Indian techie finds flaw in Instagram again, wins $10,000 reward
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10,000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
Get Latest Business News, Stock Market Updates and Videos; Check your tax outgo through Income Tax Calculator and save money through our Personal Finance coverage. Check Business Breaking News Live on Zee Business Twitter and Facebook. Subscribe on YouTube.
RECOMMENDED STORIES
Fundamental picks by brokerage: These 3 largecap, 2 midcap stocks can give up to 28% return - Check targets
SBI Senior Citizen Latest FD Rates: What senior citizens can get on Rs 7 lakh, Rs 14 lakh, and Rs 21 lakh investments in Amrit Vrishti, 1-, 3-, and 5-year fixed deposits
Tamil Nadu Weather Alert: Chennai may receive heavy rains; IMD issues yellow & orange alerts in these districts
SIP+SWP: Rs 10,000 monthly SIP for 20 years, Rs 25 lakh lump sum investment, then Rs 2.15 lakh monthly income for 25 years; see expert calculations
Top 7 Mutual Funds With Highest Returns in 10 Years: Rs 10 lakh investment in No 1 scheme has turned into Rs 79,46,160 in 10 years
SIP vs PPF: How much corpus you can build in 15 years by investing Rs 1.5 lakh per year? Understand through calculations
Retirement Planning: Investment Rs 20 lakh, retirement corpus goal Rs 3.40 crore; know how you can achieve it
02:48 PM IST