Back to directory
WRITEUP #1110

Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability

XSSAccount takeoverOAuth
bymrhavit
Program
TikTok
Published
Jun 4, 2023
Added to HackDex
Jun 5, 2023
Read Full Writeuphttps://medium.com/@mrhavit/breaking-tiktok-our-journey-to-finding-an-account-takeover-vulnerability-b0646aba1c4b
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Stealing First Party Access Token of Facebook Users: Meta Bug Bounty
OAuthAccount takeover
Over 1 Million websites are at risk of sensitive information leakage - XSS is dead. Long live XSS
XSSOAuth
Self XSS + Login CSRF + OAuth = Account Takeover
Auth BypassAccount takeover
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat