2845 | Spoofing and Attacking With Skype |
Spoofing |
Microsoft |
mr.d0x (@mrd0x) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2844 | 1st Facebook Bug Bounty | Disclose page’s admin to mod/admin of group |
Information disclosure |
Meta / Facebook |
nhiephon (@_nhiephon) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2843 | Applying Offensive Reverse Engineering to Facebook Gameroom |
Insecure deserialization |
Meta / Facebook |
Eugene Lim (@spaceraccoonsec) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2842 | Stealing Chat session ID with CORS and execute CSRF attack |
CSRF
CORS misconfiguration |
NA |
Sunil Yedla (@sunilyedla2) |
Bug Bounty | 2021-02-02 | 2023-06-13 |
2841 | CVE-2020-9759 - Getting root on webOS |
Local Privilege Escalation
Browser hacking |
LG |
Andreas Lindh (@addelindh) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2840 | How I was able to Turn a XSS into a Account Takeover |
Web cache poisoning
Stored XSS
Account takeover
OAuth
Logic flaw |
NA |
Josh Fam (@Pullerze) |
Bug Bounty | 2021-02-03 | 2023-06-13 |
2839 | Microsoft Remote Desktop Web Access Authentication Timing Attack |
Timing attack
Authentication flaw |
Microsoft |
Matt Dunn |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2838 | Open Redirect vulnerability found using link parameter |
Open redirect |
NA |
Muhammad Aamir (@Muhammad__Aamir) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2836 | Redwood Report2Web XSS and Frame injection |
Reflected XSS
Frame injection |
NA |
vict0ni (@vict0ni) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2835 | Page Admin Disclosed In Groups Due To Improper Session Handling In Facebook Web |
Information disclosure |
Meta / Facebook |
Samip Aryal (@samiparyal_) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2834 | Facebook Messenger Desktop App Arbitrary File Read |
Arbitrary file read |
Meta / Facebook |
Renwa (@RenwaX23) |
Bug Bounty | 2021-02-04 | 2023-06-13 |
2832 | Escalating SSRF to RCE |
SSRF
RCE |
NA |
Sander Wind (@SanderWind) |
Bug Bounty | 2021-02-06 | 2023-06-13 |
2831 | How I Gain Access to the Server Administration of a Million-Dollar Company |
Privilege escalation
Mass assignment |
NA |
Marx Chryz Del Mundo |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2830 | Reflected XSS on a Public Program |
Reflected XSS |
NA |
Naveen J (@thevillagehackr) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2829 | Bigbasket Bug Bounty Writeup |
Insecure data storage
Android |
NA |
Lohith Gowda M (@lohi_gowda_) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2828 | Duplicate Registration - The Twinning Twins |
Account takeover
Authentication flaw |
NA |
Jerry Shah (@Jerry) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2827 | Abusing URI Parsers for fun and profit |
URL validation bypass |
NA |
Mohammad Owais (@_mohammadowais) |
Bug Bounty | 2021-02-08 | 2023-06-13 |
2826 | Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies |
Dependency confusion |
Paypal
Shopify
Apple
Netflix
Yelp
Uber
Microsoft |
Alex Birsan (@alxbrsn) |
Bug Bounty | 2021-02-09 | 2023-06-13 |
2825 | Self-XSS to rXSS via Uploaded File Name |
Self-XSS
Reflected XSS |
NA |
P4nda (@InfoSecP4nda) |
Bug Bounty | 2021-02-09 | 2023-06-13 |
2824 | How I Got An Appreciation Letter From Harvard University |
Subdomain takeover |
Harvard University |
Santosh Bobade (@Santosh88267387) |
Bug Bounty | 2021-02-10 | 2023-06-13 |
2823 | A Tale of 2nd $xxx Bounty from Facebook |
Logic flaw |
Meta / Facebook |
Kunjan Nayak |
Bug Bounty | 2021-02-10 | 2023-06-13 |
2821 | Fastest Subdomain Take Over & DNS Misconfiguration Hunt. |
Subdomain takeover
DNS zone transfer |
NA |
Kabeer (@iTheKabeer) |
Bug Bounty | 2021-02-10 | 2023-06-13 |
2820 | An Accidental XSS on uu.nl |
XSS |
Utrecht University |
Santosh Bobade (@Santosh88267387) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2819 | The "P" in Telegram stands for Privacy |
Privacy issue |
Telegram |
Dhiraj (@RandomDhiraj) |
Bug Bounty | 2021-02-11 | 2023-06-13 |
2818 | Hacking Chess.com and Accessing 50 Million Customer Records |
Reflected XSS
Information disclosure
Account takeover |
Chess.com |
Sam Curry (@samwcyo) |
Bug Bounty | 2021-02-11 | 2023-06-13 |