Technology
Chennai techie finds flaw in Instagram again, wins $10,000
Chennai, Aug 26
Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
2 hours ago
UAE: Two Indians among four injured by missile debris in Dubai
3 hours ago
AAPI Announces 44th Annual Convention In Tampa, FL
3 hours ago
US presses Iran with strikes, open to deal
3 hours ago
Trump slams allies France and UK over Iran, Hormuz
3 hours ago
US signals action to keep Hormuz open
3 hours ago
US troops push for faster, decisive Iran war
4 hours ago
Trump invites King Charles, Camilla for state visit as US commemorates 250th Independence anniversary
5 hours ago
Russia expecting PM Modi's visit to Moscow in 2026: Deputy FM Rudenko
9 hours ago
From Nalanda to Prayagraj, crowd crush incidents raise safety concerns
10 hours ago
Bhumi Pednekkar says it’s ‘heartbreaking’ to see women-led stories shrinking in mainstream cinema
10 hours ago
‘Satrangi - Badle Ka Khel’ starring Mahvash, Kumud Mishra to tell story of cross-dressing dancer burning with vengeance
10 hours ago
4th Florida South Asian Film Festival (FL-SAFF) Showcases Global South Asian Cinema in New Jersey
10 hours ago
Simbu-starrer Arasan's shooting to be wrapped up by June first week?
