Researcher steals Instagram, Google and Microsoft via 2FA

Belgian security researcher Arne Swinnen has discovered a way to steal money from companies like Facebook (through Instagram), Google and Microsoft using 2FA token systems.
2fa pwned
Most companies use 2FA (Two-Factor ) to send SMS shortcodes to their users. Optionally, if the user chooses, he can receive a voice call from the company, during which a robot says the code.

These calls are usually made to the number που είναι συσδεδεμένος με τον λογαριασμό. Ο Swinnen ανακάλυψε στα πειράματά του ότι μπορούσε να δημιουργήσει λογαριασμούς του Instagram της Google και του Microsoft Office 365 στους οποίους αντί να βάλει τον αριθμό του κινητού του, χρησιμοποίησε έναν αριθμό .

So if one of these three accounts used 2FA instead of calling his number, he was sending premium SMS by charging businesses.

Swinnen argues that attackers could create premium services and Instagram, Google or Microsoft accounts.

Using automated scripts, Swinnen reports that an attacker could request 2FA tokens for all accounts, thereby making legitimate phone calls to the service, making a lot of money.

According to Swinnen's calculations, he could theoretically obtain EUR 2.066.000 annually from Instagram, 432.000 € per year from Google, and 669.000 € per premium number from Microsoft.

The technical and exploitation details are different for each service, and Swinnen explains it on his blog.

https://www.arneswinnen.net/2016/07/how-i-could-steal-money-from-instagram-google-and-microsoft/

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).