Justdial patches security flaw that exposed sensitive data of over 156 million accounts

SHARE:

In the world of constant data leaks and breaches, you can now add one more company to the list. A critical security flaw was found on Justdi...

In the world of constant data leaks and breaches, you can now add one more company to the list. A critical security flaw was found on Justdial, which could enable attackers to access sensitive account information of 156.1 million users on the platform. Justdial has now patched the flaw but we suggest you change your account password right away, in case you use the platform. The issue reportedly stemmed from Justdial’s Register API that would enable an attacker to get access into any Justdial account by using a phone number in the username parameter. The flaw was reported by the security researcher Ehraz Ahmed, via MoneyControl.

As per the report, the Register API vulnerability could enable hackers to access anyone’s Justdial account. This would be done by replacing the phone number under the username parameter so that the system returns an access token, system ID (SID) and user ID (UID). The SID would then be used to access the account and another accounts linked to it while the UID enabled posting on the user’s Justdial Social Profile. The worrying bit is that accessing a Justdial account also gives access to the Justdial Pay account and its settings can be changed to redirect funds to another bank account. However, transferring existing funds to another account is not possible since an account or UPI pin is required to confirm the transaction. 

The security researcher also mentions that hackers and telemarketers can mine Justdial data by using a script and phone number dumps found online. You can see how Ahmed exploited the flaw to gain access to a Justdial account from the video above. As mentioned above, Justdial patched the flaw and sent out a statement to the media that reads, “We at Justdial take security seriously. There was a bug in one of our API which could potentially be accessed by an expert hacker. This bug has been fixed. We work with various security researchers to strengthen our platform and would like to thank Ehraz Ahmed for bringing this out to us.”



from Latest Technology News https://ift.tt/2VvgSkt

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: Justdial patches security flaw that exposed sensitive data of over 156 million accounts
Justdial patches security flaw that exposed sensitive data of over 156 million accounts
https://i.ytimg.com/vi/2KUoT5xpOn0/hqdefault.jpg
https://i.ytimg.com/vi/2KUoT5xpOn0/default.jpg
Genius Baba
https://geniusbabaa.blogspot.com/2019/10/justdial-patches-security-flaw-that.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2019/10/justdial-patches-security-flaw-that.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy