Friday, Jun 19, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | India | Indian Techies Bug Alert Wins Rs 36 Lakh From Microsoft

Indian techie’s bug alert wins Rs 36 lakh from Microsoft

After assessing his report, the Microsoft security team patched the issue and rewarded him $50,000 as a part of their Identity Bounty Program, security researcher Laxman Muthiyah wrote in a blog post

By IANS
Published Date - 3 March 2021, 07:23 PM
Indian techie’s bug alert wins Rs 36 lakh from Microsoft
whatsapp facebook twitter telegram

Chennai: Microsoft has awarded a Chennai-based security researcher $50,000 (approximately Rs 36 lakh) for spotting vulnerability on the company’s online services that “might have allowed anyone to takeover any Microsoft account without consent”.

After assessing his report, the Microsoft security team patched the issue and rewarded him $50,000 as a part of their Identity Bounty Program, security researcher Laxman Muthiyah wrote in a blog post on Tuesday. Muthiyah earlier won bug bounty from Facebook for finding a similar account takeover vulnerability in Instagram.


“I found Microsoft is also using the similar technique to reset user’s password so I decided to test them for any rate limiting vulnerability,” he said.

Muthiyah explained that to reset a Microsoft account’s password, users need to enter email address or phone number in their forgot password page. After that they will be asked to select the email or mobile number that can be used to receive the security code.

Once they receive the 7-digit security code, they will have to enter it to reset the password.
“Here, if we can bruteforce all the combination of 7 digit code, we will be able to reset any user’s password without permission. But, obviously, there will be some rate limits that will prevent us from making a large number of attempts,” he said.

After several days of efforts, he was able to spot the account takeover flaw.

“Immediately, I recorded a video of all the bypasses and submitted it to Microsoft along with detailed steps to reproduce the vulnerability. They were quick in acknowledging the issue,” Muthiyah said.

  • Follow Us :
  • Tags
  • 7 digit code
  • bruteforce
  • Microsoft
  • Microsoft account

Related News

  • Microsoft cuts Claude Code access as AI coding costs surge

    Microsoft cuts Claude Code access as AI coding costs surge

  • Microsoft veteran and VC leader Soma Somasegar dies, tributes pour in

    Microsoft veteran and VC leader Soma Somasegar dies, tributes pour in

  • Thousands of IT jobs set to disappear as Meta, Microsoft restructure workforce in AI era

    Thousands of IT jobs set to disappear as Meta, Microsoft restructure workforce in AI era

  • Musk seeks up to $134 billion in damages from OpenAI, Microsoft

    Musk seeks up to $134 billion in damages from OpenAI, Microsoft

Latest News

  • RBI compounds FEMA violations of Sai Rayalaseema Paper Mills

    9 hours ago
  • YSRCP chief Jagan seeks CBI inquiry into Vijayawada custodial death

    9 hours ago
  • Verdict on Telegram app suspension plea set for June 19

    9 hours ago
  • India, France to launch TRISHNA satellite for global food security

    9 hours ago
  • Bank of Baroda offers up to 6.25% interest to NRIs under new FCNR(B) scheme

    9 hours ago
  • Daily wager found dead in Siddipet lake after fishing trip

    9 hours ago
  • BSH unveils premium four-door side-by-side refrigerators in Hyderabad

    9 hours ago
  • Bisleri workers seek Labour Minister Vivek’s intervention over job dismissals in Sangareddy

    10 hours ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam