4874 | How I was able to Bypass XSS Protection on HackerOne’s Private Program |
XSS |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-02-02 | 2023-06-13 |
4869 | How I found IDOR on Twitter’s Acquisition – Mopub.com |
IDOR |
Twitter |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-02-05 | 2023-06-13 |
4776 | Stealing money from one account to another account |
Logic flaw |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2018-05-02 | 2023-06-13 |
4510 | Privilege Escalation like a Boss |
IDOR |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2018-10-27 | 2023-06-13 |
4368 | Workplace Logo ID to workplace owner name Disclosure Facebook Bug Bounty |
IDOR |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-01-11 | 2023-06-13 |
4208 | Multiple xss in *.skype.com |
XSS |
Microsoft |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2019-04-10 | 2023-06-13 |
4081 | Page Admin Disclosure | Facebook Bug Bounty 2019 |
Authorization flaw |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-06-22 | 2023-06-13 |
4049 | Story of my Biggest Bounty ever : Command Execution on Jenkins |
RCE
Exposed Jenkins instance |
NA |
Jay Jani (@JayJani007) |
Bug Bounty | 2019-07-11 | 2023-06-13 |
3949 | Shodan is your friend!!! If you ignore him you will lose many… |
SQL injection
Authentication bypass |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2019-08-28 | 2023-06-13 |
3917 | Google Referer Leak Bug |
Referer leakage
Information disclosure |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2019-09-15 | 2023-06-13 |
3865 | Session Expiration Bypass in Facebook Creator App |
Session expiration issue |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-10-24 | 2023-06-13 |
3761 | Airbnb : Steal Earning of Airbnb hosts by Adding Bank Account/Payment Method (IDOR) |
IDOR |
Airbnb |
Vijay Kumar (@IndoAppSec) |
Bug Bounty | 2019-12-24 | 2023-06-13 |
3753 | Bypassing Brand Collabs Manager Eligibility on Facebook |
Authorization flaw |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2019-12-26 | 2023-06-13 |
3709 | How I was able to take over any users account with host header injection |
Host header injection |
NA |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-01-23 | 2023-06-13 |
3696 | How I was able to takeover the company’s LinkedIn Page |
Broken link hijacking |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-01-29 | 2023-06-13 |
3685 | How, I dumped crypto data by chaining directory listing to open S3 Bucket |
AWS misconfiguration
Directory listing
Information disclosure |
NA |
Ddigvijay |
Bug Bounty | 2020-02-05 | 2023-06-13 |
3653 | Tale of Account Takeovers (Part-1) |
Account takeover
HTTP parameter pollution
Password reset
OTP bypass |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-02-22 | 2023-06-13 |
3536 | CORS bug on GOOGLE’s 404 page REWARDED!!! |
CORS misconfiguration |
Google |
Jayateertha Guruprasad (@JayateerthaG) |
Bug Bounty | 2020-04-21 | 2023-06-13 |
3482 | How I got my first swag on Edmodo with a simple XSS. |
Stored XSS |
Edmodo |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-16 | 2023-06-13 |
3475 | Tale of Account Takeovers (Part-2) |
Account takeover |
NA |
Vijaysimha Reddy Bathini (@fatratfatrat) |
Bug Bounty | 2020-05-17 | 2023-06-13 |
3467 | How I got 200$ in 5 minutes – Sensitive data leak |
Information disclosure |
NA |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-19 | 2023-06-13 |
3459 | How Source code reading helped me find an IDOR |
IDOR
Information disclosure |
NA |
Sanjay Verdu (@codersanjay) |
Bug Bounty | 2020-05-22 | 2023-06-13 |
3419 | Local file read via XSS using PDF generate functionality |
XSS
LFI |
NA |
Sanjay Singh Jhala (@lordjerry0x01) |
Bug Bounty | 2020-06-05 | 2023-06-13 |
3392 | How to Secure AWS ServerLess Lambda from ReDoS(Regular Expression Denial-of-Service) & Resultant Financial Impact |
ReDoS |
NA |
Ddigvijay (@itsdig) |
Bug Bounty | 2020-06-14 | 2023-06-13 |
3229 | How I was able to find page/personal account disclosure on Instagram |
Information disclosure |
Meta / Facebook |
Ajay Gautam (@evilboyajay) |
Bug Bounty | 2020-08-11 | 2023-06-13 |