Express Computer
Home  »  News  »  Indian techie’s bug alert wins Rs 36 lakh from Microsoft

Indian techie’s bug alert wins Rs 36 lakh from Microsoft

0 147

Microsoft has awarded a Chennai-based security researcher $50,000 (approximately Rs 36 lakh) for spotting vulnerability on the company’s online services that “might have allowed anyone to takeover any Microsoft account without consent”.

After assessing his report, the Microsoft security team patched the issue and rewarded him $50,000 as a part of their Identity Bounty Program, security researcher Laxman Muthiyah wrote in a blog post on Tuesday.

Muthiyah earlier won bug bounty from Facebook for finding a similar account takeover vulnerability in Instagram.

“I found Microsoft is also using the similar technique to reset user’s password so I decided to test them for any rate limiting vulnerability,” he said.

Muthiyah explained that to reset a Microsoft account’s password, users need to enter email address or phone number in their forgot password page. After that they will be asked to select the email or mobile number that can be used to receive the security code.

Once they receive the 7-digit security code, they will have to enter it to reset the password.

“Here, if we can bruteforce all the combination of 7 digit code, we will be able to reset any user’s password without permission. But, obviously, there will be some rate limits that will prevent us from making a large number of attempts,” he said.

After several days of efforts, he was able to spot the account takeover flaw.

“Immediately, I recorded a video of all the bypasses and submitted it to Microsoft along with detailed steps to reproduce the vulnerability. They were quick in acknowledging the issue,” Muthiyah said.

–IANS

Get real time updates directly on you device, subscribe now.

Leave A Reply

Your email address will not be published.

LIVE Webinar

Digitize your HR practice with extensions to success factors

Join us for a virtual meeting on how organizations can use these extensions to not just provide a better experience to its’ employees, but also to significantly improve the efficiency of the HR processes
REGISTER NOW 

Stay updated with News, Trending Stories & Conferences with Express Computer
Follow us on Linkedin
India's Leading e-Governance Summit is here!!! Attend and Know more.
Register Now!
close-image
Attend Webinar & Enhance Your Organisation's Digital Experience.
Register Now
close-image
Enable A Truly Seamless & Secure Workplace.
Register Now
close-image
Attend Inida's Largest BFSI Technology Conclave!
Register Now
close-image
Know how to protect your company in digital era.
Register Now
close-image
Protect Your Critical Assets From Well-Organized Hackers
Register Now
close-image
Find Solutions to Maintain Productivity
Register Now
close-image
Live Webinar : Improve customer experience with Voice Bots
Register Now
close-image
Live Event: Technology Day- Kerala, E- Governance Champions Awards
Register Now
close-image
Virtual Conference : Learn to Automate complex Business Processes
Register Now
close-image