{"id":183157,"date":"2019-10-10T10:25:56","date_gmt":"2019-10-10T07:25:56","guid":{"rendered":"http:\/\/ww-vb.mine.nu\/w108\/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts\/"},"modified":"2019-10-10T10:26:05","modified_gmt":"2019-10-10T07:26:05","slug":"a-bug-in-indian-local-search-app-exposed-over-156-million-accounts","status":"publish","type":"post","link":"https:\/\/hameed.nwar.uk\/sa\/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts\/","title":{"rendered":"A bug in Indian native search app uncovered over 156 million accounts"},"content":{"rendered":"<p> [ad_1]<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/10\/JustDial-796x418.jpg\" \/><\/p>\n<div>\n<p>A significant flaw in an Indian native search app, Justdial, allowed hackers to log in to any of its 156 million customers accounts.<\/p>\n<p>Aside from accessing consumer data resembling names, telephone numbers, and e mail addresses, the vulnerability allowed them to peek into monetary particulars together with stability and transactions of an account via JustDial Pay, the corporate\u2019s fee service.<\/p>\n<p>First reported by MoneyControl, the bug was found by safety researcher <a href=\"https:\/\/twitter.com\/ehrazofficial\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Ehraz Ahmed<\/a>\u00a0final month. It exploited the positioning\u2019s Register API used for sign-ups.<\/p>\n<p>A video posted by Ahmed reveals a hacker can use an individual\u2019s telephone quantity as consumer title and achieve entry to the account via the flaw. The bug allowed hackers to even change account particulars for JD Pay so all the cash despatched to that account will get redirected. Nonetheless, it didn\u2019t permit them to ship cash because it requires a further PIN.<\/p>\n<p><iframe loading=\"lazy\" width=\"500\" height=\"375\" src=\"https:\/\/www.youtube.com\/embed\/2KUoT5xpOn0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen=\"\"><\/iframe><\/p>\n<p>JustDial stated in an announcement the flaw was mounted yesterday:<\/p>\n<blockquote>\n<p><span>We at Justdial take safety significantly. There was a bug in one among our APIs which may doubtlessly be accessed by an knowledgeable hacker. This bug has been mounted. We work with varied safety researchers to strengthen our platform and want to thank Ehraz Ahmed for bringing this out to us.<\/span><\/p>\n<\/blockquote>\n<p>The corporate stated there was no lack of information.<\/p>\n<\/p><\/div>\n<p><script async src=\"http:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thenextweb.com\/security\/2019\/10\/10\/a-bug-in-indian-local-search-app-exposed-over-156-million-accounts\/\">Supply hyperlink <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] A significant flaw in an Indian native search app, Justdial, allowed hackers to log in to any of its 156 million customers accounts. Aside from accessing consumer data resembling names, telephone numbers, and e mail addresses, the vulnerability allowed them to peek into monetary particulars together with stability and transactions of an account via &hellip;<\/p>\n","protected":false},"author":1,"featured_media":183159,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-183157","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tie-world"],"_links":{"self":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/183157","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/comments?post=183157"}],"version-history":[{"count":0,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/posts\/183157\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media\/183159"}],"wp:attachment":[{"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/media?parent=183157"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/categories?post=183157"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hameed.nwar.uk\/sa\/wp-json\/wp\/v2\/tags?post=183157"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}