Skip to main content

Indian techie awarded 10,000 for discovering a flaw in Instagram

Facebook has awarded an Indian techie $10,000 for spotting a flaw in the app. Interestingly, he was awarded $30,000 by Facebook for finding a bug in the mobile recovery flow of the Facebook-owned photo and video sharing app. Chennai-based security researcher Laxman Muthiyah said he again discovered a new account takeover vulnerability in Instagram. The new vulnerability is similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.

Facebook says it has fixed the spotted vulnerability. "Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post. 

The vulnerability could allow hackers to use the same device ID - the unique identifier used by Instagram server to validate password reset codes - to request multiple passcodes of different users.

In reply, Facebook said in a letter to Muthiyah, "You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery.”

Last month, he found a bug that allowed hackers to hack in three simple steps:

Triggering a password reset. Requesting a recovery code. Quickly trying out every possible recovery code against the account.

While looking for an account takeover vulnerability, the techie turned his attention to the Instagram forgot password endpoint. Last month he claimed that he had sent thousands of requests to check whether Instagram’s systems are validating and rate limiting the requests properly. He found he was able to send requests continuously without getting blocked. In order to be able to change the password, he needed the code (which was sent to the account user’s registered mobile number). So there was only one, hit-and-trial, method that could have provided him with success. 

This is not the second time Muthiyah has found a flaw in a Facebook app. In the past, he uncovered a data deletion flaw and a data disclosure bug on Facebook as well. 



from Latest Technology News https://ift.tt/2PdpVXQ

Comments

Popular posts from this blog

PS5 unboxing videos show how huge the console is

To say that Sony has been a bit coy when it comes to the PlayStation 5 would be a bit of an understatement. The company only recently announced the India pricing of the console and now finally we have unboxings of the console going live and one thing is pretty clear - The console is HUGE!  So what do you get in the box? Well… besides the console itself (and the manuals), you get: DualSense controller USB Type-C charging cable for the controller HDMI 2.1 cable Power cable for the console (no bulky adapter/box) Plastic stand Now the plastic stand is used if you place the console on its side. As there is no flat surface on either side of the console, the stand will ensure that it remains still. But you can also place it when propping up the console vertically. However, it does seem like the PS5 can stand on its own vertically if need be. IGN’s unboxing video gives you a good idea of how to place the stand. All of the unboxing videos mention the size of the console because it is pr...

Pixel 4a (5G) Model Tipped in Google Camera v7.5 App Code, Pixel 5 XL May Not Launch This Year: Report

Google Camera app version 7.5 teardown, rolled out for Android 11 beta users, shows mentions of three upcoming Pixel devices - Pixel 4a, Pixel 4a (5G), and Pixel 5, with no reference to the Pixel 5 XL. This hints that Google may be ditching the Pixel 5 XL this year. The codenames of the three upcoming Pixel devices are listed to be sunfish, bramble... from Gadgets 360 https://ift.tt/3gd9bJp