Uber Security Bug: Hacker Gets Free Unlimited Uber Rides
Vittorio HernandezBy selecting an invalid payment method, such as “abc” or “xyz,” an Uber passenger could ride the cab for free. It is an Uber security bug that Anand Prakash, a product security engineer, discovered while testing the app of the ride-hailing service for security loopholes.
Trials In U.S. & India
Prakash tried exploiting Uber’s security loophole and he avoided paying for the ride when he exploited the bug by specifying an invalid payment method, The Telegraph reports. But before he did that, he sought permission from the Uber team and tried the security loophole in India and the U.S. to demonstrate the bug.
“I wasn’t charged from any of my payment methods, Prakash, also a computer programmer, shares. He notes that attackers could misuse the security loophole and get away having unlimited free rides from their Uber accounts. However, since he identified the issue in August 2016, the bug has been fixed and freeloaders could no longer exploit it.
Uber, in turn, rewarded Prakash under its bug bounty hunters program which has 200 researchers looking for bugs that hackers could exploit. The reward for researchers who could identify critical issued could be up to $10,000.
Uber's Bounty Reward
Since it is Prakash’s source of livelihood, he has so far been paid by Uber $13,500 as bounty reward. Besides Uber, Prakash had also identified how to take over any Facebook account and alter its password. As a result, Facebook signed him up under its White Hat bug-finding program where Prakash is one of its top hackers.
Prakash has a blog on web application security where he wrote about the Uber security bug and Facebook hack, The Sun reports. Had he not discovered the bug and other hackers did and exploited it, the security loophole could potentially dent the financial viability of San Francisco-based Uber which has operations in 528 cities globally.
© Copyright 2020 Mobile & Apps, All rights reserved. Do not reproduce without permission.most read
related stories
more stories from News
Join the reunion of iPhone and Pixel at Coachella in the #BestPhonesForever ad campaign. Experience the excitement!
ernest hamiltonHuawei challenges Apple with the new Pura 70 amid chip scrutiny. Explore the details of their fresh lineup in China.
ernest hamiltonLearn about Google's bold move in merging its Android and Hardware teams, emphasizing AI integration. Read more!
ernest hamiltonExplore Samsung's latest budget offering, the Galaxy A35 5G! Discover how this new phone delivers quality without compromise.
ernest hamiltonGet ready for an epic showdown as 'Street Fighter: Duel' partners with the Teenage Mutant Ninja Turtles in an exciting collaboration! Join the action now!
ernest hamiltonExplore the world of classic gaming with Delta, the iOS Game Boy emulator that's here to stay, but still probable. Dive into nostalgia now!
ernest hamiltonStay secure with Samsung's April 2024 Security Patch, now available for select Galaxy devices. Update yours today!
ernest hamiltonGet a sneak peek at iOS 17.5 Beta 2! Explore the exciting new features coming soon to your iPhone.
ernest hamilton