3431 | Information disclosure and reflected XSS on Tokopedia |
Reflected XSS
Information disclosure |
Tokopedia |
wis4nggeni |
Bug Bounty | 2020-06-01 | 2023-06-13 |
3425 | How I got my first big bounty payout with Tesla |
Information disclosure |
Tesla |
CJ Fairhead (@xyantix) |
Bug Bounty | 2020-06-04 | 2023-06-13 |
3417 | Multiple Information exposed due to misconfigured Service-now ITSM instances |
Missing authentication
Information disclosure |
NA |
Th3G3nt3lman (@Th3G3nt3lman) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3415 | XSS to Database Credential Leakage & Database Access — Story of total luck! |
Reflected XSS
Information disclosure |
NA |
Harsh Bothra (@harshbothra_) |
Bug Bounty | 2020-06-06 | 2023-06-13 |
3412 | This is fine 🐶 |
Information disclosure |
NA |
Ricardo Iramar dos Santos (@ricardo_iramar) |
Bug Bounty | 2020-06-08 | 2023-06-13 |
3384 | How I made more than $30K with Jolokia CVEs |
Reflected XSS
RCE
Information disclosure |
NA |
Patrik Fehrenbach (@ITSecurityguard) |
Bug Bounty | 2020-06-16 | 2023-06-13 |
3381 | Hackerone Bug Bounty Report: Hinge |
Information disclosure |
Hinge |
Tyle Butler (@tbutler0x90) |
Bug Bounty | 2020-06-18 | 2023-06-13 |
3380 | Replying on LiveStream leading to Page Admin Disclosure: Facebook Bug Bounty |
Information disclosure |
Meta / Facebook |
Saugat Pokharel (@saugatpk5) |
Bug Bounty | 2020-06-18 | 2023-06-13 |
3379 | One Token to leak them all : The story of a $8000 NPM_TOKEN |
Information disclosure |
Google |
Aseem Shrey (@AseemShrey) |
Bug Bounty | 2020-06-19 | 2023-06-13 |
3378 | From Recon to Bypassing MFA Implementation in OWA by Using EWS Misconfiguration |
Information disclosure
MFA bypass |
NA |
YoKo Kho (@YokoAcc) |
Bug Bounty | 2020-06-19 | 2023-06-13 |
3376 | How did i find information Disclosure on Facebook-Writeup |
Information disclosure |
Meta / Facebook |
Alaa Abdulridha (@Madrid89001310) |
Bug Bounty | 2020-06-20 | 2023-06-13 |
3368 | Exploiting Bitdefender Antivirus: RCE from any website |
RCE
Information disclosure |
Bitdefender |
Wladimir Palant (@WPalant) |
Bug Bounty | 2020-06-22 | 2023-06-13 |
3357 | API Endpoint leads to Account Takeover In Android Application |
Exposed token generation endpoint
Information disclosure |
NA |
Adesh Nandkishor kolte (@AdeshKolte) |
Bug Bounty | 2020-06-28 | 2023-06-13 |
3347 | How I made $1500 dollars using base64 decoder :) |
Information disclosure |
NA |
Dilip (@dilip_spartn) |
Bug Bounty | 2020-07-02 | 2023-06-13 |
3327 | How i was able to bypass Email Confirm — P4 |
Information disclosure |
NA |
Mohammed Ehssan (@alone_Wwolf) |
Bug Bounty | 2020-07-06 | 2023-06-13 |
3321 | From N/A to Resolved For BackBlaze Android App[Hackerone Platform] Bucket Takeover |
Hardcoded credentials
Information disclosure |
BackBlaze |
Sahil Tikoo (@viperbluff) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3319 | Exploiting Application Logic to Referral Code Disclosure |
Logic flaw
Information disclosure |
NA |
Vaibhav Joshi (@vj0shii) |
Bug Bounty | 2020-07-09 | 2023-06-13 |
3308 | How An API Misconfiguration Can Lead To Your Internal Company Data |
Information disclosure |
NA |
Me9187 (@Me9187) |
Bug Bounty | 2020-07-12 | 2023-06-13 |
3304 | Admin ,Editor can disclose personnel email of other editor, admin on page(who created shop) |
Information disclosure |
Meta / Facebook |
The 3 Day Account Takeover |
Bug Bounty | 2020-07-16 | 2023-06-13 |
3302 | I am able to see user’s sensitive data through JSON file. |
Information disclosure
Authorization flaw |
NA |
Saurabh siddharam sanmane (@saurabhsanmane2) |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3301 | The Story of My first 4 digit bounty from Facebook |
Logic flaw
Information disclosure |
Meta / Facebook |
Sudip Shah |
Bug Bounty | 2020-07-17 | 2023-06-13 |
3285 | Hunting Android Application Bugs Using Android Studio. |
Authorization flaw
Client-side enforcement of server-side security
Information disclosure |
NA |
Tarek Mohammed (@Conan0x3) |
Bug Bounty | 2020-07-24 | 2023-06-13 |
3282 | A Simple IDOR which should not be missed on dating site ;) |
IDOR
Information disclosure |
NA |
neelam |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3281 | Obtained a bunch of sensitive data in just few steps — Hacking |
AWS misconfiguration
Information disclosure |
NA |
Airlangga Visnhu Murthi |
Bug Bounty | 2020-07-26 | 2023-06-13 |
3270 | FFUF and my first bounty |
Information disclosure |
NA |
Suryansh Mansharamani |
Bug Bounty | 2020-07-29 | 2023-06-13 |