follow us on twitter . like us on facebook . follow us on instagram . subscribe to our youtube channel . announcements on telegram channel . ask urgent question ONLY . Subscribe to our reddit . Altcoins Talks Shop Shop


This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here

Author Topic: How Hackers Can Hijack Your Online Wallets!!!  (Read 4077 times)

Offline CryptoZenWorld

  • Sr. Member
  • *
  • *
  • Activity: 601
  • points:
    1
  • Karma: 20
  • ShowMeBiz-New Era of Exhibition Industry
  • Trade Count: (0)
  • Referrals: 7
  • Last Active: April 05, 2020, 10:12:25 AM
    • View Profile

  • Total Badges: 20
    Badges: (View All)
    10 Posts First Post Fifth year Anniversary
How Hackers Can Hijack Your Online Wallets!!!
« on: July 24, 2018, 02:16:02 AM »
Researchers have been warning for years about critical issues with the Signaling System 7 (SS7) that could allow hackers to listen in private phone calls and read text messages on a potentially vast scale, despite the most advanced encryption used by cellular networks.

Despite fixes being available for years, the global cellular networks have consistently been ignoring this serious issue, saying that the exploitation of the SS7 weaknesses requires significant technical and financial investment, so is a very low risk for people.

However, earlier this year we saw a real-world attacks, hackers utilised this designing flaw in SS7 to drain victims' bank accounts by intercepting two-factor authentication code (one-time passcode, or OTP) sent by banks to their customers and redirecting it to themselves.

If that incident wasn't enough for the global telecoms networks to consider fixing the flaws, white hat hackers from Positive Technologies now demonstrated how cybercriminals could exploit the SS7 flaw to take control of the online bitcoin wallets to steal all your funds.

Created in the 1980s, SS7 is a telephony signalling protocol that powers over 800 telecom operators across the world, including AT&T and Verizon, to interconnect and exchange data, like routing calls and texts with one another, enabling roaming and other services.

While demonstrating the attack, the Positive researchers first obtained Gmail address and phone number of the target, and then initiated a password reset request for the account, which involved sending a one-time authorization token to be sent to the target's phone number.

Just like in previous SS7 hacks, the Positive researchers were able to intercept the SMS messages containing the 2FA code by exploiting known designing flaws in SS7 and gain access to the Gmail inbox.

From there, the researchers went straight to the Coinbase account that was registered with the compromised Gmail account and initiated another password reset, this time, for the victim's Coinbase wallet. They then logged into the wallet and emptied it of crypto-cash.

Fortunately, this attack was carried out by security researchers rather than cybercriminals, so there wasn't any actual fraud of bitcoin cryptocurrencies.

This issue looks like a vulnerability in Coinbase, but it's not. The real weakness resides in the cellular system itself.
Positive Technologies has also posted a proof-of-concept video, demonstrating how easy it is to hack into a bitcoin wallet just by intercepting text messages in transit.

Different SS7 Attack Scenarios

This attack is not limited to only cryptocurrency wallets. Any service, be it Facebook or Gmail, that relies on two-step verification are vulnerable to the attacks.

The designing flaws in SS7 have been in circulation since 2014 when a team of researchers at German Security Research Labs alerted the world to it.

The flaws could allow hackers to listen to phone calls and intercept text messages on a potentially massive scale, despite the most advanced encryption used by cellular network operators.

Last year, the researchers from Positive Technologies also gave demonstrations on the WhatsApp, Telegram, and Facebook hacks using the same designing flaws in SS7 to bypass two-factor authentication used by those services.

At TV program 60 Minutes, Karsten Nohl of German Security Research Labs last year demonstrated the SS7 attack on US Congressman Ted Lieu's phone number (with his permission) and successfully intercepted his iPhone, recorded call, and tracked his precise location in real-time just by using his cell phone number and access to an SS7 network.
Although the network operators are unable to patch the issues anytime soon, there's little a smartphone user can do.

Avoid using two-factor authentication via SMS texts for receiving OTP codes. Instead, rely on cryptographically-based security keys as a second authentication factor.

Source: thehackernews.com
█████████
███
██████

█████████████
███████████████████
███████████████████
█████████████████
██████████████████
████████████████
█████████████████
██████████████████████
████████████████████████
█████████████████████████
████████████████████████
████████████████████████
███████████████
████████████████
██████████████████
█████████████████
███████████████████
███████████████████
█████████████
███████
███████
████
███████████


.ExpoCoin


























  №1 platform for Exhibition Industry
  Revenue sharing platform
  Highly secure platform














Altcoins Talks - Cryptocurrency Forum

How Hackers Can Hijack Your Online Wallets!!!
« on: July 24, 2018, 02:16:02 AM »

This is an Ad. Advertised sites are not endorsement by our Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise Here


Giepher C

  • Guest
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #1 on: July 24, 2018, 07:37:15 PM »
Researchers have been warning for years about critical issues with the Signaling System 7 (SS7) that could allow hackers to listen in private phone calls and read text messages on a potentially vast scale, despite the most advanced encryption used by cellular networks.

