PinnedCritical Account Takeover (MFA + Auth Bypass) due to Cookie MisconfigurationHello Folks,Dec 1, 2024A response icon2Dec 1, 2024A response icon2
PinnedHow I Deleted Users from the Database on Private Bug Bounty ProgramHello Friends,Oct 16, 2024Oct 16, 2024
Pinned2FA Bypass Using Custom Cookie ParameterHello All,May 22, 2023A response icon4May 22, 2023A response icon4
Pinned2FA Enabled Accounts Can Bypass Authentication & Access Account After DeactivationHello All,Nov 27, 2022A response icon2Nov 27, 2022A response icon2
PinnedAccess Any Owner Account without Authentication (Auth bypass + 2FA bypass)Hello Folks,Nov 27, 2022A response icon1Nov 27, 2022A response icon1
Critical Authentication Bypass & Account Takeover via Attacker’s MFA CodeHello Folks,Dec 8, 2024Dec 8, 2024
Payment Bypass via API Request to Activate Premium Plan on Private Bug Bounty ProgramHello Folks,Oct 28, 2024A response icon1Oct 28, 2024A response icon1
Passively Found Secrets in Javascript File on a Private Bug Bounty ProgramHello Friends,Oct 14, 2024Oct 14, 2024