22 ms·
How two dead accounts allowed remote crash of any Instagram Android user
- dillonmckay 7y agoAny speculation on what a bounty like this is worth?
- netdur 7y agoMore like debugging than security researching? Wonder how much he got! Congratulations
- donretag 7y agoWas about to comment the same thing. Just an average bug, not a security issue.
- valbrux 7y agoI would like to highligth that after the exploitation the instagram application could not be successfully opened until the affected users were removed from the group
- spydum 7y agoin what way is denial of service not a security issue? It may not be omg-sql-injection, or myspace worm-worthy.. but it's availability is the "a" in the C-I-A security triad.
- tyingq 7y ago"java.lang.NullPointerException" That is probably responsible for more of the lost sleep in my life than any other single entity. Various versions of "out of file descriptors" might be a close second.
- tormeh 7y agoTo be fair, all new serious languages now don't have null pointers. ... but we'll still struggle with java.lang.NullPointerException in 2080.
- gdy 7y agoAnd serious languages are those that don't have null pointers?
- fortran77 7y agoThe original 8-bit BASICs didn't have null pointers. They were _serious_ languages!
- pg_is_a_butt 7y agoPHP is moving away from that... what a joke
- jsjohnst 7y agoSo is Go not a “new serious language”? You can definitely have nil pointers panic in Go if written poorly.
- grapehut 7y agoGo is even worse. They just use the word "nil" instead of "null". Go does a lot of really silly things too, like the nil pointer receiver's (basically something that allow you dereference null in certain contexts) ends up having terrible side-effects on the type theory and you end up with really stupid exceptions, like nil represents an empty slice and you can do stuff like get it's size or append to it, but the same operations would cause a panic with a map. But both Java and Go are serious languages.
- mikeyk 7y agoIG co-founder here: users 1 and 2 were our first two attempts at creating users end to end when getting Instagram v0.1 hooked up to the backend we'd written. There was a bug so they were left in an incomplete state; post bugfix, 3 was my co-founder Kevin and 4 is me.
- JorgeGT 7y agoTwo ghost users, left in an incomplete state by a bug in a previous version of the codebase... you basically created the Twins from The Matrix!
- UncleEntity 7y agoAt my work there were some drivers who cloned the app and were using (a presumably hacked version of) it on another tablet with the "test user" ID to make a whole bunch of money, they could see where the trips were going and would only take the really good ones. Bare minimum we're probably talking at least an extra $1k/week. Who knows how long they got away with this before someone noticed "ghost tablets" logged into the system and locked down the test user account -- which is also how they got caught because they then had to log in with their actual ID and The Powers That Be could pinpoint who exactly was doing it. So, yeah, lock down invalid user account IDs.
- Dylan16807 7y agoSo any account could do this? It doesn't sound like extra IDs were the real problem. And there's something deeply sad about "they prioritized the better jobs, so we blacklisted them".
- larkeith 7y agoOriginal (non-Medium) post: https://www.valbrux.it/blog/2019/09/13/how-two-dead-users-allowed-remote-crash-of-any-instagram-android-user/ https://www.valbrux.it/blog/2019/09/13/how-two-dead-users-al...