Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
2818Hacking Chess.com and Accessing 50 Million Customer Records Reflected XSS Information disclosure Account takeover Chess.com Sam Curry (@samwcyo) Bug Bounty2021-02-112023-06-13
2814OAuth Misconfiguration Leads to Full Account takeover OAuth Clickjacking CSRF Account takeover NA Yasser Mohammed (@boomneroli) Bug Bounty2021-02-132023-06-13
2802Full account takeover worth $1000 Think out of the box Account takeover CSRF IDOR NA Mohsin Khan (@tabaahi_) Bug Bounty2021-02-152023-06-13
2794Story of a very lethal IDOR. XSS IDOR Account takeover NA Vedant Tekale (@_justYnot) Bug Bounty2021-02-172023-06-13
2782Account Take Over by Response Manipulation Authentication bypass Account takeover NA Naveen J (@thevillagehackr) Bug Bounty2021-02-172023-06-13
2779Account Takeover via Response Manipulation worth 1800$.. Authentication bypass OTP bypass Account takeover NA Ashutosh mishra (@ashutoshmish_ra) Bug Bounty2021-02-202023-06-13
2775Web Cache Poisoning to Account Takeover Web cache poisoning Account takeover NA Josh Fam (@Pullerze) Bug Bounty2021-02-212023-06-13
2770Hijacking Reset Password Link in https://www.niteflirt.com/ via Host Header Poising (Write Up) Host header injection Account takeover Password reset Niteflirt Evan Ricafort (@evanricafort) Bug Bounty2021-02-252023-06-13
2767Password Reset Token Leak via X-Forwarded-Host Host header injection Account takeover Password reset NA Saajan Bhujel (@saajanbhujel) Bug Bounty2021-02-262023-06-13
2766Account Takeover - Smoking with null’ Account takeover Authentication flaw NA Jerry Shah (@Jerry) Bug Bounty2021-02-262023-06-13
2758Any Account Takeover Through Privilege Escalation Privilege escalation Account takeover NA Shubham Chaskar (@chaskar_shubham) Bug Bounty2021-02-282023-06-13
2745How I Might Have Hacked Any Microsoft Account Account takeover Password reset Bruteforce MFA bypass Microsoft Laxman Muthiyah (@laxmanmuthiyah) Bug Bounty2021-03-022023-06-13
2726Chain of Low Level Bugs and Misconfigurations Leads to Account Takeover Reflected XSS Clickjacking Account takeover NA pleorqy (@pleorqy) Bug Bounty2021-03-102023-06-13
2722Account Takeover Via Reset Password Worth 2000$ Password reset Account takeover NA Ashutosh mishra (@ashutoshmish_ra) Bug Bounty2021-03-122023-06-13
2714An Interesting Account Takeover!! IDOR Account takeover Weak encryption Password reset NA Mayank Pandey (@mayank_pandey01) Bug Bounty2021-03-172023-06-13
2711Abusing Data Protection Laws For D0xing & Account Takeovers SSTI Account takeover NA Hx01 (@Hxzeroone) Bug Bounty2021-03-172023-06-13
2707How I hacked Facebook: Part Two SSRF Account takeover Cookie manipulation Meta / Facebook Alaa Abdulridha (@alaa0x2) Bug Bounty2021-03-182023-06-13
2689Increasing impact of Information Disclosure — Full Account Takeover ! Information disclosure Password reset NA Abhisek R (@abh1sek_r) Bug Bounty2021-03-262023-06-13
2684CSRF to Full Account Takeover CSRF Account takeover NA Ashraf Harb (@ashrafharb97) Bug Bounty2021-03-292023-06-13
2681Missing CORS leads to Complete Account Takeover Missing CORS CSRF Account takeover NA Niraj Modi (@nirajmodi51) Bug Bounty2021-03-302023-06-13
2677Zero click vulnerability in Apple’s macOS Mail Account takeover Information disclosure RCE Apple Mikko Kenttälä (@Turmio_) Bug Bounty2021-04-012023-06-13
2650Unauthenticated Account Takeover Through Forget Password Password reset Account takeover Information disclosure NA Nikhil (niks) (@niksthehacker) Bug Bounty2021-04-122023-06-13
2636Lets Learn English - Hacking 10M+ Users AWS misconfiguration Insecure Firebase database OTP bypass Account takeover Logic flaw NA Aseem Shrey (@AseemShrey) Bug Bounty2021-04-172023-06-13
2632Misconfiguration in Change-password Functionality Leads to Account Takeover IDOR Logic flaw Password reset Account takeover NA Mahmoud Radwan (@0x___2m) Bug Bounty2021-04-182023-06-13
2610From Wayback Machine To Account Takeover Account takeover Password reset Open redirect NA Demon (@R29k_) Bug Bounty2021-04-252023-06-13