How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number
Hojt Communication is a consulting company focused on our clients need to rapidly bring the right product to the right market. We stand out due to our ability to combine skills in strategy, implementation, operations and technology with deep understanding about the connected world and the new levels of security and privacy protection that world brings.
vision,strategy,product,market,business development,marketing,mobility,Internet of Things,IoT,Security
23012
wp-singular,post-template-default,single,single-post,postid-23012,single-format-standard,wp-theme-stockholm,wp-child-theme-hojtcom,stockholm-core-2.4.6,select-child-theme-ver-1.0.0,select-theme-ver-9.13,ajax_fade,page_not_loaded,,qode_menu_,wpb-js-composer js-comp-ver-8.2,vc_responsive

How you could steal money from Instagram, Microsoft and Google with help from a premium rate phone number

See on Scoop.itApps and Internet of Things
77BynsMb2zoGxpMliZa-tzl72eJkfbmt4t8yenImKBXEejxNn4ZJNZ2ss5Ku7Cxt

Researcher Arne Swinnen found an ingenious way to make money from the likes of Google, Microsoft and Instagram – getting their two-factor authentication registration schemes to call a premium rate phone number:
"They all offer services to supply users with a token via a computer-voiced phone call, but neglected to properly verify whether supplied phone numbers were legitimate, non-premium numbers. This allowed a dedicated attacker to steal thousands of EUR/USD/GBP/… Microsoft was exceptionally vulnerable to mass exploitation by supporting virtually unlimited concurrent calls to one premium number"
Clever!
Swinnen told the tech companies concerned about the issue. Despite the fact that it was clear that no customer data was being put at risk through the technique (the actual potential damage was for the tech companies to lose some cash), the researcher was awarded $2000 and $500 by Instagram’s and Microsoft’s respective bug bounties.
You can learn more in Arne Swinnen’s blog post.

A warning. If you use a call based multi-factor authentication you check that you users doesn’t use a premium number. If not, it might cost you a lot of money.

See on grahamcluley.com

Hojt Digital
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.