26 ms·
How I Could Have Hacked Any Instagram Account
- hmate9 7y agoThis is probably applicable to a lot of other services. I always find it weird that if I accidentally enter the wrong code, I get to try again instead of being sent a new one.
- np_tedious 7y agoFat fingers happen, so I could see allowing maybe 3 attempts from a usability and convenience standpoint. Beyond that, definitely should regenerate / resend. This is to confirm you own that phone number. It's not hard to get another
- penagwin 7y agoYeah for sure, a few attempts isn't a problem IMO, even only say 6 digits there's too many permutations. > I have used 1000 different machines (to achieve concurrency easily) and IPs to send 200k requests (that’s 20 percent of total one million probability) in my tests. I'm just surprised nobody looked at a dashboard and said "huh this account is getting 200k requests", surely that should be raising red flags?
- kristiandupont 7y agoHow many requests does IG handle per second? I am not even going to guess a number but I am sure 1000 specific requests would drown in that. So you would need a dashboard that specifically visualizes this kind of thing. Do that and you are now protecting yourself in one type of scenario. But there are endless other scenarios that you still wouldn't see.
- penagwin 7y agoAuthentication is certainly a scenario I think you'd want to monitor for brute force attacks? Sure IG gets 1000's+ requests a second, but they shouldn't be getting 1000's+ requests per second per user - especially on a login route. I monitor 400 requests on our website - A massive spike in those would warrant investigation.
- ilikehurdles 7y agoI'm sure IG gets several orders of magnitude more than 1000s of requests per second. Even if a dashboard existed visualizing excess request traffic per route per user, when you're talking about this kind of request volume, there is an indexing lag + a reporting lag + alerting lag (assuming there is alerting on this specific scenario on top of the dashboard) + human or automated response lag. It sounds like this attack could be completed in minutes rather than hours or days, it's feasible that it would have succeeded well before anyone got around to mitigating it.
- davinic 7y agoBut once you know that this is a specific attack surface, it's far easier to limit the surface (fix the problem) rather than build a dashboard that a human has to monitor perpetually.
- jumbopapa 7y agoI'm surprised that it's limited to just numbers. Introducing letters and symbols would significantly increase the number of permutations and decrease the odds of a successful brute force attack. I think my bank uses letter is text-based 2FA.
- deanclatworthy 7y agoPretty interesting that distributed circumvention of rate limiting has to be considered its own class of vulnerability nowadays. I would think (of course) many other services are vulnerable. Rate limiting is hard.
- fortran77 7y agoThat's some hole! Imagine if this were used to get access to a celebrity's IG account. A lot of "damage" to a celebrity brand could have been done.
- eitland 7y agoNow this left me wondering how hard it would be to guess the bugcrowd url at the bottomof the last picture.
- odensc 7y agoI've always wondered - is there some kind of software that can match font glyphs from a partial image?
- degenerate 7y agoI spot-checked some of those IPs in the video, and it appears all of them are on Amazon. So, what does the attacker's stack look like? Is it a bunch of servers running PHP and listening for a connection to run curl? Or Lambda functions configured to proxy the connection attempt to IG? Curious how much effort goes into setting up an attack like this. It's surprising (to me) that so many IPs can be used for so little money.
- stibba 7y agoI'm curious too, how would he set up so many machines that do the same thing?
- natrik 7y agohttps://stackoverflow.com/questions/38032666/how-to-create-and-run-multiple-ec2-instances-with-same-configurations-and-softwa https://stackoverflow.com/questions/38032666/how-to-create-a...
- laumars 7y agoHe's probably lambda rather than EC2 or even docker but I'd be interested to know the details too.
- ldoughty 7y agoDocker doesn't help distribute requests over IPs, lambda or ec2 most likely. You can easily set up a launch configuration for EC2 that runs a script or program... But with a bit more work lambda will save a lot of money
- laumars 7y ago> Docker doesn't help distribute requests over IPs That depends on your orchestration. AWS provide several tools for running Docker without having to maintain your own EC2 hosts. > You can easily set up a launch configuration for EC2 that runs a script or program... But with a bit more work lambda will save a lot of money You could do that via a launch configuration but that would be a pretty naff way of doing it. Baked AMI would be easier but personally I'd prefer ECS (Docker) or lambda. Cheaper, quicker to deploy, lower ramp up times. Ultimately though, there's no wrong way to do this - just personal preference.
