Please register to access this content.
To continue viewing the content you love, please sign in or create a new account
Dismiss
This content is for our paying subscribers only

World Americas

Indian gets $6,500 for Uber bug discovery

Anand explained that the bug was an account takeover vulnerability



Uber
Image Credit: Supplied

San Francisco: Global ride-hailing giant Uber has recently fixed a hacking bug found by Indian cybersecurity researcher Anand Prakash which allowed hackers to log into anyone's Uber account.

The company has paid Anand $6,500 (Dh23,874) i.e. about Rs 460,000 as a reward for giving information about this bug.

Anand explained that the bug was an account-takeover-vulnerability on Uber that allowed attackers to take over any other user's Uber account, including those of partners and Uber Eats users, inc42 reported.

As per media report, the bug was present in the API request function of the Uber app.

According to Uber, the bug was immediately fixed through the company's bug bounty programme. It also said that over $2 million was paid to more than 600 researchers around the world, including Indian researchers.

Advertisement

Earlier Anand had once removed a bug in Uber, by taking advantage of which anyone could travel for free for a lifetime in an Uber cab.

Advertisement