Explorer

Chennai Techie Finds Flaw In Instagram Again, Wins $10,000

The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.

Chennai: Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme. The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission. Facebook has now fixed the vulnerability that Muthiyah reported. "Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post. Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users. He showed that this vulnerability can be exploited to hack Instagram accounts. "You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.

Top Headlines

Iran To Target 18 US Companies In Middle East Including Microsoft, Apple, Google From April 1
Iran To Target 18 US Companies In Middle East Including Microsoft, Apple, Google
Trump Shares Poll Claiming 89% Support For Iran War, Says Conflict Nearing End
Trump Shares Poll Claiming 89% Support For Iran War, Says Conflict Nearing End
Air India Express Flight Sends Mayday Alert Mid-Air, 148 Passengers Safe After Emergency Landing In Lucknow
Air India Express Flight Issues Mayday Mid-Air, Makes Emergency Landing In Lucknow
Who Is New IndiGo CEO William Walsh, & Why It Matters To You Now
Who Is New IndiGo CEO William Walsh, & Why It Matters To You Now

Videos

POLITICAL ACE: Former Tennis Star Leander Paes Joins BJP Ahead of Bengal Elections
GLOBAL CONFLICT: AI-Assisted Strikes Escalate US-Israel Attacks on Iran, 11 Dead in Mahallat
GLOBAL ALERT: Iran Threatens UAE as US Considers Ground Operation on Kharg Island
TRAGEDY ALERT: Nalanda Temple Stampede Claims 8 Lives Amid Mahavir Jayanti Crowds
War Update: UAE intercepts Iranian Shahed drones mid-air, video surfaces

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget