Swinnen: How I broke Instagram

Security researcher Arne Swinnen found out on Instagram που επιτρέπουν την ανεύρεση κωδικών πρόσβασης των μελών του με επιθέσεις brute force. Το κενό ασφαλείας θα επέτρεπε στον ερευνητή να αποκτήσει πρόσβαση σε περίπου 20 accounts.Instagram

NVISO researcher reports a gap in authentication coupled with a vulnerability in object reference allowed attackers to access 4% of the accounts that were in temporary lock status.

Facebook owned by Instagram rewarded Swinnen (@arneswinnen) with 5000 dollars to announce the vulnerability, and within 10 days developed a patch that corrects the security vulnerability.

Swinnen discovered an account verification link with a demo and then started changing the user ID in the URL trying a million accounts.

The verification format was different for different accounts. Some accounts were secure, while others allowed an attacker to intercept passwords.

"The case was quite embarrassing, as an attacker could collect sensitive user information (phone numbers) on the one hand, and on the other hand change the phone numbers associated with the victim's account on Instagram," Swinnen said.

More details from the link below:

https://www.arneswinnen.net/2016/03/how-i-could-compromise-4-locked-instagram-accounts/

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).