DEV Community

Harsha Hegde
Harsha Hegde

Posted on

Instagram flaw

There is a security flaw in instagram in updating the email Id. Here is how you can exploit.

  1. Create a instagram account, use your genuine email Id
  2. Once the signup is complete, log off
  3. Now go to instagram and say forgot password.
  4. Instagram will send a mail to the email and in bottom there is a link to 'Remove your email from this account.'
  5. Click on that link
  6. Now your instagram account is delinked with the email address
  7. Now again Try to log into account using your instagram Id, now provide the password.
  8. In next screen you will be asked to provide the email Id to link.
  9. In above step you can provide any email Id (if not used in instagram), there is no verfication required!!

Top comments (2)

Collapse
 
moopet profile image
Ben Sinclair

No verification apart from the valid username and password, right?

Collapse
 
harshakhegde profile image
Harsha Hegde

Yes.