- someexgamedev 7y agoIs this reset mechanism conceptually flawed? Even with one attempt before invalidating the code, you have a 1:999,999 shot of stealing someone's account by lotto. Not bad odds for an automated process. It's like every account on Instagram has an alternative six digit password.
- floatingatoll 7y agoSony was using 8 characters of alphanumeric at one point. They reduced it to 6 digits. It turns out that the chance of guessing six digits successfully given one or two tries only is low enough to satisfy human beings when it comes to “annoyance versus protection”, especially when codes expire after a couple attempts.
- raws 7y agoYeah that is if they limit attempts and put code expiry in place which instagram did not have and as well it's missing warning systems for users as well as a temporary locking mechanism for such a feature if fraud is detected by the user. Those limits are more important to personalities than a lambda user.
- throwaway66666 7y agoProblem with alphanumeric, is you have people from foreign countries who do not even have an english keyboard installed on their phone. Default is probably their native language and they do not care to add a secondary or switch. Numeric values solve that problem. edit: drunk typing
- kalleboo 7y agoIs that a thing? Domain names, email addresses, passwords all tend to require the latin character set. Here in Japan I can't remember seeing a single site that uses kanji passwords.
- deleted 7y ago[deleted]
- 7y ago
- GhostVII 7y agoUsing a phone number for password reset seems like a terrible idea in general, especially if you have SMS-based 2FA. Phone numbers are way to easy to social engineer, and if your second factor can reset your first one, you don't have 2FA. Also if I am reading it correctly, it sounds like the rate limiting was being done per-IP, which sounds strange. Why wouldn't Instagram just allow a fixed number of tries (some low limit, like 25) from any IP before invalidating the code? I don't really see a scenario where it makes sense to have per-IP rate limiting here. I guess they are probably just using the rate limiting features which are built in to whatever framework Instagram is using for their API.
- pmarreck 7y agoI have turned off phone 2FA on all services that permit me to do so after getting hacked by someone using that exploit. Typically I use Google 2FA via Authy or Authy itself
- shawabawa3 7y agoyou should be aware that Authy can by default be taken over with just your sim card. I believe with the right settings you can disable this behaviour
- zwily 7y agoYes, you have to disable “multiple devices”. You just have to remember to re-enable it if you want to install Authy on a new phone and reinstall from backup.
- claviola 7y agoI've been considering getting a second, secret SIM card exclusively for use with services where SMS 2FA is the only option.
- filoleg 7y agoI've been using Google Voice for that purpose for years, and it has been perfect. The phone number that is for 2FA only, shouldn't be as easy to social engineer your typical telcom, since it is all controlled from within my Google account, and I get immediate security notifications if something fishy is up.
- tuna-piano 7y agoCould someone explain how this person is allowed to do that type of testing (sending 200,000 requests)? How would Facebook know he is a white hat and not a black hat? I would be interested in starting to try some of these programs, but a bit scared I'd be doing something illegal... Where is the line?
- jakecraige 7y agoThey have a bug bounty program that gives you permission to do certain kinds of things and it not be illegal since you’re planning to report anything you find (and get paid for it)
- stibba 7y agoIf you want to test a company look at their 'Responsible disclosure'. For example: https://www.facebook.com/whitehat https://www.facebook.com/whitehat
- btown 7y agoThe actual "bug" is that Facebook did not have sufficient controls in place to even detect this type of brute-force attack, much less make it impossible to attempt in the first place. Facebook seems (IN THIS INSTANCE) to have appreciated the white-hat nature of this and awarded the bug bounty, but it very well might not have. And certainly other organizations don't take nearly as friendly stances. Generally, I wouldn't bet on most organizations seeing brute-force attacks as in-scope for bug bounties - this is by no means legal advice though.
