info Disclosure: obtain any user’s backup data |
Information disclosure
IDOR |
NA |
Tommaso De Ponti |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2870 | IDOR Revealing Images CDN Links |
IDOR |
NA |
susan wagle |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2862 | Bragging Rights(Part 1): Short story of a bug wave |
IDOR
Stored XSS
SSRF
Subdomain takeover
Hardcoded credentials |
NA |
Manas Harsh (@ManasH4rsh) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2853 | Broken Access Control & Stored XSS - Easy Hunt |
Stored XSS
IDOR |
NA |
Kabeer (@iTheKabeer) |
Bug Bounty | 2021-01-29 | 2023-06-13 |
2850 | An Interesting Account Takeover Vulnerability |
IDOR
Account takeover |
NA |
Avanish Pathak (@avanish46) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2846 | Access developer tasks list of any Facebook Application (GraphQL IDOR) |
IDOR |
Meta / Facebook |
Amine Aboud (@amineaboud) |
Bug Bounty | 2021-02-01 | 2023-06-13 |
2811 | Changing other users Episode title & description - IDOR Vulnerability in [REDACTED] (Write Up) |
IDOR |
NA |
Evan Ricafort (@evanricafort) |
Bug Bounty | 2021-02-13 | 2023-06-13 |
2810 | How I Hacked Everyone’s Resume/CV’s and Got €€€ |
IDOR
Authorization flaw
Information disclosure |
NA |
Vishal Bharad |
Bug Bounty | 2021-02-14 | 2023-06-13 |
2809 | IDOR via Websockets allow me to takeover any users account |
IDOR |
NA |
Mohsin Khan (@tabaahi_) |
Bug Bounty | 2021-02-14 | 2023-06-13 |