Despite fixes being available for years, the global cellular networks have consistently been ignoring this serious issue, saying that the exploitation of the SS7 weaknesses requires significant technical and financial investment, so is a very low risk for people.

However, earlier this year we saw a real-world attacks, hackers utilised this designing flaw in SS7 to drain victims' bank accounts by intercepting two-factor authentication code (one-time passcode, or OTP) sent by banks to their customers and redirecting it to themselves.

If that incident wasn't enough for the global telecoms networks to consider fixing the flaws, white hat hackers from Positive Technologies now demonstrated how cybercriminals could exploit the SS7 flaw to take control of the online bitcoin wallets to steal all your funds.

Created in the 1980s, SS7 is a telephony signalling protocol that powers over 800 telecom operators across the world, including AT&T and Verizon, to interconnect and exchange data, like routing calls and texts with one another, enabling roaming and other services.

While demonstrating the attack, the Positive researchers first obtained Gmail address and phone number of the target, and then initiated a password reset request for the account, which involved sending a one-time authorization token to be sent to the target's phone number.

Just like in previous SS7 hacks, the Positive researchers were able to intercept the SMS messages containing the 2FA code by exploiting known designing flaws in SS7 and gain access to the Gmail inbox.

From there, the researchers went straight to the Coinbase account that was registered with the compromised Gmail account and initiated another password reset, this time, for the victim's Coinbase wallet. They then logged into the wallet and emptied it of crypto-cash.

Fortunately, this attack was carried out by security researchers rather than cybercriminals, so there wasn't any actual fraud of bitcoin cryptocurrencies.

This issue looks like a vulnerability in Coinbase, but it's not. The real weakness resides in the cellular system itself.
Positive Technologies has also posted a proof-of-concept video, demonstrating how easy it is to hack into a bitcoin wallet just by intercepting text messages in transit.

Different SS7 Attack Scenarios

This attack is not limited to only cryptocurrency wallets. Any service, be it Facebook or Gmail, that relies on two-step verification are vulnerable to the attacks.

The designing flaws in SS7 have been in circulation since 2014 when a team of researchers at German Security Research Labs alerted the world to it.

The flaws could allow hackers to listen to phone calls and intercept text messages on a potentially massive scale, despite the most advanced encryption used by cellular network operators.

Last year, the researchers from Positive Technologies also gave demonstrations on the WhatsApp, Telegram, and Facebook hacks using the same designing flaws in SS7 to bypass two-factor authentication used by those services.

At TV program 60 Minutes, Karsten Nohl of German Security Research Labs last year demonstrated the SS7 attack on US Congressman Ted Lieu's phone number (with his permission) and successfully intercepted his iPhone, recorded call, and tracked his precise location in real-time just by using his cell phone number and access to an SS7 network.
Although the network operators are unable to patch the issues anytime soon, there's little a smartphone user can do.

Avoid using two-factor authentication via SMS texts for receiving OTP codes. Instead, rely on cryptographically-based security keys as a second authentication factor.

Source: thehackernews.com

Offline altery0518

  • Sr. Member
  • *
  • Activity: 583
  • points:
    1134
  • Karma: 1
  • Trade Count: (0)
  • Referrals: 6
  • Last Active: April 22, 2021, 12:07:47 PM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    10 Posts First Post Fifth year Anniversary
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #2 on: October 12, 2018, 04:56:32 PM »
This topics will remind us to be careful in all of our so can't hackers can't hack our valuable information that might risk our  hold crypto investment or other accounts most especially if it involves in money.
███▌
 ▐██▌
   ███
    ▐██▌
      ███
 ███   ▐██▌                  ██
 ████    ███               ████
 █████▌   ▐██▌           █████
 ███ ███    ███        ████ ███
 ███  ▐██▌   ▐██▌    ████   ███
 ███    ███    ██ ████     ███
 ███     ▐██▌   █████       ███
 ███       ███   ▐█▌        ███
 ███        ▐██▌            ███
 ███          ███           ███
 ███           ███         ███
                 ▐██▌
                  ▐██
                    ██▌
                      ████




..#1 DERIVATIVE.............
..ECOSYSTEM FOR..
..CRYPTO ASSETS.......................

██
██
██
██
██
██
██
██
██
██
██
██
██

██
██
██
██
██
██
██
██
██
██
██
██
██

        ▄▄████████▄▄
     ▄████████████████▄
   ▄████████████████████▄
  ███████████████▀▀  ████
 ████████████▀▀      ██████
▐████████▀▀   ▄▄     ██████▌
▐████▀▀    ▄█▀▀     ███████▌
▐████████ █▀        ███████▌
 ████████ ▄███▄   ███████
  ████████████████▄▄██████
   ▀████████████████████▀
     ▀████████████████▀
        ▀▀████████▀▀

Offline Theroyals

  • Sr. Member
  • *
  • Activity: 340
  • points:
    408
  • Karma: 4
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: October 24, 2020, 04:19:40 PM
    • View Profile

  • Total Badges: 19
    Badges: (View All)
    10 Posts First Post Fifth year Anniversary
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #3 on: October 28, 2018, 04:44:45 AM »
Hackers will hijack our Wallet by using the web phishing that we open. So we should be more careful when opening a web that must enter our personal data including Wallet and Private Key. So if anyone asks for Private Key to get airdrop or giveaway it is sure it will try to cheat and steal hijaking our wallet.

