4 ms·
> The attacker used social engineering to gain access to a mobile phone number that allowed them to gain access to other accounts, one of which had access to an
by qz_ 10y ago
> The attacker used social engineering to gain access to a mobile phone number that allowed them to gain access to other accounts, one of which had access to an old database backup from the forum.
Forgive me if I'm missing something blatantly obvious, but how was a hacker able to gain backup access with just a phone number? What kind of auth is that?
- chmars 10y ago2FA with SMS?
- Something1234 10y agoIt's a thing. Google uses it, Paychex and Adp too. Just about every really big one uses it for two factor.
- mastre_ 10y agoAre you asking what it means or disagree with it? If a: 2-Factor Authentication with Short Message Service (called "text" in the US). If b: It's how Google's 2FA works by default, falls back to SMS. Basically, getting control of (i.e. stealing) the 2nd factor in the 2FA scheme, and bypassing the 1st factor, the password (by resetting it). Plausible.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- azdle 10y agoIt looks like Google uses SMS for account recovery, could have been something like that. https://support.google.com/accounts/answer/183723?hl=en https://support.google.com/accounts/answer/183723?hl=en
- to3m 10y agoPresumably something along these lines: 1. attempt to log in to target's email system 2. "I forgot my password" 3. get 2FA key via SMS 4. enter 2FA key and new password, gain access to email <rummage through email looking for anything interesting> 5. attempt to log in to target's backup system 6. "I forgot my password" 7. get password reset key via email...