Instagram hacked: completely….

Ο Wesley Wineberg, ένας ανεξάρτητος ερευνητής ασφαλείας, που συμμετείχε στο πρόγραμμα bug bounty του Facebook, κατάφερε να σπάσει τις άμυνες του Instagram και να αποκτήσει σχεδόν τον πλήρη έλεγχο της υπηρεσίας. Όταν ο ερευνητής αποκάλυψε την ευπάθεια στο Facebook, η threatened to sue him, rather than pay his fee.hack Instagram

Wineberg began his research into Instagram's systems after a friend advised him that the site sensu.instagram.com, provides access to the Instagram admin panel.

The researcher identified the software that ται από το πάνελ διαχείρισης, (Sensu-Admin), και χρησιμοποιώντας μια παλαιότερη which states that the software may be vulnerable to RCE (remote code execution), managed to gain access to one of the configuration files containing the Sensu credentials associated with a PostgreSQL database.

In this database, Wineberg discovered over 60 λIemployee compliments on Instagram and Facebook. The codes they were encrypted with bcrypt, but that didn't stop him from cracking some that were very easy (changeme, Instagram, password).

So soon she was able to log-in to the sensu environment.

But Wineberg did not stop here. From the configuration files, he discovered an access key to an account (AWS Amazon Web Services), which is used to access various S3 (data storage) drives.
He also discovered Instagram SSL certificates, keys and other APIs used to interact with other services, user photos, and static content on Instagram.com.

http://exfiltrated.com/research-Ιnstagram-RCE.php

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).