Jump to content

Man Awarded $30,000 Bounty After Spotting Major Privacy Bug In Instagram


Recommended Posts

Posted

A Chennai based security researcher has hit gold for finding a flaw in the famous photo sharing app Instagram, reports NDTV

a26ca719-07d0-4840-8a7f-ae05b6a2249b.jpg Source: Unsplash.com

Laxman Muthiyah won $30,000 or ₹20,64,532 as part of a bug bounty programme for finding a vulnerability in the app, which allowed him to hack any Instagram account without the account holder's permission. 

facc2eb8-43e0-4945-b097-53f69260b8a3.jpg Source: Hindustan Times
 

He claimed he could take over any account by simply triggering a password reset, requesting a recovery code, or by quickly trying out multiple recovery codes against the account.

 
He added in his blog

I reported the vulnerability to the Facebook security team and they were unable to reproduce it initially due to lack of information in my report. After a few email and proof of concept video, I could convince them that the attack is feasible. 

b6b991c5-8364-4e9e-8b3b-bb6e0511e355.jpg Source: Hackread.com

Muthiyah not only found a data deletion flaw on Instagram, but also found a data disclosure bug on Facebook. For this, he was rewarded $30,000 by Facebook and Instagram's security team. 

c4d820d3-7329-4053-a407-53b7fe1746e2.jpg Source: We Live Security
 

The bug that Muthiyah had spotted no longer exists and the Tamil Nadu researcher was hailed for hacking the accounts ethically in compliance with Facebook's Bug Bounty programme. 

 
He disclosed the bugs responsibly to the respective agencies, nullifying the threat on millions of Instagram accounts that were earlier prone to being hacked. 

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...