Technology
Chennai techie finds flaw in Instagram again, wins $10,000
Chennai, Aug 26
Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.

2 hours ago
Fuel switches were turned off prior to the accident of the Air India Boeing 787.

7 hours ago
Reji Valiyakala from New York Speaks on the Importance of Life Insurance

10 hours ago
GOP senators alarmed by Hegseth's Ukraine aid freeze, seek probe

12 hours ago
Tesla to India: First showroom to open in Mumbai on July 15.

12 hours ago
Nasscom US CEO Forum launched; aims to strengthen India–US tech ties.

12 hours ago
US: Trump, First Lady to visit flood-hit Texas as rescue ops continue

13 hours ago
Tara K. Menon, an Indian-origin scholar at Harvard University, receives the Roslyn Abramson Award.

13 hours ago
Zelensky meets US Senators on sidelines of Ukraine Recovery Conference in Rome

13 hours ago
MoS Margherita meets US Secretary of State in Malaysia

13 hours ago
South Korea, US, Japan stage joint air drills involving B-52 bomber

13 hours ago
Canada will defend its workers, businesses: PM Carney responds to Trump’s tariff threat

13 hours ago
Indians lead among the richest immigrants in America; 12 Indian-origin individuals featured on Forbes list.

16 hours ago
Coast Guard rescues two crew members from stranded US yacht