Uber Security Bug: Hacker Gets Free Unlimited Uber Rides
Vittorio HernandezBy selecting an invalid payment method, such as “abc” or “xyz,” an Uber passenger could ride the cab for free. It is an Uber security bug that Anand Prakash, a product security engineer, discovered while testing the app of the ride-hailing service for security loopholes.
Trials In U.S. & India
Prakash tried exploiting Uber’s security loophole and he avoided paying for the ride when he exploited the bug by specifying an invalid payment method, The Telegraph reports. But before he did that, he sought permission from the Uber team and tried the security loophole in India and the U.S. to demonstrate the bug.
“I wasn’t charged from any of my payment methods, Prakash, also a computer programmer, shares. He notes that attackers could misuse the security loophole and get away having unlimited free rides from their Uber accounts. However, since he identified the issue in August 2016, the bug has been fixed and freeloaders could no longer exploit it.
Uber, in turn, rewarded Prakash under its bug bounty hunters program which has 200 researchers looking for bugs that hackers could exploit. The reward for researchers who could identify critical issued could be up to $10,000.
Uber's Bounty Reward
Since it is Prakash’s source of livelihood, he has so far been paid by Uber $13,500 as bounty reward. Besides Uber, Prakash had also identified how to take over any Facebook account and alter its password. As a result, Facebook signed him up under its White Hat bug-finding program where Prakash is one of its top hackers.
Prakash has a blog on web application security where he wrote about the Uber security bug and Facebook hack, The Sun reports. Had he not discovered the bug and other hackers did and exploited it, the security loophole could potentially dent the financial viability of San Francisco-based Uber which has operations in 528 cities globally.
© Copyright 2020 Mobile & Apps, All rights reserved. Do not reproduce without permission.most read
related stories
more stories from News
Walmart CEO emphasizes Walmart app usage in stores amidst a reevaluation of self-checkout systems. Learn more by reading the article!
ernest hamiltonOne UI 6.1.1 reportedly introduces exciting video AI features to Samsung devices. Explore the latest enhancements!
ernest hamiltonTencent is gearing up to launch the 'Dungeon and Fighter' mobile game in May, promising an exciting new gaming experience for fans of the franchise.
ernest hamiltonApple's latest software release confirms iPhone AI plans, unveiling eight small AI language models for on-device use, promising enhanced performance and privacy.
ernest hamiltonHMD introduces budget-friendly phones, all under $200, promising affordability without compromise.
ernest hamiltonExperience the latest Android 15 Beta 1.2! Pixel users, unlock additional bug fixes and enhancements now!
ernest hamiltonCheck out the latest from Glance! They're piloting their Android Lockscreen Platform in the US. Don't miss it!
ernest hamiltonExciting news! X plans to launch a Smart TV app for an immersive entertainment experience. Stay tuned!
ernest hamilton