Explorer

Ahmedabad Security Researcher Paid Rs 23.8 Lakh By Facebook For Identifying Security Bug

An ethical hacker from Ahemadabad has been paid Rs 23.8 lakh by Facebook for exposing a security bug in its social networking platform.

New Delhi: It is raining bug bounties for Indian ethical hackers and cybersecurity researchers as now, an Ahmedabad-based security researcher Bipin Jitiya has won Rs 23.8 lakh ($31,500) from Facebook for identifying a bug in its social networking platform and a third-party business intelligence portal. Jitiya, 26, identified the web security vulnerability in internal blind Server-Side Request Forgery (SSRF) in the source code of a publicly accessible endpoint, built using tools from MicroStrategy, that performed custom data collection and content generation. MicroStrategy has partnered with Facebook on data analytics projects for several years. Jitiya reported the bug to the MicroStrategy's security team, who acknowledged it, saying the issue has been mitigated. "I have always aimed in finding bugs in Facebook because it is the biggest social network on Earth with best-in-class security features in place. This time, they have awarded me with $31,500 for finding a critical bug. I have identified bugs in their systems in the past too," Jitiya said on Monday. In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. In typical SSRF attacks, the attacker might cause the server to make a connection back to itself, or to other web-based services within the organization's infrastructure, or to external third-party systems. "I created a scenario that shows how the sensitive information leakage may be useful for launching specific attacks like path traversal and Server Side Request Forgery (SSRF). If an attacker is able to learn the internal IP addresses of the network, it is much easier for him/her to target systems in the internal network," explained Jitiya. The bug has now been fixed. "When I first got this bug on Facebook server I tried to convert it to RCE (remote code execution) but, unfortunately, they implemented good security measures. However, I made a total of $31500 ($1,000 + $30,000 + $500) from this vulnerability," he informed. On a question whether he would join Facebook cybersecurity research team if given an offer, Jitiya said: "I would like to stay in India and work as a security researcher for Indian firms. I am not a bug bounty hacker". Last month, a 27-year-old Indian security researcher Bhavuk Jain grabbed $100,000 (over Rs 75.5 lakh) from Apple for discovering a now-patched Zero Day vulnerability in the Sign in with Apple account authentication. The Zero Day vulnerability could have allowed a hacker to break into an Apple user's account who log into third-party apps like like Dropbox, Spotify, Airbnb and Giphy (now acquired by Facebook) and more. "Indian ethical hackers and security researchers have come of age, and are now creating headlines the world over with their unmatched skills," said Jitiya. WATCH | Facebook India launches a new security feature

Top Headlines

Samsung Owned 'Ultra'; Apple Owns 'Pro': Now Both Are Using Each Other's Names
Samsung Owned 'Ultra'; Apple Owns 'Pro': Now Both Are Using Each Other's Names
Could iPhone 18 Pro Max Get A 7-Inch Screen? Here Is What Leaks Are Saying
Could iPhone 18 Pro Max Get A 7-Inch Screen? Here Is What Leaks Are Saying
Vivo X300 FE vs X200 FE: One Costs Rs 20,000 More And Still Loses
Vivo X300 FE vs X200 FE: One Costs Rs 20,000 More And Still Loses
Best Smartphones Under Rs 15,000: Poco C85, Galaxy M35, Realme Narzo 100 Lite & More In Focus
Best Smartphones Under Rs 15,000: Poco C85, Galaxy M35, Realme Narzo 100 Lite & More In Focus

Videos

Bashir Badr Death: Legendary Urdu Poet Passes Away in Bhopal, Leaves Behind Timeless Legacy of Shayari
Breaking: BJP Announces New State Chiefs for Delhi, Haryana, Punjab and Tripura Ahead of Key Poll Battles
Breaking: Karnataka Power Shift Complete: Siddaramaiah Resigns, DK Shivakumar Set to Take Over
Breaking: Amit Shah Claims Illegal Infiltrators Leaving Bengal as BJP Govt Tightens Crackdown
Tusha Sharma Death: CBI Tightens Grip as Giribala Singh’s Arrest Looms Large

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget