Security researcher Arne Swinnen discovered security flaws on Instagram that allow the retrieval of members' passwords via brute force attacks. The security flaw would allow the researcher to gain access to approximately 20 million accounts.
NVISO researcher reports that a vulnerability in authentication combined with a direct object reference flaw allowed attackers to gain access to 4% of accounts that were in a temporary lock state.
Facebook, which owns Instagram, rewarded Swinnen (@arneswinnen) with $5,000 for reporting the vulnerability, and within 10 days, it developed a patch that fixes the security hole.
Swinnen discovered an account verification link with a test account and then began changing the user identifier in the URL, testing one million accounts.
The verification format was different for various accounts. Some accounts were secure, while others gave an intruder the ability to steal passwords.
“The case was quite annoying, as an intruder could on one hand gather sensitive user information (phone numbers) and on the other hand change the phone numbers linked to the victim's Instagram account,” says Swinnen.
More details from the link below:
https://www.arneswinnen.net/2016/03/how-i-could-compromise-4-locked-instagram-accounts/
