10 ms·
PayPal 2FA Bypass
- greyskull 10y agoWhat could the backend logic possibly be this worked?
- Dinius 10y agoSomething like this: (PHP felt like the right approach here :p) if ($selectedOption == SECURITY_QUESTION) { if (isset($_POST["SecurityQuestion0"]) && isset(["SecurityQuestion1"])) { if ($_POST["SecurityQuestion0"] != $answer0 || $_POST["SecurityQuestion1"] != $answer1) { // invalid answers return; } } authenticateUser(); }
- dkopi 10y agoMore likely along the lines of if ((isset($_POST["SecurityQuestion0"]) && $_POST["SecurityQuestion0"] != $answer0) || (isset($_POST["SecurityQuestion1"]) && $_POST["SecurityQuestion1"] != $answer1)
- Chyzwar 10y agoYou should use !==. isset is do not handle all corner cases, it would return true for empty strings or false for NULL. You should use framework like Laravel: Input::has('key') By design type of security challenge should not be an option. API endpoint should not check for $selectedOption == SECURITY_QUESTION. In this case you still vulnerable for the same attack. You always should return something. having just return; is bad. Finally you should use something safer than PHP since mistake can cost you money.
- psybin 10y agoIf there's a SMS challenge, process. If there's a question challenge, process. If no exceptions were thrown, you're authenticated.
- deleted 10y ago[deleted]
- djf1 10y agoreturn all([is_valid_answer(q, a) for q, a in params])
- citruspi 10y agoHopefully not, but I've seen worse. def validate_security_questions(): if not question_0 or not question_1: raise AuthException('Invalid security questions') try: validate_security_questions(question_0, question_1) except AuthException as ex: # Todo: Present error to user pass
- sinaa 10y agolikely using the following pseudo-ish code: # possibly done using a session variable security_questions = [] # first question security_questions.push({question: answer}) # second question security_questions.push({question: answer}) forEach(security_questions as x) if(!validate_answer(x)) return false; return true;
- xorgar831 10y agoI've seen equally as ridiculous web bugs, computing prices browser side in javascript, credit card numbers encoded in REST API endpoints, financial websites not supporting 2FA at all or mixing http requests into the sites. We're solidly in the dark ages of web security still.
- Itsdijital 10y agoWhen I went to setup my online account for my old bank, I entered a randomly generated 16 digit key and got an error; "Maximum password length limited to 6 characters...only alpha-numeric" I called to inform them that their account creation was broken, because obviously that was a bug. They told me that sometimes people have a hard time remembering their password, so they "need to balance between ease of use and security". My jaw dropped and my head rolled off my shoulders. I didn't setup an online account.
- xioxox 10y agoIt seems standard practice for German banks to limit online passwords to five alpha-numeric characters. Fortunately, you need a TAN number (generated by a device or from an SMS message) to actually make a transaction. I have no idea why they limit the password length like this.
- kuschku 10y agoCommerzbank actually uses 8 characters, but that’s still horrible. Luckily, you can also require all transactions to be done via HBCI with proper security and a smart card for auth.
- pluma 10y agoI'm guessing it's five characters so people don't just use their four digit PIN. I don't have any explanation for why they would limit it to five characters though, or why it has to be alphanumeric. That said, Comdirect seems to offer regular passwords or six digit PINs and Bank of Scotland (in Germany) seems to also offer regular passwords. But there are plenty of other offenders. For example my energy provider E-wie-einfach requires a mix of alphanumeric characters but forbids pasting and autofill (the latter of which luckily Chrome simply ignores). I don't know what idiot ever came up with the idea that disabling paste makes logins more secure (only justification I've ever heard was about preventing brute force attacks, proving an utter lack of understanding of the technology involved) but sadly it's still a thing and it still leads to people using trivial and easy to type passwords.
- the7nd 10y agoThe simplicity of this exploit demonstrates something profound. The most dangerous things in life are not hidden deep in the weeds. Rather, they stare us in the face in the most obvious spots. It isn't the unknown that presents the biggest threat. It is the known that we never gave a second look.
- 1812calif 10y agoheart disease vs. terrorism. it seems to be an unfortunate emergent behavior of groups of humans.
- witty_username 10y agoI noticed that if it's a fire that kills many people it's only a one day news; while if it's a bomb that kills one everybody's afraid.
- enraged_camel 10y agoIt's not the number of casualties that scares people, but rather the nature of the threat. Fires have existed for several millennia. Our ancestors who built and lived in the very first settlements suffered from their homes/stores occasionally burning down. We know what types of conditions increase risk of fires and we know how to minimize those risks and put the fires out when they occur. Bombs on the other hand are unpredictable. They also cause their damage instantly and there is no way to minimize or prevent it. You can escape from a burning building, or if stuck, wrap a piece of wet cloth around your mouth to minimize the amount of smoke you breathe while you wait for rescue. You can't outrun an explosion. That's why people are a lot more scared of bombs than they are of fires (or car accidents, for that matter, which kill many more people than both fires and bombs combined).
