HomeSecurityInstagram vulnerability exploit code publicly available

Instagram vulnerability exploit code publicly available

0_600_800_0_70_http---i.haymarket.net.au-News-instagram hack security infosecA developer in London discovered that an Instagram could be easily hacked and released a proof of method to the public after Facebook refused to provide him with a reward for finding the bug, saying they were aware of the problem described.

Due to Instagram's insecure communications, StevieGraham was able to monitor traffic from the Instagram iOS app and retrieve session cookies, which allowed him to compromise the account.

The vulnerability is not new and consists of the fact that Instagram does not have encrypted communication implemented in all its parts and API calls are made to the endpoints via plain HTTP. These contain cookies.

Collecting and tracking cookies can be done easily, with free tools that capture network traffic and place them in a web browser, giving the attacker access to the Instagram, without the need for authentication.

The usual connection to the service is done via encryption, but then communication with cookies is done without encryption.

With access to the account, a potential attacker could initiate the same actions as if they were the account owner, making modifications, adding new content or editing comments. They could also send spam messages or direct other users to pages hosting malicious files and much more.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS