Justdial patches security flaw that exposed sensitive data of over 156 million accounts

By Digit NewsDesk | Published on Oct 10 2019
Justdial patches security flaw that exposed sensitive data of over 156 million accounts

Apple iPhone XR 64GB at Lowest Price Ever

6.1" display | 50% Faster Graphics performance | TrueDepth camera

Click here to know more

HIGHLIGHTS

A flaw in Justdial could enable hackers to access any account with a phone number.

The vulnerability has been patched.

The company has said none of its accounts were breached and no data was leaked

In the world of constant data leaks and breaches, you can now add one more company to the list. A critical security flaw was found on Justdial, which could enable attackers to access sensitive account information of 156.1 million users on the platform. Justdial has now patched the flaw but we suggest you change your account password right away, in case you use the platform. The issue reportedly stemmed from Justdial’s Register API that would enable an attacker to get access into any Justdial account by using a phone number in the username parameter. The flaw was reported by the security researcher Ehraz Ahmed, via MoneyControl.

As per the report, the Register API vulnerability could enable hackers to access anyone’s Justdial account. This would be done by replacing the phone number under the username parameter so that the system returns an access token, system ID (SID) and user ID (UID). The SID would then be used to access the account and another accounts linked to it while the UID enabled posting on the user’s Justdial Social Profile. The worrying bit is that accessing a Justdial account also gives access to the Justdial Pay account and its settings can be changed to redirect funds to another bank account. However, transferring existing funds to another account is not possible since an account or UPI pin is required to confirm the transaction. 

The security researcher also mentions that hackers and telemarketers can mine Justdial data by using a script and phone number dumps found online. You can see how Ahmed exploited the flaw to gain access to a Justdial account from the video above. As mentioned above, Justdial patched the flaw and sent out a statement to the media that reads, “We at Justdial take security seriously. There was a bug in one of our API which could potentially be accessed by an expert hacker. This bug has been fixed. We work with various security researchers to strengthen our platform and would like to thank Ehraz Ahmed for bringing this out to us.”

logo
Digit NewsDesk

The guy who answered the question 'What are you doing?' with 'Nothing'.

Digit caters to the largest community of tech buyers, users and enthusiasts in India. The all new Digit in continues the legacy of Thinkdigit.com as one of the largest portals in India committed to technology users and buyers. Digit is also one of the most trusted names when it comes to technology reviews and buying advice and is home to the Digit Test Lab, India's most proficient center for testing and reviewing technology products.

We are about leadership-the 9.9 kind! Building a leading media company out of India.And,grooming new leaders for this promising industry.