- tttttttttttt 10y agoI think perception of danger = amount of times hearing people die from doing act / amount of times doing act. So flying is much higher than diving: People drive much more than they fly (a few times a year vs twice a day) and hear about air-crashes (9/11, Malaysia Airlines) more than car crashes. It's the brain playing games with us
- algesten 10y agoI'm using Verisign's VIP Access app (silly name) to generate PayPal's 2FA tokens. Good thing is it works without access to my phone. Bad thing, the app has a unique ID that PayPal only allows me to use for one of my three accounts. Wish they implement TOTP.
- agildehaus 10y agoOne of my PayPal 2FA phone numbers is listed twice and both cannot be removed (errors when I try). Their support can't help with the situation because their side wasn't able to see the duplicate. This is not surprising to me.
- zifnab06 10y agoI've been unable to remove a credit card from my account for almost 5 years. It's since expired, and is somehow stuck as the default payment method.
- discordance 10y agoOuch! Also, PayPal really needs to stop using SMS for 2fa. I expect more from a payment processor that is linked to my bank account.
- vinay427 10y agoAs I just mentioned elsewhere on this thread, SMS isn't the problem here. I use a VeriSign dongle for PayPal 2FA but PayPal still offers the same option of using security questions instead. I was previously under the reasonable assumption that the security questions form was ar least handled correctly, but apparently not.
- necessity 10y agoEveryone except maybe phone apps should stop using SMS for 2FA.
- aguo 10y agoAgreed, NIST stopped recommending SMS 2FA a few months back (https://www.schneier.com/blog/archives/2016/08/nist_is_no_long.html https://www.schneier.com/blog/archives/2016/08/nist_is_no_lo...) I really wish they had Google authenticator or Yubikey support.
- jlgaddis 10y agoThey have both. I have a "Symantec VIP" co-branded Yubikey that I've used with PayPal for years along with an authenticator app on my phone as a fallback.
- tP5n 10y agoI have both a yubikey and an auth app but can't seem to find a way to use them with paypal. Do you have some kind of special account or is that a feature bound to a certain market?
- jlgaddis 10y agoI don't think there's anything special about my account. It was a "personal" account when I created it, probably almost 15 years or so ago, then upgraded to a business account maybe 8-10 years ago. I don't have my password handy right now so I can't login to check, but look for settings related to their "security key". I don't know if they still do or not but at one point they offered a hardware OTP generator (similar to the old RSA SecurID key fob) for a one-time $5 fee. Alternatively, you could use an existing one you already had just by entering its "ID number"; I used the IDs of my Symantec VIP Yubikey and also the app. Sorry I can't be more specific or give you better guidance. I know that the option does exist, though; perhaps just explore the available options and maybe you'll stumble across it. Good luck!
- deleted 10y ago[deleted]
- ryanfreeborn 10y agoIs 17 days an acceptable TAT here? I know investigation and fixes can be a challenge, but with the severity of this exploit+PayPal being a serious financial service, I kind of would hope for a faster fix. Maybe I'm off base...I really don't know; curious what others think. How much time would've had to pass (without PayPal doing anything) before the author is ethically obligated to post to HN/media/etc about the hack? I believe publicizing an (unpatched) exploit like this crosses into criminality, but it would be essential to demonstrate some kind of proof, for credence and gravity. I'm guessing the community has some standardized guidelines for this sort of thing, but I'm not aware of them.
- blazespin 10y ago17 days is fast, relatively speaking. Security questions are hardly really that great of 2FA protection anyways.
- ryanfreeborn 10y agoGood to know. And ya, a security question to bypass a phone 2SV is a joke. Almost entirely defeats the purpose.
- vinay427 10y agoJust to be clear, it bypasses any of their 2FA codes, not just SMS-based codes. The security questions bypass "feature" also appears on my account for which I use a VeriSign 2FA dongle.
- jlgaddis 10y agoThe "standardized guidelines" sometimes vary -- mostly dependent on the nature of the vulnerability -- but 90 days seems to be a pretty common timeframe. That's what Google gives others before they publicize the details, for example.
- noamyoungerm 10y agoNotice that 17 days is basically what is needed to add the issue to the next sprint, complete its development along with everything else for that sprint, and deploy to a live site. To me that sounds fair.
- jknoepfler 10y agoThank you to the author for reporting this big in a responsible way. They are a credit to our profession.
- foota 10y agoOh my god.
