Swinnen: How I broke Instagram

X X X X X X X X X X X X X X X X Arne Swinnen ανακάλυψε στο Instagram that allow finding codes of its members with brute force attacks. The security flaw would have allowed the researcher to gain access to around 20 million accounts.Instagram

The NVISO researcher reports that an authentication gap coupled with a direct object reference vulnerability allowed attackers to gain access to the 4% of accounts in temporary lock.

Facebook owned by Instagram rewarded Swinnen (@arneswinnen) with 5000 dollars to announce the vulnerability, and within 10 days developed a patch that corrects the security vulnerability.

Swinnen has discovered an account verification link with a test account and then started changing the user ID to the URL by testing a million accounts.

The verification format was different for different accounts. Some were secure, while others allowed an attacker to intercept passwords.

"The case was quite embarrassing, as an attacker could collect sensitive user information (phone numbers) on the one hand, and on the other hand change the phone numbers associated with the victim's account on Instagram," Swinnen said.

More details from the link below:

https://www.arneswinnen.net/2016/03/how-i-could-compromise-4-locked-instagram-accounts/

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).