Offline PRIBO247

  • Hero Member
  • *
  • Activity: 1071
  • points:
    900
  • Karma: 6
  • Trade Count: (0)
  • Referrals: 3
  • Last Active: April 09, 2019, 01:08:13 PM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    10 Posts First Post Sixth year Anniversary
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #4 on: November 03, 2018, 06:09:09 PM »
We should also be careful about the links we click in our emails. Most are hackers set up. In fact, one of the latest ways hackers try to steal funds from the unsuspecting is by sending emails with a projects name that the recipient is familiar with. They post a link that is suppose to belong to this project and ask the email receiver to click and check something or the other in the site. The minute you do that, a malware starts stealing information from your phone.

Offline Stuart

  • Hero Member
  • *
  • Activity: 1161
  • points:
    11855
  • Karma: 22
  • FRX: Ferocious Alpha
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: March 02, 2023, 08:45:36 PM
    • View Profile

  • Total Badges: 23
    Badges: (View All)
    Fifth year Anniversary Fourth year Anniversary 10 Posts
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #5 on: November 22, 2018, 07:53:32 PM »
We should also be careful about the links we click in our emails. Most are hackers set up. In fact, one of the latest ways hackers try to steal funds from the unsuspecting is by sending emails with a projects name that the recipient is familiar with. They post a link that is suppose to belong to this project and ask the email receiver to click and check something or the other in the site. The minute you do that, a malware starts stealing information from your phone.

Yeah, this is a true say. I read a little about how hackers can steal useful and meaningful information from anybody, and often time through emails.
Clicking on links that is not from the right/original source is also another pattern used by them, and they do this by creating a similar page with a different extension which one will not easily recognise, and through this, ing of forms/password has been disclosed to them.

Offline M.bhussaini

  • Plagiarism strike
  • Member
  • *
  • Activity: 116
  • points:
    183
  • Karma: -52
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: November 19, 2020, 07:07:40 AM
    • View Profile

  • Total Badges: 16
    Badges: (View All)
    10 Posts First Post Fifth year Anniversary
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #6 on: November 26, 2018, 07:19:09 AM »
Most are hackers set up. In fact, one of the latest ways hackers try to steal funds from the unsuspecting is by sending emails with a projects name that the recipient is familiar with. They post a link that is suppose to belong to this project and ask the email receiver to click and check something or the other in the site.

Altcoins Talks - Cryptocurrency Forum

Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #6 on: November 26, 2018, 07:19:09 AM »


Offline Bhussainn2

  • Full Member
  • *
  • Activity: 243
  • points:
    355
  • Karma: -37
  • Trade Count: (0)
  • Referrals: 2
  • Last Active: November 19, 2020, 07:05:41 AM
    • View Profile

  • Total Badges: 21
    Badges: (View All)
    10 Posts First Post Fifth year Anniversary
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #7 on: November 26, 2018, 07:22:27 AM »
this is a true say. I read a little about how hackers can steal useful and meaningful information from anybody, and often time through emails.
                  ███████████████▄▄                   █████████▄▄▄▄▄▄▄▄▄▄▄                   █████████████████████▄                   ███████    ▀▀██▄▄▄▄                   ███████        █████▌                   ███████        █████▌           ███████    ▄▄██████            ████████████▀▀▀▀▀▀▀                   ██████████████████▀ █████████████████████▄ █████████    ▀▀███████                   ███████        ██████▌     ███████        ██▀▀▀▀      ███████    ▄▄████████                   ██████████████▀▀▀▀▀▀▀                   ███████████████████▀                   ████████████████▀▀ITZON | First Marketplace▬▬▬▬▬ ● ● Powered by the Blockchain |

Offline Rehan

  • Baby Steps
  • *
  • Activity: 20
  • points:
    573
  • Karma: 0
  • Trade Count: (0)
  • Referrals: 0
  • Last Active: December 06, 2023, 05:38:31 PM
    • View Profile

  • Total Badges: 8
    Badges: (View All)
    Fifth year Anniversary Fourth year Anniversary 10 Posts
Re: How Hackers Can Hijack Your Online Wallets!!!
« Reply #8 on: December 27, 2018, 10:11:21 PM »
Computer geniuses can do whatever they want if we do not stick to even the elementary rules of security and anonymity.

 

ETH & ERC20 Tokens Donations: 0x2143F7146F0AadC0F9d85ea98F23273Da0e002Ab
BNB & BEP20 Tokens Donations: 0xcbDAB774B5659cB905d4db5487F9e2057b96147F
BTC Donations: bc1qjf99wr3dz9jn9fr43q28x0r50zeyxewcq8swng
BTC Tips for Moderators: 1Pz1S3d4Aiq7QE4m3MmuoUPEvKaAYbZRoG
Powered by SMFPacks Social Login Mod