writeups.xyz writeups.xyz / Arne Swinnen (@ArneSwinnen)

Title Vulnerabilities Programs Authors
Authentication bypass on Uber’s Single Sign-On via subdomain takeover
Authentication bypass on Airbnb via OAuth tokens theft
Authentication bypass on Ubiquity’s Single Sign-On via subdomain takeover
How I Could Steal Money from Instagram, Google and Microsoft
InstaBrute: Two Ways to Brute-force Instagram Account Credentials
How I Could Compromise 4% (Locked) Instagram Accounts