3 ms·
Can someone shed light on how this sort of attack might have been carried out?
by jefferson123 9y ago
Can someone shed light on how this sort of attack might have been carried out?
- mkolodny 9y agoThe title of this article isn't accurate. Personally I think it's just meant to scare people. Money can't be "stolen" from your Uber account. Someone can find out your password to your Uber account the same way they could get your password for any website. Then they log in as you, and take trips using your account. Your card would then be charged for the trips. It's OP's fault that someone found out their password. Uber was nice and refunded them for the trips.
- Bartweiss 9y ago> Then they log in as you Except the account in the article had two factor auth enabled. Someone triggered the second factor (a text message) then logged in without access to it. That's the question at the heart of "how did this attack happen?"
- URSpider94 9y agoWe do not know that the attacker did not have access to the TFA code. That's an assumption. For all we know, it was the customer's roommate reading the SMS off his phone and sharing it to the pirates. It is certainly possible that Uber's TFA system is compromised, but that's not the only explanation.
- deleted 9y ago[deleted]
- Procrastes 9y agoTo offer one alternative explanation. It could be that the victim had some app on their phone which was logging SMS. The exploit may have involved sending the SMS code to the phone and forwarding it to the attacker. It's possible there was no exploit on Uber's side at all. We don't have enough information to know one way or the other.
- camoby 9y agoIndeed. I think the story here, isn't so much about the loss in transaction fees, but how an attacker in Russia ordered and paid for a user in Australia's account. I notice the victim uses Android: Is it rooted? What other random stuff do they have installed? etc. etc. - because that will make a huge difference.
- codedokode 9y agoThere are many possible attack vectors. For example, password could be bruteforced by botnet, Android phone could be infected using some Linux kernel vulnerability, SMS could be intercepted because of vulnerabilities in cellular networks. And of course there could be vulnerabilities on Uber's side.