City
Epaper

Indian techie's bug alert wins Rs 36 lakh from Microsoft

By IANS | Updated: March 3, 2021 20:50 IST

Chennai, March 3 Microsoft has awarded a Chennai-based security researcher $50,000 (approximately Rs 36 lakh) for spotting vulnerability on ...

Open in App

Chennai, March 3 Microsoft has awarded a Chennai-based security researcher $50,000 (approximately Rs 36 lakh) for spotting vulnerability on the company's online services that "might have allowed anyone to takeover any Microsoft account without consent".

After assessing his report, the Microsoft security team patched the issue and rewarded him $50,000 as a part of their Identity Bounty Program, security researcher Laxman Muthiyah wrote in a blog post on Tuesday.

Muthiyah earlier won bug bounty from Facebook for finding a similar account takeover vulnerability in Instagram.

"I found Microsoft is also using the similar technique to reset user's password so I decided to test them for any rate limiting vulnerability," he said.

Muthiyah explained that to reset a Microsoft account's password, users need to enter email address or phone number in their forgot password page. After that they will be asked to select the email or mobile number that can be used to receive the security code.

Once they receive the 7-digit security code, they will have to enter it to reset the password.

"Here, if we can bruteforce all the combination of 7 digit code, we will be able to reset any user's password without permission. But, obviously, there will be some rate limits that will prevent us from making a large number of attempts," he said.

After several days of efforts, he was able to spot the account takeover flaw.

"Immediately, I recorded a video of all the bypasses and submitted it to Microsoft along with detailed steps to reproduce the vulnerability. They were quick in acknowledging the issue," Muthiyah said.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Laxman muthiyahmicrosoftFacebookFacebook connectivityAfter facebookNl salviCs - connectivityWhatsapp facebookFacebook newsFacebook twitter
Open in App

Related Stories

Business‘Microsoft Is a Digital Weapons Manufacturer’: Indian-American Engineer Calls Out Gates, Ballmer, Nadella Over AI Ties to Gaza War (Watch Video)

LifestyleEid Mubarak 2025 Wishes: Send Eid Al-Fitr Greetings and Messages on WhatsApp, Facebook to Loved Ones

LifestyleHappy Gudi Padwa 2025: Wishes, WhatsApp Status, Images, Messages, Photos, and Greetings To Share and Celebrate Marathi New Year

NationalHC on Uploading of Intimate Video of Facebook: Marriage Does Not Grant Husband Ownership over His Wife, Says Allahabad High Court

TechnologyFacebook Down: Meta-Owned Social Media Platform Faces Global Outage

Technology Realted Stories

TechnologyZoho CEO Sridhar Vembu has no ‘confidence in tech’, shelves $700 million chip plan

TechnologyYouTube commits Rs 850 crore to power India’s ‘Creator Nation’: CEO Neal Mohan

TechnologyApple clocks 28 pc growth in iPhone shipments in India: Industry data

TechnologyNHRC asks 11 states to boost measures to prevent heat-related deaths

TechnologyNRAI and ONDC refute speculative reports, reaffirm strong partnership