- rvolkan 10y agoI'm happy to see that the article doesn't have any BS that I have to ignore. It's a simple page that only tells the 'required' story. As a reader, I want more people to cut the crap about 'blah blah blah' and get to the subject.
- blazespin 10y agoThat only works if you can assume your audience has the necessary context. That being said, I've often thought Hacker News should have a nice crowd sourced tldr summary at the top of all the comments.
- madeofpalk 10y agoWell, here the succinctness is a part of the story. It emphasises just how basic this bypass is. For what it's worth, I thought the "I was in a hotel..." story was superfluous and probably not true.
- phreack 10y agoThis is scarily simple. Profit indeed for a black hat. Coupled with a recent post about Gmail on how phone carriers are the weakest link, I just don't feel safe with anything but a dongle based 2fa these days.
- tmzt 10y agoUnless the master key is compromised allowing anyone to generate authenticator codes, as I seem to recall happened a few years ago with a major provider.
- jlgaddis 10y agoI think you're referring to RSA's SecurID? That was roughly five years or so ago.
- vinay427 10y agoThat doesn't help in this case. I have a VeriSign 2FA dongle for PayPal and it still offers the same option of logging in with security questions.
- bad_user 10y agoDoes anybody know how to activate 2FA for PayPal? In the security section I don't even have that option.
- thisone 10y agoI don't remember exactly where it is in settings, but it's not called 2fa or something obvious it's called something like PayPal Security Key
- nobodyshere 10y agoMight be unavailable for your country.
- gaza3g 10y agoYup, I'm in Singapore and they told me that they don't have that feature yet. I find that really ridiculous.
- deleted 10y ago[deleted]
- TorKlingberg 10y agoThis seems like a good time to rant about PayPal 2FA and its poor usability. Every time I open the PayPal app I have to wait for a text message and type a code across. That should not be necessary! PayPal should count the app as the second factor and only ask for the password. I am happy to us 2FA with Google because I only have to use it when on a new device, or once a month or so in the browser. Second, support 2FA apps like Authy already. SMS based 2FA is both insecure and unreliable.
- TekMol 10y agoWhat is the additional phone verification good for if you can bypass it anyhow? I mean - if you can chose between pw+phone and pw+pw2 ... why bring the phone into play at all?
- 0xmohit 10y agoIf I were to guess this flaw was a result of monkey-patching to support 2FA that didn't quite consider different scenarios. I've come across a few authentication bypass vulns that seem similar.
- chirau 10y agoOut of curiosity, how much was the bounty? 3, 4 or 5 digits?
- benevol 10y agoThis is surreal. Does PayPal outsource their web development to an anonymous script kiddie on 4chan?
- kimshibal 10y agono, they outsource to cheap dev in india
- hogrammer 10y agoI can tell you first hand what they do! They call a company like "Accenture" (which we call "Accidenture" or "HP Consulting" and a GE Capital Porta-building appears with H1-B programmers. They're there for a few months, and then they go away.
- yashafromrussia 10y agoWhat kind of API design is this? Post data should be sent within the request's body over HTTPS. Not as a url query.
- continuational 10y agoThe URL is encrypted too, so what's the difference in terms of security?
- mrcarrot 10y agoNowhere in the article does it say that the POST data was in the URL. As I understood it, he was editing the request body before the request was sent to PayPal's server.
- ComodoHacker 10y agoDoes it matter in this case?
- dkopi 10y agoMistakes were made, and there are definitely lessons to be learned, but if we want to improve the state of security, we really need to change the way we react to these types of bugs. If a service has an outage and a company posts a postmortem, we all think: "wow! that was an interesting bug, lets learn from this". We shouldn't be treating security issues differently. People who make security mistakes aren't idiots. They aren't negligent. They're engineers just like us, who have tight deadlines, blindspots and mistakes. Shaming people and companies for security bugs will only cause less transparency and less sharing of information - making us all less secure. This is a really cool bug. Kudos to the researcher for finding it, responsibly reporting it, and to paypal for fixing it in a timely fashion. Hopefully - this type of bug changes some internal processes and the way the company thinks about 2FA. As for security questions - these are obviously insecure, and should really never be relied on. If you can opt out of security questions - do so. If you can't - just generate a random password as the answer. "I_ty/:QWuCllV?'6ILs`O12kl;d0-`1" is an excellent name for your first dog / high school. Just don't forget to use a password manager to store these.
- TeMPOraL 10y ago> If you can't - just generate a random password as the answer. "I_ty/:QWuCllV?'6ILs`O12kl;d0-`1" is an excellent name for your first dog / high school. Just don't forget to use a password manager to store these. Be wary of social engineering attacks though. - <support on the phone> I'd also need you to provide me an answer to your security question. What was your first dog's name? - <me> Oh, you know, it's a long string of random characters I generated, I'd have to give them to you one by one... - <support> (looks at the answer) uh, right. I see. Let's continue then.
