Technology
Chennai techie finds flaw in Instagram again, wins $10,000
Chennai, Aug 26
Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.

12 hours ago
Pak Army official sparks outrage with throat slit gesture at London protest against J&K terror strike

12 hours ago
Pak Army Chief escalates anti-India rant, rakes up two-nation theory again

12 hours ago
Over two lakh people, top world leaders attend funeral ceremony of Pope Francis at Vatican

12 hours ago
Meeting has potential to become historic, says Zelensky after holding talks with Trump in Rome

12 hours ago
"That was bad one": US President Donald Trump on Pahalgam terrorist attack

12 hours ago
FBI arrests Wisconsin judge for allegedly obstructing immigration agents

12 hours ago
US: Luigi Mangione, accused of killing UnitedHealthcare CEO, pleads not guilty to federal charges

12 hours ago
US: Musk's DOGE slashes USD 400 million in AmeriCorps grants

12 hours ago
Not in favour of war": Karnataka CM Siddaramaiah's stand on Pahalgam terror attack draws BJP crticism

12 hours ago
Vatican City: President Murmu pays homage to Pope Francis

15 hours ago
Pooja Hegde on song ‘Kanimaa’: My social media is filled with people recreating the hookstep

15 hours ago
Unni Mukundan's fan club issues final warning to fan pages spreading false information about him

15 hours ago
‘Aamar Boss’ trailer starring Raakhee Gulzar tells heartwarming story of mother and son