On Monday, he again discovered a defect in the photo and video-sharing app winning him a whopping $10,000 prize as part of the social network’s bug bounty programmer.
Armed with smartphones, Myanmar e-sports players battle power outages
The unique identifier Instagram server which is used to approve password reset codes can be used to request multiple passcodes of different users.
“Last month, I published a write-up on Instagram account takeover vulnerability where I was able to hack any Instagram within 10 minutes. This is also a similar vulnerability with less severity,” stated Muthiyah in a blog post.
Tencent launches WeChat for drivers
Furthermore, Muthiyah showed how this defect be exploited to easily hack Instagram accounts.
Muthiyah detected similar vulnerability to the one he had previously reported in July which enabled anyone to hack accounts without consent and permission.
This story originally appeared on The Economist.
COMMENTS
Comments are moderated and generally will be posted if they are on-topic and not abusive.
For more information, please see our Comments FAQ