Uber Security Bug: Hacker Gets Free Unlimited Uber Rides
Vittorio HernandezBy selecting an invalid payment method, such as “abc” or “xyz,” an Uber passenger could ride the cab for free. It is an Uber security bug that Anand Prakash, a product security engineer, discovered while testing the app of the ride-hailing service for security loopholes.
Trials In U.S. & India
Prakash tried exploiting Uber’s security loophole and he avoided paying for the ride when he exploited the bug by specifying an invalid payment method, The Telegraph reports. But before he did that, he sought permission from the Uber team and tried the security loophole in India and the U.S. to demonstrate the bug.
“I wasn’t charged from any of my payment methods, Prakash, also a computer programmer, shares. He notes that attackers could misuse the security loophole and get away having unlimited free rides from their Uber accounts. However, since he identified the issue in August 2016, the bug has been fixed and freeloaders could no longer exploit it.
Uber, in turn, rewarded Prakash under its bug bounty hunters program which has 200 researchers looking for bugs that hackers could exploit. The reward for researchers who could identify critical issued could be up to $10,000.
Uber's Bounty Reward
Since it is Prakash’s source of livelihood, he has so far been paid by Uber $13,500 as bounty reward. Besides Uber, Prakash had also identified how to take over any Facebook account and alter its password. As a result, Facebook signed him up under its White Hat bug-finding program where Prakash is one of its top hackers.
Prakash has a blog on web application security where he wrote about the Uber security bug and Facebook hack, The Sun reports. Had he not discovered the bug and other hackers did and exploited it, the security loophole could potentially dent the financial viability of San Francisco-based Uber which has operations in 528 cities globally.
© Copyright 2020 Mobile & Apps, All rights reserved. Do not reproduce without permission.most read
related stories
more stories from News
Billie Eilish fans, get ready! The iconic singer will be performing live at the Fortnite Festival this week. Don't miss out!
ernest hamiltonMoondrop, known for audiophile gear, teases its inaugural smartphone, the MIAD 01, promising a unique blend of audio excellence and mobile technology.
ernest hamiltonAndroid 15 aims to streamline notification channels by hiding unused ones, enhancing user experience and decluttering notification settings.
ernest hamiltonDolphiniOS developers shed light on why the GameCube and Wii emulator won't be available in the App Store.
ernest hamiltonGet your screen fixed! Galaxy S21 and S22 owners in India facing the green line issue can now enjoy free screen replacements. Don't miss out on this offer!
ernest hamiltonStay updated! The second April update for Pixel phones resolves a widespread network issue. Read more to ensure your device stays connected.
ernest hamiltonStay ahead of the curve with Gurman's insights into iOS 18's groundbreaking features. Learn how on-device LLM empowers AI with privacy and speed benefits!
ernest hamiltonTroubled by green lines on your Galaxy phone after the April 2024 update? Learn how to address this screen issue.
ernest hamilton