Indian security Scholar gets Rs 36 lakh prize from Microsoft for bug alert
Indian security Scholar gets Rs 36 lakh prize from Microsoft for bug alert
Share:

Great recognition, Microsoft has awarded USD50,000 (Approx Rs 36 lakh) to a Chennai-based security researcher for spotting vulnerability on the company's online services that "might have allowed anyone to take over any Microsoft account without consent".

After assessing his report, the Microsoft security team patched the issue and rewarded him USD 50,000 as a part of their Identity Bounty Program, security researcher Laxman Muthiyah wrote in a blog post on Tuesday. Muthiyah had earlier won bug bounty from Facebook for finding a similar account takeover vulnerability in Instagram.

"I found Microsoft is also using the similar technique to reset user's password so I decided to test them for any rate limiting vulnerability," he said.  Muthiyah explained that to reset a Microsoft account's password, users need to enter email address or phone number in their forgot password page. After that, they will be asked to select the email or mobile number that can be used to receive the security code.  Once they receive the 7-digit security code, they will have to enter it to reset the password.

"Here, if we can brute-force all the combinations of 7 digit code, we will be able to reset any user's password without permission. But, obviously, there will be some rate limits that will prevent us from making a large number of attempts," he said.

"Putting all together, an attacker has to send all the possibilities of 6 and 7 digit security codes that would be around 11 million request attempts and it has to be sent concurrently to change the password of any Microsoft account (including those with 2FA enabled)," he added.   After several days of efforts, he was able to spot the account takeover flaw.

 

Wait and Watch Apple’s foldable iPhone likely to launch in 2023,

Tech Update: NASSCOM launches campaign to accelerate AI-led innovation

Animate your old photos with this awesome new Artificial intelligence

 

Join NewsTrack Whatsapp group
Related News