How can they violate your Facebook account

Security researchers from Positive Technologies show us how a Facebook account can be violated. All you need to know is the user's phone number.

As demonstrated in the below , οι επιτιθέμενοι μπορούν να εκμεταλλευτούν τη λειτουργία ανάκτησης κωδικών πρόσβασης του κοινωνικού δικτύου για να την κάνουν να αποστείλει έναν κωδικό πρόσβασης (one-time password) μέσω SMS στο χρήστη.facebook pass

In previous publication we had reported that hackers managed to make an exploit in mobile using the SS7 global network.

Signaling System 7 (or Signaling System 7 - SS7) is a global network that connects all telephone operators around the world in a single node. Exploit exploits a known security flaw in SS7, which has proven to be relatively difficult to determine due to the way the Signaling System 7 works.

Currently, Signaling System 7 is used by all its cellular networks , so the vulnerability affects all devices from every provider around the world.

Οι ερευνητές λοιπόν κατάφεραν να εκμεταλλευτούν τρωτά σημεία του δικτύου SS7 και να αποκτήσουν λεπτομέρειες για την κινητή συσκευή του θύματος. Μετά “γράφουν” το θύμα σε ένα roaming network. This allows them to receive all calls and SMS meant for the victim, as well as the aforementioned SMS coming from Facebook.

With this code, attackers can easily access the victim's Facebook account and throw it out with a simple change of access.

Security investigator Karsten Nohl told Forbes that creating simple rules on the SS7 firewall would resolve the 90% of 7 Signal Security

Your Facebook account will not be at risk of this attack by using two-factor authentication provided by the company. Once you add the security feature, password retrieval stops sending SMS passwords.

Since this attack is possible due to the vulnerability of the SS7 system rather than through Facebook, it is very likely that it could also work for violations of other online services that use the same password recovery mechanism.

Watch the video

https://www.youtube.com/watch?v=wc72mmsR6bM

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).