- filleokus 7y agoI quite recently learnt about “Residential proxies”, for a scraping idea I had. Seems like that can be useful for attacks like this. It’s surprisingly cheap to get access to services which fan out your requests over millions of normal residential IPs, making them (I assume) hard to block. Of course their use can be highly objectionable, as well as how they got the proxies installed in homes of people in the first place (semi-malware?) E.g https://oxylabs.io/pricing/residential-proxy-pool https://oxylabs.io/pricing/residential-proxy-pool
- CPLX 7y agoThis page was amusing to me: https://oxylabs.io/solutions/ad-verification https://oxylabs.io/solutions/ad-verification This is a euphemism right? Like what they're really saying is that this service would make it possible to fake ad traffic right?
- 55555 7y agolol... The first sentence below definitely doesn't belong. The second outlines the legitimate use case. > Hackers and fraudsters use various schemes to fake ad traffic and, as a result, a vast number of ads are never seen by real people. Therefore, more and more companies use proxies to detect fraud, improve ad performance, and check advertisers’ landing pages anonymously.
- CPLX 7y agoIs there actually a legit use though? Like what's the use case for needing a million residential proxy IP's to legitimately test and evaluate advertising?
- sbarre 7y agoThis has to be provided by a botnet or some other malware, right? They claim 30M residential IP addresses.. How would this be done otherwise? There's no info on the site about "signing up" to be a proxy, just about using them..
- T1glober 7y agoThis is pretty much dependent on your attack vector being, for the most part, infinite. Method of delv and spawn rate, etc. A 0day RAT for android was hitting about 500 devs per second before getting fixed.
- mettamage 7y agoI saw this a couple of days ago in the /new section. It seems some good modding is being done! I take my hat of for you mister (or miss) mod :)
- rwmj 7y agoI wonder if they (FB) have an IPv6 API endpoint. That could make acquiring the necessary number of distinct IP addresses much easier.
- yardstick 7y agoGood question! I can see IPv6 rate limiters being adjusted to work on /64s and larger.
- miyuru 7y agoAll Facebook services are IPv6 enabled by default and their internal network is IPv6 only. https://code.fb.com/production-engineering/legacy-support-on-ipv6-only-infra/ https://code.fb.com/production-engineering/legacy-support-on...
- Chris_Chambers 7y agoHaving all the text below the headline and above the fold be a giant text-only ad indistinguishable from the content is really stupid. I couldn’t even swipe right to go back to write this comment because it somehow hijacked the implicit mobile back button. This site is a cancerous pile of shit.
- rolltiide 7y ago"WE have decided to reward you $30,000" should be "Because the market has decided that hacking top tier instagram accounts is worth a low seven figures, here is your $1,000,000 payout to save you the time, effort and liability of monetizing this yourself"
- ISL 7y agoThere's one key omission in that list -- time, effort, liability, and prison.
- rolltiide 7y agoliability covers prison, it is not an omission.
- paulpauper 7y agoit would not be that profitable anyway after factoring server costs. say you hack into one celeb account. Instagram would immediately recognize the problem and fix it. but until they fix it, maybe you could make a few hundred dollars promoting some crpyto thing. Who knows. .s Instagram does not allow live links and suppresses posts that look like ads, so instead of being seen by millions of followers is only seen by thousands.
- rolltiide 7y agothats not how the instagram economy works. accounts are basically worth an additional $100 for every 5,000 followers, multiplied by engagement percent. ie. 1% engagement account with 5,000 followers would be worth around $100, 2% with 5,000 followers worth around $200. forget accounts with high heat (A and B-list celebrities), people flip meme and inspirational accounts ALL DAY. (this a simplistic scale from how I've seen the opening bids be set, and the negotiations I've had). when when you aren't flipping and suddenly rebranding accounts, you get ROI by doing promos which have a fairly fixed cost. $10 to post about someone else or tag them in a story. the better your account is, the more you can charge and the less time you have to show someone. with stories you can stack promos all day and break even on an account in a week. you get ROI to break even very quick. (a hacker or phish may try other things like scamming D-list model's thirsty followers in Direct Messages.) > maybe you could make a few hundred dollars promoting some crpyto thing false. you'll get 2% of the entire currency pre-mined and minted straight to you, 3% of the funds raised, and upfront fees in the low five figures. and if the crypto is post-launch, you'll get upfront fees, a lot less tokens, and then the hundreds of thousands you'll make pumping it if people bite. otherwise, you have to buy yourself and hope you can pump it, and if you are poor thats the only way you'll wind up with "just a few hundred dollars promoting some crypto thing" yeah leave this to the pros and imagine people are still just buying fake followers or something relevant half a decade ago. honestly, I feel like Facebook should be acting as an escrow agent and taking a cut of the promos and account sales. Would be safer for participants and lucrative for FB.
