2895 | How I hijacked the top-level domain of a sovereign state |
Domain takeover |
Internet Bug Bounty |
Fredrik N. Almroth (@Almroot) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2894 | Attack of the clones 2: Git CLI remote code execution strikes back |
RCE |
GitHub |
Vitor Fernandes (@Rapt00rVF) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2893 | BitLocker Lockscreen bypass |
Lock screen bypass
Local Privilege Escalation
Windows |
Microsoft |
Jonas L (@jonasLyk) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2892 | Hacking naked Akamai ARL at scale |
Akamai ARL attack |
NA |
Randy Gingeleski (@gingeleski) |
Bug Bounty | 2021-01-15 | 2023-06-13 |
2891 | Weaponizing Apify for mass bug bounty $$$ |
Akamai ARL attack |
NA |
Randy Gingeleski (@gingeleski) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2890 | Finding 0day to hack Apple |
RCE
ColdFusion |
Apple |
Harsh Jaiswal (@rootxharsh) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2889 | My first and last crit of 2020 on Hackerone |
Lack of rate limiting
Bruteforce
IDOR
Password reset
Account takeover |
NA |
Takester (@dhiraj_ramteke) |
Bug Bounty | 2021-01-16 | 2023-06-13 |
2888 | Strange Admin Panel Bypass Story | | Bug Bounty |
Authentication bypass
Account takeover |
NA |
Ranjeet Kumar Singh (@geekboyranjeet) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2887 | ShazLocate! Abusing CVE-2019-8791 & CVE-2019-8792 |
Insecure deeplink
Information disclosure
Android |
Google
Apple |
Ashley King (@AshleyKingUK) |
Bug Bounty | 2021-01-17 | 2023-06-13 |
2886 | Let’s know How I have explored the buried secrets in React Native application |
Information disclosure
Hardcoded credentials |
NA |
secureITmania (@secureitmania) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2885 | How I was rewarded a $1000 bounty after abusing File Upload functionality to Stored XSS Vulnerability leading to credential theft of a vistor in a website. |
Unrestricted file upload
Stored XSS |
NA |
Kunal Khubchandani (@iamkun4l) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2884 | The Embedded YouTube Player Told Me What You Were Watching (and more) |
Information disclosure |
Google |
David Schütz (@xdavidhu) |
Bug Bounty | 2021-01-18 | 2023-06-13 |
2883 | Simple & Sweet: Bypass email update restriction to change emails of team members |
Logic flaw
Authorization flaw |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2882 | Open-redirect [in email] |
Open redirect |
NA |
Akhil |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2881 | [Bug Bounty] 600$ Info Disclosure: obtain any user’s backup data |
Information disclosure
IDOR |
NA |
Tommaso De Ponti |
Bug Bounty | 2021-01-19 | 2023-06-13 |
2880 | SSRF Exploitation in Libreoffice Spreadsheet File Converter |
SSRF |
NA |
R4id3n (@R4id3n__) |
Bug Bounty | 2021-01-21 | 2023-06-13 |
2879 | Story Behind Sweet SSRF. |
SSRF
XSS |
NA |
Rohit Soni (@streetofhacker) |
Bug Bounty | 2021-01-21 | 2023-06-13 |
2878 | KindleDrip — From Your Kindle’s Email Address to Using Your Credit Card |
RCE |
Amazon |
Yogev Bar-On |
Bug Bounty | 2021-01-21 | 2023-06-13 |
2877 | Staff Information Disclosure on Support Ticketing System ($x,xxx) |
Information disclosure |
NA |
Ph.Hitachi |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2876 | Page Admin Disclosure When Replying Comments |
Information disclosure |
Meta / Facebook |
Prakash Panta (@prakashpanta268) |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2875 | CSRF Protection Bypass in Atlassian Confluence Server |
CSRF |
Atlassian |
yeuchimse (@yeuchimse) |
Bug Bounty | 2021-01-22 | 2023-06-13 |
2874 | The Secret Parameter, LFR, and Potential RCE in NodeJS Apps |
Local File Read
RCE |
NA |
CaptainFreak (@0xCaptainFreak) |
Bug Bounty | 2021-01-23 | 2023-06-13 |
2873 | $10,000 for automatic email confirmation bug in Microsoft’s Edge browser |
Logic flaw |
Microsoft |
Karan Chaudhary (@0xKaran) |
Bug Bounty | 2021-01-23 | 2023-06-13 |
2872 | Sql Injection via hidden parameter |
SQL injection |
NA |
Rutvik Hajare (@HajareRutvik) |
Bug Bounty | 2021-01-24 | 2023-06-13 |
2871 | Bypassing WAF with incorrect proxy settings for Hunting Bugs. |
URL validation bypass |
NA |
Shaurya Sharma (@ShauryaSharma05) |
Bug Bounty | 2021-01-25 | 2023-06-13 |