3031 | Account takeover through password reset |
Account takeover
Password reset |
NA |
Omar Hamdy (@seaman00o) |
Bug Bounty | 2020-11-14 | 2023-06-13 |
3028 | Weak Cryptography to Account Takeover’s |
Cryptographic issues
Account takeover
IDOR |
NA |
letmeslidein (@VasuYadaav) |
Bug Bounty | 2020-11-15 | 2023-06-13 |
3019 | Tale of 3 vulnerabilities to account takeover! |
SSRF
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2020-11-17 | 2023-06-13 |
3009 | Escalating XSS to Account Takeover |
Reflected XSS
Account takeover |
NA |
Aditya Verma (@0cirius0) |
Bug Bounty | 2020-11-22 | 2023-06-13 |
3003 | Pre-Account Takeover using OAuth Misconfiguration |
OAuth |
NA |
the_unluck_guy (@7he_unlucky_guy) |
Bug Bounty | 2020-11-26 | 2023-06-13 |
3000 | Bcrypt — Account TakeOver Due To Weak Encryption — #HR51KDB |
Information disclosure
Account takeover |
NA |
DarkLotus (@darklotuskdb) |
Bug Bounty | 2020-11-29 | 2023-06-13 |
2995 | Chaining vulnerabilities lead to account takeover |
Account takeover
Password reset
Open redirect
Lack of rate limiting |
NA |
Ahmed (@ahzsec) |
Bug Bounty | 2020-12-01 | 2023-06-13 |
2982 | Story of the best vulnerability I’ve found so far… |
Self-XSS
Blind XSS
Account takeover |
NA |
Vedant Tekale (@_justYnot) |
Bug Bounty | 2020-12-07 | 2023-06-13 |
2973 | Exploiting new-era of Request forgery on mobile applications |
CSRF
Account takeover |
Pinterest |
Sayed Abdelhafiz (@dPhoeniixx) |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2970 | How I hacked Facebook: Part One |
Missing authentication
Authentication bypass
Account takeover |
Meta / Facebook |
Alaa Abdulridha (@alaa0x2) |
Bug Bounty | 2020-12-11 | 2023-06-13 |
2965 | TikTok Careers Portal Account Takeover |
CSRF
Open redirect
Account takeover |
TikTok |
Lauritz Holtmann (@_lauritz_) |
Bug Bounty | 2020-12-15 | 2023-06-13 |
2958 | Broken Access Control on samsung.com subdomain leads to Mass Account Takeover of Samsung employees application accounts |
Information disclosure
Account takeover
Authorization flaw |
Samsung |
Gal Nagli (@naglinagli) |
Bug Bounty | 2020-12-18 | 2023-06-13 |
2948 | EN | Account Takeover via Web Cache Poisoning based Reflected XSS |
Reflected XSS
Web cache poisoning
Account takeover |
NA |
Lütfü Mert Ceylan (@lutfumertceylan) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2945 | Chaining CORS by Reflected xss to Account takeover #My first Blog |
CORS misconfiguration
Reflected XSS
Account takeover |
NA |
Santosh Kumar Sha (@killmongar1996) |
Bug Bounty | 2020-12-26 | 2023-06-13 |
2919 | Github Organization Takeover By Claiming Owner Invitation |
Account takeover
Logic flaw |
GitHub |
Abss (@absshax) |
Bug Bounty | 2021-01-07 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2888 | Strange Admin Panel Bypass Story | | Bug Bounty |
Authentication bypass
Account takeover |
NA |
Ranjeet Kumar Singh (@geekboyranjeet) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2869 | Chaining a self XSS to Account Takeover |
Self-XSS
Reflected XSS
Account takeover |
NA |
Arman Sameer (@ArmanSameer95) |
Bug Bounty | 2021-01-25 | 2023-06-13 |
2861 | Weird functionality leads to Account Takeover (Millions of Users affected) |
Account takeover
Authentication flaw |
NA |
Sahil Mehra (@nullr3x) |
Bug Bounty | 2021-01-27 | 2023-06-13 |
2858 | OTP Bypass Account Takeover to Admin Panel — Ft. Header Injection |
OTP bypass
Account takeover |
NA |
Avinash Jain (@logicbomb_1) |
Bug Bounty | 2021-01-28 | 2023-06-13 |
2852 | How I chained P4 To P2 [Open Redirection To Full Account Takeover] |
Open redirect
Account takeover |
NA |
Bishal Shrestha (@bishal0x01) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2850 | An Interesting Account Takeover Vulnerability |
IDOR
Account takeover |
NA |
Avanish Pathak (@avanish46) |
Bug Bounty | 2021-01-30 | 2023-06-13 |
2848 | An Account Takeover Vulnerability Due to Response Manipulation. |
Authentication bypass
Account takeover |
NA |
Avanish Pathak (@avanish46) |
Bug Bounty | 2021-01-31 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2828 | Duplicate Registration - The Twinning Twins |
Account takeover
Authentication flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-02-08 | 2023-06-13 |