What is a InstaBrute?
Instagram contained two distinct vulnerabilities that allowed an attacker to brute-force
passwords of user accounts. Combined with user enumeration, a weak password policy,
no 2FA nor other mitigating security controls. This could have allowed an attacker to compromise
many accounts without any user interaction, including high-profile ones.
Facebook fixed both issues and awarded a combined bounty of $5.000.
For more details on Instabrute
Go to your terminal and type in;
git clone https://github.com/Ha3MrX/InstaBrute.git
After download, locate you file directory with your terminal;
If you have issues with the password list,
Download the list from here