paint-brush
I Could Crash Your Instagram Remotely. But I Chose to Report It.by@valbrux
1,479 reads
1,479 reads

I Could Crash Your Instagram Remotely. But I Chose to Report It.

by Valerio Brussani3mOctober 8th, 2019
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

Instagram uses a simple incremental PKID in its database to define user accounts on the platform. The first and second Instagram accounts (PKID = 1 & PKID=2) were associated to an ID, but their username was not populated. The username field contained an empty string (“”), and I was almost certain this behavior could have created some issues. My idea is that those accounts were created during the initial testing phases of Instagram, when it was nothing more than an alpha release. From here on in, let’s call them ghost users.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - I Could Crash Your Instagram Remotely. But I Chose to Report It.
Valerio Brussani HackerNoon profile picture
Valerio Brussani

Valerio Brussani

@valbrux

Penetration Tester & Security Researcher

About @valbrux
LEARN MORE ABOUT @VALBRUX'S
EXPERTISE AND PLACE ON THE INTERNET.
L O A D I N G
. . . comments & more!

About Author

Valerio Brussani HackerNoon profile picture
Valerio Brussani@valbrux
Penetration Tester & Security Researcher

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Also published here