TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How two dead accounts allowed remote crash of any Instagram Android user

108 pointsby pentestercrabover 5 years ago

6 comments

mikeykover 5 years ago
IG co-founder here: users 1 and 2 were our first two attempts at creating users end to end when getting Instagram v0.1 hooked up to the backend we'd written. There was a bug so they were left in an incomplete state; post bugfix, 3 was my co-founder Kevin and 4 is me.
评论 #20978242 未加载
tyingqover 5 years ago
<i>&quot;java.lang.NullPointerException&quot;</i><p>That is probably responsible for more of the lost sleep in my life than any other single entity.<p>Various versions of <i>&quot;out of file descriptors&quot;</i> might be a close second.
评论 #20977574 未加载
评论 #20977363 未加载
larkeithover 5 years ago
Original (non-Medium) post: <a href="https:&#x2F;&#x2F;www.valbrux.it&#x2F;blog&#x2F;2019&#x2F;09&#x2F;13&#x2F;how-two-dead-users-allowed-remote-crash-of-any-instagram-android-user&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.valbrux.it&#x2F;blog&#x2F;2019&#x2F;09&#x2F;13&#x2F;how-two-dead-users-al...</a>
UncleEntityover 5 years ago
At my work there were some drivers who cloned the app and were using (a presumably hacked version of) it on another tablet with the &quot;test user&quot; ID to make a whole bunch of money, they could see where the trips were going and would only take the really good ones. Bare minimum we&#x27;re probably talking at least an extra $1k&#x2F;week.<p>Who knows how long they got away with this before someone noticed &quot;ghost tablets&quot; logged into the system and locked down the test user account -- which is also how they got caught because they then had to log in with their actual ID and <i>The Powers That Be</i> could pinpoint who exactly was doing it.<p>So, yeah, lock down invalid user account IDs.
评论 #20981921 未加载
netdurover 5 years ago
More like debugging than security researching? Wonder how much he got! Congratulations
评论 #20977175 未加载
dillonmckayover 5 years ago
Any speculation on what a bounty like this is worth?
评论 #20977397 未加载