Epic Games, the Fortnite game maker, silently removed a vulnerability from its infrastructure, allowing hackers to access users' accounts with incredible ease.
The vulnerability was detected by researchers its security Israeli company Security Check Point, which cited the issue privately in Epic Games last year.
"We reported the vulnerability in early November, and by the end of November it had been fixed," said Oded Vanunu, a Check Point researcher at ZDNet.
Vulnerability was in fact a combination of many errors in different parts of the company's infrastructure and some were not related to Fortnite.
Watch the video:
To carry out a successful attack the users they would have to click on a malicious link connecting to Epic Games. Of course, the vulnerability shocked the children, who as users with less experience could not detect the dangerous parameters contained in the link.
“It wasn't an advanced attack at all, and it was very simple to execute on backgroundVanunu said. "Login Token theft is one of the most emerging attack methods."
Of course, Fortnite's accounts are all at risk. Since June of 2018, it has been reported that over nine million accounts of this game have been hacked by hackers.
Why this game? Originally because it's popular.
On the other hand, Fortnite's V-Bucks currency is known to be used to launder (real) money by cybercriminals. And it's not just cybercriminals who are after V-Bucks. Teenagers enter the procedure to hack accounts, stealing from each other.
In many cases, hackers do not mind Fortnite's accounts, as they only want players' money.
_______________________
- KeePass 2.41 New update
- NSA: free GHIDRA reverse engineering tool
- What is Software, Hardware and Motherboard RAID? Guide for Beginners