Back to directory
WRITEUP #2701

Multiple bugs chained to takeover Facebook Accounts which uses Gmail.

XSSCSRFAccount takeover
by@samm0uda(Youssef Sammouda)
Bounty
44,625
Program
Meta / Facebook
Published
May 14, 2022
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://ysamm.com/?p=763
RELATED WRITEUPS
Self-XSS to ATO via Site Features
XSSSelf-XSS
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
XSSReflected XSS
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover
How Almost Sacrificing a University Group Project led to a Microsoft Bug Bounty
XSSCSRF
Interesting Story of an Account Takeover Vulnerability
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat