race-condition

16 articles
Sort: New Top Best
clear filter
0

Researcher Josip Franjković documented multiple race condition vulnerabilities discovered in Facebook, DigitalOcean, and LastPass that allowed attackers to bypass single-action restrictions by sending concurrent requests—including inflating page reviews, creating multiple usernames, and redeeming promo codes multiple times. All bugs were subsequently fixed and disclosed through responsible disclosure timelines.

Facebook DigitalOcean LastPass Josip Franjković GitHub Team Tasteless
josipfranjkovic.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0

A comprehensive writeup documenting multiple race condition vulnerabilities discovered across major platforms including Cobalt.io, Facebook, Mega, and Keybase, demonstrating how concurrent requests can bypass security controls for unauthorized financial transactions, account confirmations, and resource redemptions. The article includes detailed exploitation techniques and timelines of responsible disclosure across various bug bounty programs.

Josip Franjković Cobalt.io Facebook Mega.nz DigitalOcean Keybase Starbucks Medium LastPass LetsEncrypt HackerOne DefuseSec w3af BlueHat KITCTF
josipfranjkovic.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0

A race condition vulnerability in Facebook chat groups allows an attacker to become invisible in group conversations while maintaining full read/write access and the ability to add/remove users without triggering read receipts. By rapidly adding and removing a target user from a group conversation, an attacker can exploit timing flaws to spy on private group messages undetected.

Facebook Seif Elsallamy Seekurity Mail.ru CVE-2017-17713 CVE-2017-17714 Trape Boxug
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 3 hours ago · details
0
CVE-2026-27748 CVE-2026-27749 CVE-2026-27750
blog.quarkslab.com · Lucas Laise · 9 days ago · details
0
blog.quarkslab.com · Mathieu Farrell · 14 days ago · details
0
intigriti.com · Ayoub · 20 days ago · details
0
blog.quarkslab.com · Mathieu Farrell · 1 month ago · details