Source |
The Hacker News |
Identifiant |
2427572 |
Date de publication |
2021-03-03 02:17:44 (vue: 2021-03-03 11:05:47) |
Titre |
A $50,000 Bug Could\'ve Allowed Hackers Access Any Microsoft Account |
Texte |
Microsoft has awarded an independent security researcher $50,000 as part of its bug bounty program for reporting a flaw that could have allowed a malicious actor to hijack users' accounts without their knowledge.
Reported by Laxman Muthiyah, the vulnerability aims to brute-force the seven-digit security code that's sent to a user's email address or mobile number to corroborate his (or her) |
Notes |
|
Envoyé |
Oui |
Condensat |
$50 000 access account accounts actor address aims allowed any awarded bounty brute bug code corroborate could digit email flaw force hackers has have her hijack his independent its knowledge laxman malicious microsoft mobile muthiyah number part program reported reporting researcher security sent seven that user users vulnerability without |
Tags |
Vulnerability
|
Stories |
|
Move |
|