test-account-abuse

1 article
sort: new top best
clear filter
0 7/10

A rate-limiting bypass vulnerability allowed attackers to brute-force Instagram account passwords through Facebook's mobile endpoint by distributing attempts across multiple test accounts created via Facebook apps, enabling up to 6 million password attempts daily instead of the intended 20 per account.

Instagram Facebook Sameer Rao mbasic.facebook.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details