Sujay HazraAccount Takeover via 2FA BypassHello Everyone , This is my first writeupAug 31, 20212Aug 31, 20212
Avanish PathakAn Account Takeover Vulnerability Due to Response Manipulation.- No doesn’t necessarily mean no.! Responses can always be manipulatedJan 30, 20213Jan 30, 20213
Abdullah MudzakirHost Header Injection Leads To Account TakeoverHalo perkenalkan saya Abdullah Mudzakir disini saya akan memberikan Write up bagaimana saya menemukan celah Host Header Injection yang…Sep 28, 2020Sep 28, 2020
Abdullah MudzakirAccount Takeover via OTP Leakage in HTTP ResponseHalo semuanya pada kesempatan kali ini saya ingin membagikan sebuah pengalaman saya ketika berburu Bug disalah satu Applikasi.Dec 28, 2020Dec 28, 2020
AbhishekPassword reset poisoning to ATO and OTP bypass.A common way to implement password reset functionality is to generate a secret token and send an email with a link containing the token…Aug 1, 20202Aug 1, 20202
AbhishekClickjacking to Account TakeoverClickjacking is an attack in which a user is tricked to click on something that he didn’t intend to, meaning an attacker could possibly…May 28, 20202May 28, 20202
vikram naiduAccount takeover via stored xssHi everyone! This is Vikram Naidu, Bug bounty hunter from India. Hope you all are safe. This is my first writeup and it is about my recent…Jul 29, 20211Jul 29, 20211
Aditya Sharma[$5K] Misconfigured Reset password that leads to Account Takeover (No user Interaction ATO)Single click account takeover Write-up (Critical)Aug 24, 20211Aug 24, 20211
Kwadwo AmoakoFull Account takeover (ATO) — a tale of two bugs 🐛Hi everyone, I hope we’re all having a swell day. Before I jump into today's bug report, I’d like to express my sincerest gratitude for…Feb 8, 20223Feb 8, 20223
Kwadwo AmoakoSSRF to a Full Account Takeover (ATO)Hello hackers!! today, I will be showing you how I performed an SSRF and Account Takeover attack, using host header injection. Let's get…Mar 4, 202211Mar 4, 202211
Abhisek RIncreasing impact of Information Disclosure — Full Account Takeover !Hey, I’m Abhisek. Back with another write up. This write up is based upon my bug hunting tactics of increasing impact of information…Mar 26, 20211Mar 26, 20211
Ashutosh mishraAccount Takeover via Response Manipulation worth 1800$..Bypassing Authenitcation Mechanism lead to account takeover worth 1800$Feb 20, 20216Feb 20, 20216
Mohsin khanFull account takeover worth $1000 Think out of the boxHi everyone how are you doing today? I hope you are doing great and scoring lots of bounties. Today's story is about a bug I found on…Feb 15, 20219Feb 15, 20219
Sushmitha KatikitalaHow I can take over any user’s account with their mobile numberHi everyone! Hope you all are healthy and safe. This is my first write-up on one of the findings in a private program where I was able to…Sep 6, 20212Sep 6, 20212
Vikash MauryaAccount Takeover + A Bonus VulnerabilityHello everyone, In the article I will explain how I was able to takeover any account of redacted.com. This attack is very much similar to…Jul 18, 20211Jul 18, 20211
RamalingasamyHow can I takeover any account using only their email or mobile number.Hey guys,Jul 19, 20211Jul 19, 20211