- Swaglord333 7y agoI feel like this was worth more than 30k
- ryanlol 7y agoTo people selling IG accounts, yes. Not to facebook.
- paulpauper 7y ago$30,000 for that? >In a real attack scenario, the attacker needs 5000 IPs to hack an account. It sounds big but that’s actually easy if you use a cloud service provider like Amazon or Google. It would cost around 150 dollars to perform the complete attack of one million codes. no, it does not have nearly that many. I think they only have 100 or so. IPs are expensive. It would probably cost thousands of dollars to pull this off.
- lostmsu 7y ago> I think they only have 100 No, that is wrong. AWS has millions. > IPs are expensive. It would probably cost thousands of dollars Not if you rent them for 10 minutes each, not.
- shitloadofbooks 7y agoRather than guessing, you can check yourself: https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.... AWS has _millions and millions_ of IPv4 addresses and an unfathomably large amount of IPv6 addresses.
- mychael 7y agoLow bounties like that are going to motivate hackers to sell to malicious actors instead of going through the proper channels. Facebook should know better.
- bhandziuk 7y ago30,000 $ is a low bounty? It seems like a lot of money to me. How much should they reward?
- paulpauper 7y agoThe real vulnerability is that Amazon makes it very cheap to make a botnet almost instantly
- georgiecasey 7y agowhich most webservices have flagged as dodgy IPs. surprised instagram don;t
- dane-pgp 7y agoSo what pricing changes would you recommend Amazon adopt to make this sort of whitehat security research prohibitively expensive?
- thtthings 7y agoWhy do they not lock the account after n number of tries say 5? The user will need to use a different way to authenticate if they can't enter the correct code in 5 tries
- herpderperator 7y agoSeems like a lot of improvements could have been made here. After you get the code wrong, it should reset and send you a different code. If you get more than 3 wrong in some pre-determined time, it should lock the person out for some other pre-determined time. You could even use exponential backoff time in both scenarios. Keeping the code the same after getting it wrong just seems really stupid.
- hkai 7y agoMathematically, does regenerating the code make a lot of difference? You can simulate that by running a loop that generates a random 4-digit number in each iteration and randomly guessing it. On average, you will guess the number after 10,000 iterations. It doesn't help that you regenerate the number each time. Your chance is still 1/10,000.
- ape4 7y agoI need to say "endpoint" (rather than URL) to sound current.
- w8rbt 7y agoI'd just use IPv6 and Go from AWS. No need to have 1000's of machines.
- atum47 7y agonice job
- mcnichol 7y agoSo a bit of a strongly worded title. I'm going to nitpick for a second. First you need the device-id, second you need the code that will be sent via text. The code sent via text is 6 digits meaning 10^6 == 1MM permutations. He shows how he can enumerate these using 1K IP's ultimately bruteforcing the reset code. The Device ID is still not captured although I'm guessing they allow handwaving via a malicious app or something of that nature. Credit where credit is due, he cleverly enumerates them concurrently across 1K IP's and earned his bonus. Interested how they fixed it...guessing adding a random session guid in the url and maybe increasing entropy && length of the secret.
- AgentME 7y agoHe's doing the password reset flow from his own device, and receives a link to the form containing the session id and his device id. He doesn't need to bruteforce those. Instagram had a limit on the number of times that the user could guess the code, but they had a race condition that let the limit be bypassed. The fix is for them to fix the race condition.
- Hitton 7y agoNice find, but the original author has no idea what race condition means. This isn't race condition, it's just brute force combined with per ip rate limiting avoidance.