HomeSecurityWhite hat hacker showed how Instagram accounts can be hacked

White hat hacker shows how Instagram accounts can be hacked

Facebook has offered $10,000 to a white hat researcher named Laxman Muthiyah after he discovered a critical vulnerability that could be used by malicious hackers to hack Instagram accounts.Instagram

The issue was identified in the Instagram mobile password recovery process .When someone wants to reset their password, a six-digit code is sent to their phone.

The social networking platform uses a mechanism to prevent brute-force attacks aimed at obtaining this password.

Muthiyah discovered that Instagram randomly generates an ID for each device, which is included in the password reset request .This ID is also used to check the validity of the password.

The researcher discovered that Instagram allowed the same device ID to be used for multiple different user accounts. This could help hackers carry out brute-force attacks and obtain the six-digit passwords.

“As you can see in my previous post, the device ID is a unique identifier used by the Instagram server to validate codes, which are used to reset the password. When a user makes a request for a code using their mobile device, a device ID is sent along with the request,” the researcher wrote. “The same device ID is also used to verify the code.”.

White hat hacker shows how Instagram accounts can be hacked

“The device ID is a random string generated by the app ,” he said.

The white hat hacker explained that there are a million combinations for a 6-digit password (000001 to 999999). It is possible that the possibility of hacking Instagram accounts by requesting multiple users to reset their passwords is increasing.

Using the same device ID, a malicious hacker could obtain the six-digit password of thousands of users.

Facebook offered Muthiyah $10,000 as a reward for his findings.

This isn't the first time Muthiyah has exposed a bug in Instagram. In July, the researcher discovered a vulnerability that allowed attackers to take control of any account.

Muthiyah had received a $30,000 reward from Facebook as part of bug bounty program .

In the past, the same researcher had received other rewards from the platform for identifying bugs that could delete users' videos and photos

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS