Showing posts with label Mobile Hacking. Show all posts

Hackers Show How To Hack Anyone’s Facebook Account Just By Knowing Phone Number

By exploiting the SS7 flaw, a hacker can hack someone’s Facebook account just by knowing the associated phone number. This flaw allows a hacker to divert the OTP code to his/her own phone and use it to access the victim’s Facebook account. The security researchers, who have explained the hack in a video, advise the users to avoid adding their phone numbers to the public services.

Facebook hacking is also one of the most commonly searched terms on the internet. However, very often people become a victim of malware while searching for Facebook hacking tools.
As we continue to deploy new safety measures to secure our online accounts, hackers and security researchers continue to find new ways to control Facebook accounts.

Recently, we told you how an Indian security researcher spotted a bug in the Facebook website and got $15,000 bug bounty.

Today, we are going to tell you how hackers can hack any Facebook account just by knowing the associated phone number and exploiting an issue with SS7 network.

For those who don’t know, SS7 network (Signalling System Number 7) is a communication protocol that’s used worldwide by the cellphone carriers.

Using a flaw in SS7, hackers can divert the text messages and calls to their own devices. This hacking technique has been shared as a proof-of-concept video by the security researchers from Positive Technologies.

How To  Facebook Account By Knowing Phone Number (Video):
This flaw affects all Facebook users who have associated a phone number with their Facebook accounts.

https://www.youtube.com/watch?v=wc72mmsR6bM
In the demonstration video, the security researchers show that as the first step of the hack, the attacker needs to click on the “Forgot account?” button on Facebook.com website’s homepage.

When Facebook prompts the hacker to enter an email address or phone number, he/she should enter the correct number associated with the account.

By exploiting the SS7 flaw, the hacker is able to divert the OTP message from Facebook to his/her own computer and use it to login to the victim’s Facebook.

The researchers list some measures that a user can take to secure his/her Facebook account. They advise people to avoid adding their phone numbers to public services and rely on email for recovery purposes.

The users are also advised to use 2-factor authentication methods that don’t use SMS texts for sending OTP.
Thursday, June 16, 2016
Posted by Sivapriya

WhatsApp’s end-to-end encryption: How to enable and what it means.

WhatsApp is now end-to-end encrypted at all times. This will ensure that a user’s messages, videos, photos sent over WhatsApp, can’t be read by anyone else; not WhatsApp, not cyber-criminals, not law-enforcement agencies. Even calls and group chats will be encrypted.


WhatsApp co-founder Jan Koum announced the update on his Facebook page, stating that the company has been working on the feature for the last two years.

Koum wrote, “We’ve been working for the past two years to give people better security over their conversations on WhatsApp… People deserve security. It makes it possible for us to connect with our loved ones. It gives us the confidence to speak our minds. It allows us to communicate sensitive information with colleagues, friends, and others. We’re glad to do our part in keeping people’s information out of the hands of hackers and cyber-criminals.”

So what is end-to-end encryption and how exactly does it work in WhatsApp?

WhatsApp is using “The Signal Protocol”, designed by Open Whisper Systems, for its encryption.
In its White Paper, explaining the technical details of the end-to-end encryption, WhatsApp says that “once the session is established, clients do not need to rebuild a new session with each other until the existing session state is lost through an external event such as an app reinstall or device change.”

The post explains how messages are encrypted as well. It reads, “clients exchange messages that are protected with a Message Key using AES256 in CBC mode for encryption and HMAC-SHA256 for authentication. The Message Key changes for each message transmitted, and is ephemeral, such that the Message Key used to encrypt a message cannot be reconstructed from the session.” It also says that calls, large file attachments are end-to-end encrypted as well. 

Note the ever-changing message key can mean a delay in some messages getting delivered, according to the paper. It should be noted that feature is enabled by default in WhatsApp, which means that if you and your friends are on the latest version of the app, all chats will be end-to-end encrypted. Unlike say Telegram where users have to start a secret chat to enable the feature, WhatsApp has the feature on at all times. Users don’t have the option of switching off end-to-end encryption.


