Showing posts with label Active Defense. Show all posts
Hackers Show How To Hack Anyone’s Facebook Account Just By Knowing Phone Number
By exploiting the SS7 flaw, a hacker can hack someone’s Facebook account just by knowing the associated phone number. This flaw allows a hacker to divert the OTP code to his/her own phone and use it to access the victim’s Facebook account. The security researchers, who have explained the hack in a video, advise the users to avoid adding their phone numbers to the public services.
Facebook hacking is also one of the most commonly searched terms on the internet. However, very often people become a victim of malware while searching for Facebook hacking tools.
As we continue to deploy new safety measures to secure our online accounts, hackers and security researchers continue to find new ways to control Facebook accounts.
Recently, we told you how an Indian security researcher spotted a bug in the Facebook website and got $15,000 bug bounty.
Today, we are going to tell you how hackers can hack any Facebook account just by knowing the associated phone number and exploiting an issue with SS7 network.
For those who don’t know, SS7 network (Signalling System Number 7) is a communication protocol that’s used worldwide by the cellphone carriers.
Using a flaw in SS7, hackers can divert the text messages and calls to their own devices. This hacking technique has been shared as a proof-of-concept video by the security researchers from Positive Technologies.
How To Facebook Account By Knowing Phone Number (Video):
This flaw affects all Facebook users who have associated a phone number with their Facebook accounts.
![]() |
| https://www.youtube.com/watch?v=wc72mmsR6bM |
In the demonstration video, the security researchers show that as the first step of the hack, the attacker needs to click on the “Forgot account?” button on Facebook.com website’s homepage.
When Facebook prompts the hacker to enter an email address or phone number, he/she should enter the correct number associated with the account.
By exploiting the SS7 flaw, the hacker is able to divert the OTP message from Facebook to his/her own computer and use it to login to the victim’s Facebook.
The researchers list some measures that a user can take to secure his/her Facebook account. They advise people to avoid adding their phone numbers to public services and rely on email for recovery purposes.
The users are also advised to use 2-factor authentication methods that don’t use SMS texts for sending OTP.
Thursday, June 16, 2016
Posted by Sivapriya
Best Hacking Apps For Android Phones
As
Android has emerged as the top mobile operating system, we have seen a great
rise in the Android hacking apps. For our readers, we have prepared a list of
the best hacking apps for Android that can be used by a technology enthusiast,
an IT security administrator, or an ethical hacker.
9
Best Hacking Apps For Android Phones – 2016
AndroRAT
AndroRAT
stands for Android and RAT (Remote Administrative Tools). This top hacking tool
was released a long time ago as a client/server application. The app aims to
give you the control of the Android system remotely and fetch the information
from it. This Android app runs as a service right after the boot. So, a user
doesn’t need to interact with the service. The app provides you the ability to
trigger the server connection by a call or SMS.
The
features in this useful Android hacking app include collecting information like
contacts, call logs, messages, and location. The app also allows you to
remotely monitor received message and state of phone, making a phone call and
sending texts, taking picture from camera, opening URL in the default browser
etc.
Hackode
Hackode
is an Android app which is basically a collection of multiple tools for ethical
hackers, IT specialists, and penetration testers. In the app, there are three
modules –Reconnaissance, Scanning, Security Feed — available in the
application.
With
this app, you get the functionalities like Google hacking, SQL Injection, MySQL
Server, Whois, Scanning, DNS lookup, IP, MX Records, DNS Dif, Security RSS
Feed, Exploits etc. It’s a great Android hacking app to start with and it
doesn’t ask for your private information to operate.
zANTI
zANTI
is a reputed Android hacking suite from Zimperium. This software suite comes
with multiple tools that are widely used for penetration testing purposes. This
mobile penetration testing toolkit allows the security researchers to scan a
network easily. This toolkit allows the IT administrators to simulate an
advanced hacking environment to detect multiple malicious techniques.
zANTI
could be called an app that brings the power of Backtrack on your Android
device. As soon as you login into zANTI, it maps the entire network and sniffs
the websites being visited along with their cookies — thanks to ARP cache
poisoning on devices.
The
various modules in the app are network mapping, port discovery, sniffing,
packet manipulation, DoS, MITM, and more.
FaceNiff
FaceNiff
is a top Android hacking app that allows you to intercept and sniff your WiFi
network traffic. This tool is widely used to snoop into people’s Facebook,
Twitter and other social media websites using your Android device. This
hacker-favorite tool steals cookies from WiFi network and gives an attacker an
unauthorised access to victim’s account.
FaceNiff
is developed by Bartosz Ponurkiewicz — the same developer who wrote Firesheep
for Firefox hacking on desktop.
Droidsheep
Droidsheep
is an effective hacking app developed for security analysts interested in
playing with Wi-Fi networks. The app has the ability to hijack the web session
profiles over a network and it works with almost all services and websites.
As
you fire up the Droidsheep app, it acts a router that monitors and intercepts
all the Wi-Fi network traffic and fetches the profiles of active sessions. With
this app, one can sniff Facebook, LinkedIn, Twitter and other social media
accounts.
DroidSheep
Guard, another version of app, helps you to detect ARP-Snoofing on the networks
i.e. the attacks by FaceNiff, Droidsheep, and other software.
APKInspector
APKInspector
is an app that allows you to perform reverse engineering tricks. With this app,
you can get the graphic features and analysis functions for the users to get a
deep insight. This powerful Android hacking tool helps you get the source code
of any Android app and visualize the DEX code to erase the credits and license.
Nmap
One
of the most popular network scanning apps for desktop can also be used on
Android operating system. Nmap works on both non-rooted and rooted phones. If
you are a beginner Android hacker, this hacking app app is a must have.
SSHDroid
SSHDroid
is a SSH server implementation developed for Android that allows you to connect
your Android device to a PC and run commands like ‘terminal’ and ‘adb shell’
and edit files. It provides an extra security later when you are connecting to
a remote machine.
The
app provides features like shared-key authentication, WiFi autostart whitelist,
extended notification control etc.,
Tuesday, January 19, 2016
Posted by Sivapriya

