Can you ever imagine that a single text message is enough to hack Facebook accounts without any user interaction or do not use any other malicious tools like Trojans , phishing , keyloggers etc?
Today we are going to explain to you how a UK -based security researcher , " fin1te " is able to hack any Facebook account within a minute by implementing an SMS .Because 90 % of us are using Facebook too , so we know that there are a number of options that link your mobile phone to your account , allowing you to receive updates through your Facebook account via SMS directly to your mobile phone and you can also log into your account using the number of links rather than the email address or username .According to the hacker , vulnerability is the phone number in the link , or in technical terms , in file / ajax / settings / mobile / web confirm_phone.phpTrang work in the background when the user sends some your phone and verification code , sent by Facebook to mobile phones . It is a form of the two main parameters , a verification code , and the second is profile_id , which account to link them .
As an attacker, follow these steps to implement the hack:
. Change the value of profile_id profile_id value of a victim by masquerading parameters
Send letter F to 32 665, which is the number of Facebook SMS in the UK. You will receive a verification code 8 characters back. Enter the code in the box or as CONFIRMATION_CODE parameter values and submit the form.
Facebook will accept that confirmation code and telephone number of the attackers will be linked to the victim's Facebook account nhan.Trong next step of just going for a hacker Forgot password option and implement requirements set the password for the account of the victim.
An attacker can get the password reset code to the mobile phone number associated with your account of the victim using the steps above.
Enter the code and Reset password! Facebook no longer accept the profile_id parameter from the end user after receiving a report from the hacker error.
Facebook paid $ 20,000 in exchange for the fin1te
[Thehackernews]
0 comments:
Post a Comment