Users need to be on the same versions of WhatsApp to ensure that their chats get end-to-end encrypted. If you’ve recently updated the app, and you start a chat with someone else (also on the new version) you are likely to see a message saying, “Messages you send to this chat and calls are now secured with end-to-end encryption.

Once you tap on the message, WhatsApp has a pop-up menu explaining what end-to-end encryption means. Users can verify if the encryption is working as well. If a user taps on verify, they will taken to a page with a QR code, followed by a string of 60 numbers. If your friend is nearby, take their phone scan the code from your phone (the option is there at the bottom of the same page) and if the QR code matches, then the chat is encrypted. When the codes match, a green tick appears; when it doesn’t there’s an exclamation mark in red alerting a user that the chat is not secure. So does the end-to-end encryption work all the time?   We tried verifying some chats that had the message saying encryption was enabled. In some cases, the verification failed for us. In the first case, we tried to verify a chat between an Android and iPhone 6s device (running iOS 9.3.1), and the QR codes didn’t match. We also tried matching QR codes on an two Android phones, and once again we got the red alert indicating no end-to-end encryption
.
Android phones are on the latest version of the app from the Google Play Store. However a verification between a chat on two iOS devices, (iPhone 6s, iPhone 5s) worked for us and showed the green tick. We’re not sure why the verification failed, even though the chat says it is end-to-end encrypted. We might have to wait for another app update that could fix this issue.
Wednesday, April 6, 2016
Posted by Sivapriya

Why Android Malware is worse than you thought.

The future will not only be about thinner, faster, and bendable smartphones, but it will definitely also be about security and bigger online threats.

Let’s imagine a scenario where you don’t need to take photos any more because Google will simply choose the best pictures from a live stream of the day’s events just to make your life easier.

Soon you won’t even need to decide what to eat, your Android phone will know exactly what you need and what you like, showing you the most suitable foods for your age. 

But there’s so much hype around the future of Android that we forget to see the obvious threats, the alarmingly increasing number of Android malware, and the criminal activities carried out on smartphones.

According to a recent International Data Corporation (IDC) study, one out of every one hundred mobile devices (1.4%) on the global market was infected with malware in Q2 2015.

The same study reveals that vendors shipped a total of 334.4 million smartphones worldwide in the first quarter of 2015 and Android dominated the market with a 78% share. That’s a lot of Android phones affected by malware!

0.2% of the devices in the U.S. were infected with malware in the second quarter of 2015. Of the 0.2% infected devices, more than half (62%) were infected with malware aimed at stealing the user’s personal data.

Privacy-stealing malware can get a wide range of personal information and data from your Android device, including contacts, locations, pictures, and login credentials for your online banking.

Using this type of malware, hackers can easily gain access to your bank account data and use it to carry out criminal acts on your behalf or sell your info on the black market. This is not a spy movie we’re talking about, this is a very common scenario in 2016, anywhere in the world.

The good thing is that Google has been constantly making security improvements to the Android platform. The number of vulnerabilities that affect the OS compared to PC platforms is really small. But the customizable nature of the OS still leaves the door open to security breaches.

Guess where that leaves your Android smartphone security? That’s right, in your own hands. Every click counts!

Here are 5 must-follow tips to protect your Android device from malware:
  1. Stop exposing yourself to bad apps in unofficial stores. Always get the latest apps from official Google & partner stores.
  2. A good Antivirus is a must on your phone.
  3. Don’t be afraid of all the updates your phone asks for from time to time. They can be a life saver.
  4. Use a VPN when making online payments using public WiFi.
  5. Beware of data-pulling adware. Install an ad blocker or at least an ad tracker.
No doubt that Android is here to stay and dominate the smartphone market and we’re really excited about the future of Android technology. 

To Know more about Mobile Security.
Our Institute Location:
Redback IT Solutions Private Limited,
#AL 24 TNHB PHASE III,
Sathuvacheri,( Near Vallalar Water Tank)
Vellore. 632602

Contact :
Training Coordinator
8189985551


Friday, February 19, 2016
Posted by Sivapriya

Total Pageviews

- Copyright © REDBACK COUNCIL - RISC -- Powered by Redback - Designed by Redback Council -