Search

How Vine's Entire Source Code Was Online for Anyone to See

Advertisement
Highlights
  • The ethical hacker was taking part in Twitter's HackerOne programme
  • The hacker gained access to source code through a Docker image
  • The bug was fixed by website within 5 minutes of flaw's demonstration
How Vine's Entire Source Code Was Online for Anyone to See
Hackers are known to be notorious. They like to find out all the vulnerabilities that various sites possess and depending on their intention, they use this knowledge to either create nuisance for the website owners or inform them about the loopholes to help make the site safer.

The makers of video-clip sharing site Vine, currently owned by Twitter, should be grateful that ethical hacker known by the name 'avicoder' chose to be the latter sort when he found a way to download Vine's entire source code.

For those who are unaware about the subject, a source code for website usually contains confidential information and access to it can leave the site extremely vulnerable to attacks that can potentially even destroy it.

In this case, 'avicoder' was just looking at the potential security flaws without any ill intentions and in his blog post, he explained the entire flaw and how he gained the access to the site's source code through its Docker image, which should ideally have been private but was publicly available. With the image, he was able to run the service locally on his machine.

"I was able to see the entire source code of vine, its API keys and third party keys and secrets. Even running the image without any parameter, was letting me host a replica of VINE locally," the hacker said in his blog post.

On March 31, avicoder demonstrated a full exploitation of the security flaw to Twitter as part of its HackerOne bounty programme and the site then fixed the bug in around 5 minutes. The hacker was rewarded a bounty of $10,080(roughly Rs. 6,73,000) for informing the site about this flaw.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15 Pro 5G to Launch in India With Snapdragon 7 Gen 4 Chipset
  2. OnePlus Pad Lite With 11-Inch Display, 9,340mAh Battery Launched
  3. Samsung Galaxy Z Fold 7 With 8-Inch Inner Display Launched in India
  4. Moto G96 5G Launched in India With 50-Megapixel Sony Lytia 700C Camera
  5. Samsung Galaxy Watch 8, Watch 8 Classic With Exynos W1000 Chip Launched
  6. Samsung Galaxy Z Flip 7 Launched in India With 4.1-Inch Cover Screen
  7. Nothing Phone 3 Review: Enters the Big League With a Big Price
  8. Samsung Galaxy Watch Ultra Now Available in a New Colour Variant
  1. NASA Astronaut Captures Rare Red Sprite Over Storm from Space Station
  2. Progress 92 Spacecraft Docks at ISS with Vital Supplies for Expedition 73
  3. Scientists Trace Universe’s Missing Ordinary Matter Using FRBs and X-rays
  4. Samsung Galaxy Watch Ultra Now Available in a New Colour Variant in India
  5. Lava Blaze AMOLED 2, Blaze Dragon to Launch in India This Month
  6. Samsung Unpacked 2025: Galaxy Watch 8, Watch 8 Classic With One UI 8.0 Watch, Exynos W1000 Chip Launched
  7. Samsung Unpacked 2025: Galaxy Z Flip 7 FE With 3.4-inch Cover Display, Exynos 2400 SoC Launched
  8. Samsung Unpacked 2025: Galaxy Z Flip 7 Launched in India With 4.1-Inch Cover Screen, Exynos 2500 SoC
  9. Samsung Unpacked 2025: Galaxy Z Fold 7 With Snapdragon 8 Elite Chipset, 8-Inch Inner Display Launched in India
  10. Apple Pencil With 'Trackball' Tip, Ability to Draw on Any Surface Described in Patent Document
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »