Technology
Chennai techie finds flaw in Instagram again, wins $10,000
Chennai, Aug 26
Barely a month after winning $30,000 from Facebook for spotting a flaw in Instagram, Chennai-based security researcher Laxman Muthiyah on Monday said he again discovered a new account takeover vulnerability on the photo and video-sharing app. This time he has won $10,000 as part of the social network's bug bounty programme.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.
The new vulnerability that Muthiyah spotted was similar to the one he reported in July and allowed anyone to hack Instagram accounts without consent permission.
Facebook has now fixed the vulnerability that Muthiyah reported.
"Facebook and Instagram security team fixed the issue and rewarded me $10000 as a part of their bounty programme," Muthiyah said in a blog post.
Muthiyah found that the same device ID - the unique identifier used by Instagram server to validate password reset codes - can be used to request multiple pass codes of different users.
He showed that this vulnerability can be exploited to hack Instagram accounts.
"You identified insufficient protections on a recovery endpoint, allowing an attacker to generate numerous valid nonces to ten attempt recovery," Facebook said in a letter to Muthiyah.

13 hours ago
"You are biggest fraud to ever sit in United States Senate": FBI Director Kash Patel lashes out at Adam Schiff

13 hours ago
Bystander CPR Training for the Visually Impaired Breaks New Ground at National India Hub

13 hours ago
USCIS Unveils First Changes to Naturalization Test in Multi-Step Overhaul of American Citizenship Standards

13 hours ago
Together, we will take partnership to new heights: Netanyahu's birthday wishes to 'good friend' PM Modi

13 hours ago
Former US NSA calls India 'proud and strong', criticises Trump’s India strategy

13 hours ago
From Punjab to Vancouver, ISI nudges Khalistani outfits to step up psychological warfare

15 hours ago
Colombia stops US arms imports amid rift over drug war decertification

15 hours ago
US President, First Lady participate in Windsor Castle arrival ceremony

16 hours ago
Former US NSA calls India 'proud and strong', criticises Trump’s India strategy

18 hours ago
South Korea, US agree on 'ultimate' goal of denuclearisation of Korean Peninsula

19 hours ago
Together, we will take partnership to new heights: Netanyahu's birthday wishes to 'good friend' PM Modi

19 hours ago
Under your guidance, India achieved impressive results: Putin wishes PM Modi on birthday

19 hours ago
American singer Mary Millben extends heartfelt birthday wishes to PM Modi