Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability |
|
|
|
Imperva Red Team Discovers Vulnerability in TikTok That Can Reveal User Activity and Information |
|
|
|
How I Found an Insecure Direct Object Reference in TikTok |
|
|
|
Stored XSS at https://www.tiktok.com/ the name of the attacker’s account carrying XSS payload will be triggered when the victim Send Video |
|
|
|
Tag Myself in Your Favorite TikTok Artist Video [IDOR] |
|
|
|
Vulnerability in TikTok Android app could lead to one-click account hijacking |
|
|
|
XSS Blind Stored at 2 Assets TikTok |
|
|
|
XSS Blind Stored at Asset Domain Android Apps TikTok |
|
|
|
A Tale of Confusing IDOR |
|
|
|
Multiple vulnerability leading to account takeover in TikTok SMB subdomain. |
|
|
|
Subdomain Takeover via Leadpages Services on Tiktok |
|
|
|
How I hacked worldwide Tiktok users |
|
|
|
TikTok for Android 1-Click RCE |
|
|
|
TikTok Careers Portal Account Takeover |
|
|
|
TikTok fixes privacy issue discovered by Check Point Research |
|
|
|