Tuesday, March 28, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Two-factor authentication: Facebook Instagram bug enabled workaround

Kiratas by Kiratas
January 31, 2023
in World
Reading Time: 2 mins read
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Facebook parent company Meta was worth a reward of around 27,000 US dollars for discovering and reporting a vulnerability through which attackers could have bypassed the two-factor authentication in Meta’s account overview. The IT researcher Gtm Mänôz has now explained the errors.

Facebook gap through unrestrained trial and error

As Mänôz now explains, he came across the meta account overview via Instagram. There, under the personal details, an e-mail address and telephone number can be added, which are then added to the Instagram and Facebook accounts. Two-factor authentication takes place in the form of a six-digit code that Meta sends by email or SMS.

As the data is added, Account Management makes connections to API endpoints that attackers could use a proxy to intercept and manipulate. Since Meta did not implement a rate limit such as Fail2ban, which temporarily blocks access by a computer after too many unsuccessful attempts, attackers could have used brute force to test all six-digit combinations. In the end, attackers would have verified access with a phone number or email address.

Meta’s bug bounty program Facebook account has confirmed the bug. The company “fixed a bug reported by Nepal’s Gtm Mänôz that could allow an attacker to bypass SMS-based 2FA by exploiting a lack of rate limiting to brute-force guess the verification pin used to a phone number is confirmed”. Meta paid a reward of $27,200 for the report.

In addition to the commercial bug bounty programs, especially large and solvent corporations, there are also non-commercial projects. At the end of last year, the Open Bug Bounty project came up with a whopping one million security gaps on the web that could be fixed in this way.

(dmk)

To home page

Tags: authenticationBrute ForceBugbypassenabledFacebookInstagramSecurityTwo Factor AuthenticationTwofactorworkaround

Related Posts

World

.NET 6.0/7.0: Become an expert on modern .NET in six Heise webinars

by Kiratas
March 28, 2023
World

The parricide who killed his mother by strangling her with a belt in Seville accepts six years in prison

by Kiratas
March 28, 2023
World

HomeKit 2: Apple dares a new attempt with iOS 16.4

by Kiratas
March 28, 2023
World

Toni Costa to the PSIB: “They ask us for many explanations but they don’t give”

by Kiratas
March 28, 2023
World

New attempt at data retention in the EU Council of Ministers

by Kiratas
March 28, 2023
Next Post

Netflix: Regular WiFi logins to prevent account sharing

Andalusian bishops condemn the jihadist attack: "Violence is never justified in the name of God"

Apple HomePod 2 in the test: just as expensive, but still better?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.
Contact Us:
[email protected]

Categories

  • Automobile
  • Business
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence Bank business ChatGPT Check Cybercrime data data protection day Energy EU euros February Google government health iOS iPhone law League Linux and Open Source live Mac Madrid March Microsoft million online photo price result Security Smartphone Software Development Spain Spanish Sánchez Test time today Vulnerabilities world year years

Recent Posts

  • .NET 6.0/7.0: Become an expert on modern .NET in six Heise webinars
  • A man sentenced to nine months in prison for hanging his dog
  • The parricide who killed his mother by strangling her with a belt in Seville accepts six years in prison
  • DMCA
  • Home

© Kiratas 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Kiratas 2023. All Rights Reserved.