Uber Security Bug: Hacker Gets Free Unlimited Uber Rides
Vittorio HernandezBy selecting an invalid payment method, such as “abc” or “xyz,” an Uber passenger could ride the cab for free. It is an Uber security bug that Anand Prakash, a product security engineer, discovered while testing the app of the ride-hailing service for security loopholes.
Trials In U.S. & India
Prakash tried exploiting Uber’s security loophole and he avoided paying for the ride when he exploited the bug by specifying an invalid payment method, The Telegraph reports. But before he did that, he sought permission from the Uber team and tried the security loophole in India and the U.S. to demonstrate the bug.
“I wasn’t charged from any of my payment methods, Prakash, also a computer programmer, shares. He notes that attackers could misuse the security loophole and get away having unlimited free rides from their Uber accounts. However, since he identified the issue in August 2016, the bug has been fixed and freeloaders could no longer exploit it.
Uber, in turn, rewarded Prakash under its bug bounty hunters program which has 200 researchers looking for bugs that hackers could exploit. The reward for researchers who could identify critical issued could be up to $10,000.
Uber's Bounty Reward
Since it is Prakash’s source of livelihood, he has so far been paid by Uber $13,500 as bounty reward. Besides Uber, Prakash had also identified how to take over any Facebook account and alter its password. As a result, Facebook signed him up under its White Hat bug-finding program where Prakash is one of its top hackers.
Prakash has a blog on web application security where he wrote about the Uber security bug and Facebook hack, The Sun reports. Had he not discovered the bug and other hackers did and exploited it, the security loophole could potentially dent the financial viability of San Francisco-based Uber which has operations in 528 cities globally.
© Copyright 2020 Mobile & Apps, All rights reserved. Do not reproduce without permission.most read
related stories
more stories from News
Experience AI-enhanced One UI 6.1 on your Galaxy Z Fold 4. Upgrade now for smarter interactions and enhanced user experience!
ernest hamiltonBumble's dynamic shift: Women no longer need to make the first move. Explore automated conversation starters and new dynamics!
ernest hamiltonDiscover the latest leaked specs for the Sony Xperia 1 VI, including cameras, chipset, and battery details. Stay updated!
ernest hamiltonThe Rabbit R1 appears to be just an Android app, despite earlier speculations. Read more about Rabbit's denial.
ernest hamiltonGoogle introduces a playful twist to calls with audio emojis, including a fart button. Discover the fun!
ernest hamiltonDiscover how Apple's Safari AI upgrade is revolutionizing browsing. Click to stay ahead with the latest tech insights!
ernest hamiltonStay updated on Apple's efforts to fix iPhone alarm silence bug. Read more for the latest on this critical issue!
ernest hamiltonGoogle transitions Fitbit Pay to Google Wallet worldwide, streamlining payment experiences. Stay informed on this significant development!
ernest hamilton