HackerOne Vulnerability: Common Response Title Leak through Triggers · October 15, 2014 · Bug Bounty Elevation of Privilege HackerONe Insecure Direct Object Reference ·

Facebook FriendFeed Stored XSS · August 8, 2014 · Bug Bounty XSS Facebook API FriendFeed

Facebook MailChimp Application OAuth 2.0 Misconfiguration · August 8, 2014 · Bug Bounty Facebook OAuth MailChimp

Flipkart.com - Elevation of Privilege · March 27, 2014 · Elevation of Privilege Flipkart Insecure Direct Object Reference

SSRF/XSPA in MailChimp · February 18, 2014 · OAuth MailChimp SSRF/XSPA

PayPal CSRF aids in account takeover! · September 21, 2013 · Bug Bounty CSRF PayPal