- raverbashing 10y agoYes, having something readable (and "believable") is more useful and secure than having to rely on saying a random string Just put "Plymouth Creek High" (Not to mention the possibility that some "security genius" will ban special characters on those answers)
- 10y ago
- nobodyshere 10y agoBypass? Haha, it has been quite a while and they still haven't even enabled it for my country. Same goes for Apple.
- nobodyshere 10y agoBypass? Haha, it has been quite a while and they still haven't even enabled it for my country. Same goes for Apple.
- DavidWanjiru 10y agoAm I the only one who found it odd that the author had internet access, but there was no phone signal? Maybe it's because I'm Kenyan, where phone penetration is much higher than internet penetration, and where internet access over GSM has the biggest share of the internet access pie chart.
- dkopi 10y agoThis often happens when I'm travelling internationally. If I plan on buying a local sim card instead of purchasing a roaming plan - I might not have access to my SMS until I get back home.
- 45h34jh53k4j 10y agoGet a next gen phone; They should all do Wifi Calling now. This causes your phone to tunnel the cellular via internet link, and you get full call and sms coverage. Of course, 2FA via SMS is a bad and deprecated pattern and needs to die! But! you can get your phone overseas without roaming which is pretty neat.
- nommm-nommm 10y agoNot really. If you're American international roaming fees are usually pretty steep so many times if you want phone service you get a local number. WiFi is ubiquitous, especially hotel wifi.
- TazeTSchnitzel 10y ago> Am I the only one who found it odd that the author had internet access, but there was no phone signal? This happens to me at home. Poor cell reception, but WiFi.
- gargravarr 10y agoThe author mentioned being in a hotel, so I assume he was using their wifi.
- andrewvijay 10y agoShort and sweet. Never seen a bug explained so succinctly.
- danielsamuels 10y agoI imagine you could have got the same results with inspect element and deleting the form fields, rather than using a proxy.
- nabla9 10y agoThe lesson from this: Just looping trough input arguments from the client, validating them and then acting on them gives the client control of the code execution. It's not enough to validate each input argument. You musth also verify that all parameters are really there and no extra parameters can slip into the system. The whole combination must make sense. Enumerating all used parameter combinations in a record that can be changed easily is one way to solve this.
- pkamb 10y agoSounds like a lot of work! Paypal will just turn off two-factor themselves if you ask nicely via an unverified twitter DM. http://imgur.com/a/Tu1AN http://imgur.com/a/Tu1AN https://www.reddit.com/r/SocialEngineering/comments/3kgw3s/paypal_will_disable_an_accounts_2factor_auth_if/ https://www.reddit.com/r/SocialEngineering/comments/3kgw3s/p...
- TazeTSchnitzel 10y agoPayPal's 2FA broke on me when it started locking my account every time I attempted to use it, because I'd previously made it send too many SMSes (poor signal). I was thankful that support let me disable it, but it was worrying they didn't try to verify that I actually controlled my device first.
- giancarlostoro 10y agoIt's weird, don't all services that enable 2FA give you reset codes? Shouldn't they ask you to use those, or at least give them one if anything so they can help you disable your account? Kind of odd.
- ryanlm 10y agoI'm assuming that the relevant code, is simply an if statement checking for the existence of the url parameters, not even checking if the security questions are correct. if(isset($_GET['securityQuesiton0')) { // success, } This is negligence on the developers part and I think they should be disciplined.
- kelnage 10y agoOr they designed it to show a variable number of security questions (so management could come along and say "we need 4 questions now" without causing havoc). Then they'd iterate through the responses, verifying them against the appropriate question. Simply forgetting to enforce that the number of questions asked has to equal the number of responses sent would cause the described vulnerability.
- gengkev 10y agoThat doesn't actually make sense, since the exploit is to leave securityQuestion0 unset...
- Propen 10y agoIt's 2016. They are a financial company. Why aren't they implementing TOTP codes? NIST officially deprecated SMS.
- dczmer 10y agoreminds me of this paypal 2fa exploit from a couple years ago: https://duo.com/blog/duo-security-researchers-uncover-bypass-of-paypal-s-two-factor-authentication https://duo.com/blog/duo-security-researchers-uncover-bypass... because it was the same simple exploit on a different field.
- Tammy5 10y agoI don't know about hacking but when my ex was cheating on me, a friend of mine referred me to Mr Robert I thought it wasn't real but he later proved me wrong by helping me to spy on my ex-husband and got me all the necessary evidence I needed. He helped me to hack and spy on his emails, mobile , all his social media and his bank accounts, Robert did all this remotely without touching his devices. You can contact him with mastershield55@gmail.com if you are in the same shoe as I was..