How Vine's Entire Source Code Was Online for Anyone to See

Advertisement
By Shekhar Thakran | Updated: 25 July 2016 18:52 IST
Highlights
  • The ethical hacker was taking part in Twitter's HackerOne programme
  • The hacker gained access to source code through a Docker image
  • The bug was fixed by website within 5 minutes of flaw's demonstration
Hackers are known to be notorious. They like to find out all the vulnerabilities that various sites possess and depending on their intention, they use this knowledge to either create nuisance for the website owners or inform them about the loopholes to help make the site safer.

The makers of video-clip sharing site Vine, currently owned by Twitter, should be grateful that ethical hacker known by the name 'avicoder' chose to be the latter sort when he found a way to download Vine's entire source code.

For those who are unaware about the subject, a source code for website usually contains confidential information and access to it can leave the site extremely vulnerable to attacks that can potentially even destroy it.

In this case, 'avicoder' was just looking at the potential security flaws without any ill intentions and in his blog post, he explained the entire flaw and how he gained the access to the site's source code through its Docker image, which should ideally have been private but was publicly available. With the image, he was able to run the service locally on his machine.

Advertisement

"I was able to see the entire source code of vine, its API keys and third party keys and secrets. Even running the image without any parameter, was letting me host a replica of VINE locally," the hacker said in his blog post.

On March 31, avicoder demonstrated a full exploitation of the security flaw to Twitter as part of its HackerOne bounty programme and the site then fixed the bug in around 5 minutes. The hacker was rewarded a bounty of $10,080(roughly Rs. 6,73,000) for informing the site about this flaw.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along
  2. Redmi Note 15 Pro+, Redmi Note 15 Pro First Impressions
  3. Redmi Note 15 Pro Series 5G Launched in India With These Features
  4. iQOO 15R Dark Knight Colourway Teased Weeks Ahead of Launch in India
  5. Realme P4 Power 5G With 10,001mAh Battery Arrives in India: See Price
  6. Adobe Express Premium Is Now Free for One Year for All Airtel Users
  7. Clawdbot (Now Moltbot) Explained: What is It and Why is It Going Viral?
  8. Vivo X200T Review
  9. WhatsApp Could Soon Add a Subscription Plan With These Exclusive Features
  1. Nothing Won't Launch a Flagship Model in 2026; Company to Focus on Nothing Phone 4a and Audio Products, Carl Pei Says
  2. Redmi Turbo 5 Max Launched With 9,000mAh Battery, Redmi Turbo 5 Tags Along: Price, Specifications
  3. Ponies Starring Emilia Clarke and Haley Lu Richardson Now Available for Streaming
  4. Kingdom Come: Deliverance Could Get Current-Gen Update, PlayStation Store Leak Suggests
  5. Tecno Camon 50 Pro, Tecno Camon 50 Listed on Google Play Console, Google Play Supported Devices List
  6. Red Magic 11 Air Launched Globally With Snapdragon 8 Elite SoC, ICE Cooling System: Price, Specifications
  7. Moto G67, Moto G77 Launched With 5,200mAh Battery, 6.78-Inch AMOLED Display: Price, Features
  8. Vaa Vaathiyaar Now Streaming Online: Know Everything About This Tamil Action Comedy Film
  9. Global Smartphone SoC Shipments to Decline by 7 Percent in 2026 Amid Rising Memory Costs: Counterpoint
  10. Poco X8 Pro Max Launch Seems Imminent as Phone Bags IMDA Certification
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.