Back to directory
WRITEUP #6291

Authentication bypass on Airbnb via OAuth tokens theft

OAuthLogin CSRFOpen redirectAuthentication bypass
by@ArneSwinnen(Arne Swinnen)
Bounty
5,000
Program
Airbnb
Published
Jun 22, 2017
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/
RELATED WRITEUPS
$1600 Bounty on a Main Domain
ReconSession fixation
Self XSS + Login CSRF + OAuth = Account Takeover
Auth BypassAccount takeover
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
How I Got $250 For My Second Bug on HackerOne
OAuthSession expiration issue
The Hunt for ALBeast: A Technical Walkthrough
CloudAWS ALB

Built with ❤️ by Shubham Rawat