Moneycontrol
HomeNewsTrendsExclusive: Justdial security flaw may allow hackers to breach pay accounts of 156 million users
Trending Topics

Exclusive: Justdial security flaw may allow hackers to breach pay accounts of 156 million users

The flaw allows a hacker to log in to any Justdial account by placing the phone number in the username parameter.

October 10, 2019 / 09:49 IST
Story continues below Advertisement

A major security flaw has been detected on Justdial wherein a user's account can be hacked to use different services offered by the local search company. The flaw gives access to nearly 156 million unique users across Justdial's web, mobile website, app and voice platforms.

The flaw has been detected in Justdial’s Register API by security researcher Ehraz Ahmed, who shared the details exclusively with Moneycontrol. The flaw allows a hacker to log in to any Justdial account by placing the phone number in the username parameter. This would then give the hacker access to any person’s Justdial account.

Story continues below Advertisement

Access to  Justdial user accounts can potentially make data of its 156.1 million users available online.

How does it work?