• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

5869

Instagram, owned by Facebook, was recently found to be vulnerable to remote attacks which could even make the attackers to reset the passwords for any Instagram account and take complete control of it.

The flaw was found and reported by Laxman Muthiyah, an Indian bug bounty hunter. He pointed out that ‘password recovery’ feature of the mobile version of Instagram was having the flaw.

The ‘password reset’ or ‘password recovery’ is a feature that enables users to regain access to their accounts in case they forget their password. Recovering an Instagram account on mobile requires a user to provide a six-digit passcode to prove his/her identity. The passcode is sent to the associated mobile number or email account.

In a blog post, Muthaiya said that “My tests did show the presence of rate limiting. I sent around 1000 requests, 250 of them went through and the rest 750 requests were rate limited. Tried another 1000, now many of them got rate limited. So their systems are validating and rate limiting the requests properly.”

What caused the bypass of the rate-limiting mechanism? On further investigation, Race Hazard and IP rotation were said to be the reason for the bypassing of rate-limiting mechanism.

In order to address the vulnerability, Muthiyah has released a proof-of-concept, which has now been patched. Meanwhile, users are advised to enable ‘two-factor authentication’ which could prevent hackers from accessing their accounts even if they manage to steal the passwords

Tags:
joshwariddin
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

Related Tutorials in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

How to Install and Access Facebook Messenger on Linux
How to Install and Access Facebook Messenger on Linux
May 17, 2016
How to install Facebook Messenger 2.0.9 on Linux mint 18.3
How to install Facebook Messenger 2.0.9 on Linux mint 18.3
Mar 24, 2018

Related Forums in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

Related Forums in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

Facebook messenger
jack class=
facebook messenger in linux
May 16, 2017
Facebook messenger
daniel class=
any tool to use whatsapp as well as messenger in linux
May 26, 2017

Related News in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

Related News in Instagram Vulnerability Patched after reported by an Indian Bug Bounty Hunter

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Facebook Live Location service questions privacy and safety concerns.
Facebook Live Location service questions privacy and safety concerns.
Mar 30, 2017
Magecart Targets OpenCart Websites Payment Information
Magecart Targets OpenCart Websites Payment Information
May 17, 2019
WordPress 5.1.1 fixes a threatening XSS vulnerability
WordPress 5.1.1 fixes a threatening XSS vulnerability
Mar 22, 2019
Major Security Flaw Found in Cisco Routers
Major Security Flaw Found in Cisco Routers
Oct 2, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help legeek ?
Installation of the call center module

hello

I wish to install a call center in virtual with issabel, I downloaded the latest version of it , but I don' t arrive to install the call center module in issabel. please help me

thanks!

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.