Technology
Indian bug hunter finds flaw in Instagram, wins $30,000
New Delhi, July 18
Chennai-based security researcher Laxman Muthiyah has won $30,000 as a part of a bug bounty programme after he spotted a flaw in Facebook-owned photo-sharing app Instagram.
Muthiyah said the vulnerability allowed him to to "hack any Instagram account without consent permission."
He discovered it was possible to take over someone's Instagram account by triggering a password reset, requesting a recovery code, or quickly trying out possible recovery codes against the account.
"I reported the vulnerability to the Facebook security team and they were unable to reproduce it initially due to lack of information in my report. After a few email and proof of concept video, I could convince them the attack is feasible," Muthiyah wrote in a blog post this week.
Facebook and Instagram security teams fixed the issue and rewarded me $30,000 as a part of their bounty programme, he added.
Paul Ducklin, Senior Technologist at cyber security major Sophos, however, warned while the vulnerability found by Muthiyah no longer existed, users should familiarise themselves with the process of getting back control of their social media accounts, in case they get hacked.
"In case any of your accounts do get taken over, familiarise yourself with the process you'd follow to win them back. In particular, if there are documents or usage history that might help your case, get them ready before you get hacked, not afterwards," Ducklin said in a statement.
Muthiyah earlier identified not only a data deletion flaw, but also a data disclosure bug on Facebook.
The first bug could have zapped all your photos without knowing your password; the second meant tricking you to install an innocent-looking mobile app that could riffle through all your Facebook pictures without being given access to your account.
"To be clear: he found those holes in compliance with Facebook's Bug Bounty programme, and he disclosed them responsibly to Facebook," Ducklin said.
"As a result, Facebook was able to fix the problems before the bugs became public, and (as far as anyone knows) these bugs were patched before anyone else found them," he remarked.
Muthiyah said the vulnerability allowed him to to "hack any Instagram account without consent permission."
He discovered it was possible to take over someone's Instagram account by triggering a password reset, requesting a recovery code, or quickly trying out possible recovery codes against the account.
"I reported the vulnerability to the Facebook security team and they were unable to reproduce it initially due to lack of information in my report. After a few email and proof of concept video, I could convince them the attack is feasible," Muthiyah wrote in a blog post this week.
Facebook and Instagram security teams fixed the issue and rewarded me $30,000 as a part of their bounty programme, he added.
Paul Ducklin, Senior Technologist at cyber security major Sophos, however, warned while the vulnerability found by Muthiyah no longer existed, users should familiarise themselves with the process of getting back control of their social media accounts, in case they get hacked.
"In case any of your accounts do get taken over, familiarise yourself with the process you'd follow to win them back. In particular, if there are documents or usage history that might help your case, get them ready before you get hacked, not afterwards," Ducklin said in a statement.
Muthiyah earlier identified not only a data deletion flaw, but also a data disclosure bug on Facebook.
The first bug could have zapped all your photos without knowing your password; the second meant tricking you to install an innocent-looking mobile app that could riffle through all your Facebook pictures without being given access to your account.
"To be clear: he found those holes in compliance with Facebook's Bug Bounty programme, and he disclosed them responsibly to Facebook," Ducklin said.
"As a result, Facebook was able to fix the problems before the bugs became public, and (as far as anyone knows) these bugs were patched before anyone else found them," he remarked.
7 hours ago
From security cooperation to bilateral payment linkages: India, Malaysia sign six key pacts
7 hours ago
PM Modi's efforts in peacekeeping are unequivocal: Malaysian PM Anwar Ibrahim
7 hours ago
Our stance on terrorism firm, no double standards, no compromise: PM Modi in Malaysia
7 hours ago
True friend, full of trust and understanding: Malaysian PM Ibrahim on PM Modi
7 hours ago
North Korea to convene key party congress in late February
7 hours ago
Netanyahu to meet Trump in Washington, discuss Iran talks
7 hours ago
Heavy security blanket for Amit Shah’s Puducherry visit on Feb 14; BJP steps up poll preparations
7 hours ago
Group II and II-A main exams postponed in TN after widespread irregularities claims at test centres
7 hours ago
Fire breaks out in moving train in Rajasthan's Jaisalmer; no casualties reported
7 hours ago
Quack's clinic raided in Telangana, drugs seized
8 hours ago
Female foetus found in Rajasthan's Alwar
8 hours ago
CM Himanta Sarma asks Centre to probe ‘Pakistan links’ of Cong MP Gaurav Gogoi
8 hours ago
'Gaurav Gogoi was digitally silent for 10 days in Pakistan': Assam CM raises questions
