Showing posts with label Warning. Show all posts
Showing posts with label Warning. Show all posts

30 Oct 2013

Hacked Facebook Account with One SMS.

Hacked Facebook Account with One SMS by UK based Hacker, Facebook Security Team rewarded him reporting flaws in the System.

Guys Today's story is different from others. People usually use Malicious code, Social Engineering, Trojans, Phishing to Hack a Facebook Account, But this story is entirely change, here Hacker called "fin1te" which is from UK found a big flaws in Facebook messaging system, reported to Facebook and Facebook rewarded him By $20,000 US.



Today I am going to explain you that how a UK based Security Researcher, "fin1te" is able to hack any Facebook account within a minute by doing one SMS.

Because 90% of us are Facebook user too, so we know that there is an option of linking your mobile number with your account, which allows you to receive Facebook account updates via SMS directly to your mobile and also you can login into your account using that linked number rather than your email address or username.

According to hacker, the loophole was in phone number linking process, or in technical terms, at file /ajax/settings/mobile/confirm_phone.php

This particular webpage works in background when user submit his phone number and verification code, sent by Facebook to mobile. That submission form having two main parameters, one for verification code, and second is profile_id, which is the account to link the number to.




 
As attacker, follow these steps to execute hack: 
  1. Change value of profile_id to the Victim's profile_id value by tampering the parameters.
  2. Send the letter F to 32665, which is Facebook’s SMS shortcode in the UK. You will receive an 8 character verification code back. 
  3.  Enter that code in the box or as confirmation_code parameter value and Submit the form.

Facebook will accept that confirmation code and attacker's mobile number will be linked to victim's Facebook profile.

In next step hacker just need to go to Forgot password option and initiate the password reset request against of victim's account.

Attacker now can get password recovery code to his own mobile number which is linked to victim's account using above steps. Enter the code and Reset the password!

Facebook no longer accepting the profile_id parameter from the user end after receiving the bug report from the hacker.

In return, Facebook paying $20,000 to fin1te as Bug Bounty.

Found Really interesting?? 
Don't forget to Subscribe us..

22 Oct 2013

Mobile device could be dangerous for You

READ THIS!!!! 

IMPORTANT FROM THE UNIVERSITY OF MIAMI HOSPITAL

VERY SERIOUS WARNING...

I do this all the time! I guess I won't be doing it ANY more !
A few days ago, a person was recharging his mobile phone at home.
Just at that time a call came in and he answered it with the charging Instrument still connected to the outlet.
After a few seconds electricity flowed into the cell phone unrestrained and the young man was thrown to the floor with a heavy thud. As you can see, the phone actually exploded.
His parents rushed to the room only to find him unconscious, with a weak heartbeat and burnt fingers.
He was rushed to the nearby hospital, but was pronounced dead on arrival.
Cell phones are a very useful modern invention.
However, we must be aware that it can also be an instrument of death.
Never use the cell phone while it is hooked to the electrical outlet! If you are charging the cell phone and a call comes in, unplug it from the charger and outlet.
FORWARD THIS TO THE PEOPLE THAT MATTER IN YOUR LIFE!!!