Maybe that is expecting too much from Justin Bieber and Selena Gomez, however, it should be something that should make API security concerns viral and mainstream. Initially, the API security breach was purportedly limited to "high-profile" users ala Gomez, et. al.
The latest report shows that database of over 10,000 users may have been exposed and potentially over 6 million users' data scraped for sale @ $10/query. For details see:
Site sells Instagram users’ phone and e-mail details, $10 a search
Technical Details: Here are the steps that the hackers may have taken for this API Security Breach:
- Pick outdated Instagram mobile app version 8.5.1
- Create a valid Instagram account
- Select password-reset option.
- Use web-proxy servers to act like the mobile app calling the Instagram Servers.
- Modify the request at the web-proxy with the user id of the celebrity.
- The Instagram server would send a JSON-formatted response with personal information.
No comments:
Post a Comment