NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / Indian finds 'account-hacking' bug in Instagram, wins Rs. 20 lakh
    Next Article
    Indian finds 'account-hacking' bug in Instagram, wins Rs. 20 lakh

    Indian finds 'account-hacking' bug in Instagram, wins Rs. 20 lakh

    By Shubham Sharma
    Jul 19, 2019
    08:35 pm

    What's the story

    An Indian security researcher has bagged $30,000 (over Rs. 20 lakh) for flagging a critical bug in Instagram, the photo-sharing service owned by Facebook.

    Laxman Muthiyah was looking for vulnerabilities in Instagram's systems when he detected an issue that allowed him to break into accounts.

    He then reported the bug to Facebook, prompting the company to release an immediate fix for it.

    Here's more.

    Issue

    Bug allowed him to conduct brute-force attacks

    Being a white hat hacker, Muthiyah looked at different ways to break into Instagram accounts.

    First, he tried the platform's website to conduct an attack through the common 'forgot password' endpoint.

    However, after failing to detect a vulnerability on the web, he decided to switch to the mobile app and was able to find a way to conduct a brute-force attack.

    Quote

    Here's what Muthiyah said about Instagram's system security

    On the web, "they have a link based password reset mechanism which is pretty strong and I couldn't find any bugs after a few minutes of testing". However, when I "switched to their mobile recovery flow..I was able to find susceptible behavior."

    Details

    The issue allowed him to take over accounts

    The hack, Muthiyah said, revolved around requesting a new password and trying different possible recovery codes in the least possible time.

    And, it worked for almost every Instagram account, literally giving him the access to any Instagram of his choice without the consent or permission of the main user.

    Naturally, this could have been a major issue if it weren't for the security researcher.

    Facebook's effort

    Instagram has patched the issue, awarded Muthiyah

    When Muthiyah reached out to Facebook with his bug report, the company didn't understand the issue.

    However, after a few emails providing additional information about the issue and a video demonstrating its possible exploit, the company's security recognized the potential threat.

    Post this, Instagram issued a fix for the bug and awarded Muthiyah with $30,000 (Rs. 20 lakh) under its bug bounty program.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Facebook
    Instagram
    Security

    Latest

    Mustafizur Rahman claims 3/33 versus Punjab Kings: Key stats Mustafizur Rahman
    Shreyas Iyer registers his 26th half-century in IPL: Key stats Shreyas Iyer
    Marcus Stoinis surpasses 100 sixes in IPL: Key stats Marcus Stoinis
    Shoaib Bashir claims 6/81 versus Zimbabwe in one-off Test: Stats England Cricket Team

    Facebook

    BJP mixing religion and politics with 'Jai Shri Ram': Mamata West Bengal
    China's 'brain talker' chip can finally bring mind-reading to life Technology
    Kerala: 19-year-old engineer fixes WhatsApp bug, gets honored by Facebook India
    Facebook shareholders want to remove Zuckerberg as Chairman: Here's why Mark Zuckerberg

    Instagram

    Did Sushmita Sen just get engaged to beau Rohman Shawl? Celebrity
    F8: This is how Facebook and Instagram will change now India
    Singer-rapper Badshah now proud owner of super-expensive Rolls Royce Wraith India
    You'll be able to share song lyrics as Instagram stickers Facebook

    Security

    Watch out! Hackers are exploiting WordPress sites to spread malware Malware
    Xiaomi phones plagued by a critical security flaw: Details here Xiaomi
    Hackers sold personal, financial data on Facebook groups: Here's how Facebook
    Want to conceal your location from Google? Here's the way Google Maps
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025