Biscuit's Bug Bounty Playbook
Search...
Ctrl
K
Bug Bounty Reports & Articles
1๏ธโฃ
Takeover's (Accounts, Sub-domains, etc)
๐
Account Takeover
Previous
Sub Domain Takeover
Next
dependency confusion vulnerability
Last updated
16 days ago
0-Click Account Takeover Earned Me โฌ900 Bounty
Medium
Full Account Takeover Leading to RCE Remote Code Execution
Waqas Zaka
Pre account takeover
Medium
Oauth Misconfiguration Leads to 0-Click ATO
Medium
How I Earned $1800 for finding a (Business Logic) Account Takeover Vulnerability?
Medium
Account (of the CEO) Takeover via Password Reset
Medium
Account Takeover via Email Confirmation
Medium
Account Takeover via Weak OTP
Medium
[Account Take Over] through reset password token leaked in response, 2500 โฌ Reward
InfoSec Write-ups
5 Ways to do ATO in a Single Website
Medium
Account takeover in cups.mail.ru
qwerty
U.S. Dept Of Defense disclosed on HackerOne: Password Reset link...
HackerOne
Mail.ru disclosed on HackerOne: Account takeover through password...
HackerOne
UPS VDP disclosed on HackerOne: Admin Authentication Bypass Lead to...
HackerOne
PII Leakage via IDOR + Weak PasswordReset = Full Account Takeover
InfoSec Write-ups
0 Click Account takeover
Medium