Who would have Bhawri (2021) Hindi Web Seriesthought that, in the end, it would be the humble voicemail that would do us all in?
Your Google, Microsoft, Apple, WhatsApp, and even Signal accounts all have an Achilles' heel — the same one, in fact. And it turns out that if you're not careful, a hacker could use that weakness to take over your online identity.
Or so claims self-described "security geek" Martin Vigo. Speaking to an enthusiastic collection of hackers and security researchers at the annual DEF CON convention in Las Vegas, Vigo explained how he managed to reset passwords for a wide-ranging set of online accounts by taking advantage of the weakest link in the security chain: your voicemail.
SEE ALSO: The hackers just arrived, and they're already breaking VegasYou see, he explained to the crowd, when requesting a password reset on services like WhatsApp, you have the option of requesting that you receive a callwith the reset code. If you happen to miss the phone call, the automated service will leave a message with the code.
But what if it wasn't youtrying to reset your password, but a hacker? And what if that hacker also had access to your voicemail?
Here's the thing: Vigo wrote an automated script that can almost effortlessly bruteforce most voicemail passwords without the phone's owner ever knowing. With that access, you could get an online account's password reset code and, consequently, control of the account itself.
And no, your two-factor authentication won't stop a hacker from resetting your password.
One of Vigo's slides laid out the basic structure of the attack:
1. Bruteforce voicemail system, ideally using backdoor numbers
2. Ensure calls go straight to voicemail (call flooding, OSINT, HLR)
3. Start password reset process using "Call me" feature
4. Listen to the recorded message containing the secret code
5. Profit!
A recorded demo he played on stage showed a variation of this attack on a PayPal account.
"In three, two, one, boom — there it is," Vigo said to audience applause. "We just compromised PayPal."
Vigo was careful to note that he responsibly disclosed the vulnerabilities to the affected companies, but got a less than satisfactory response from many. He plans to post a modified version of his code to Github on Monday.
Notably, he reassures us that he altered the code so that researchers can verify that it works, but also so that script kiddies won't be able to start resetting passwords left and right.
So, now that we know this threat exists, what can we do to protect ourselves? Vigo, thankfully, has a few suggestions.
First and foremost, disable your voicemail. If you can't do that for whatever reason, use the longest possible PIN code that is also random. Next, try not to provide your phone number to online services unless you absolutely have to for 2FA. In general, try to use authenticator apps over SMS-based 2FA.
But, really, the most effective of those options is shutting your voicemail down completely. Which, and let's be honest here, you've likely been looking for a reason to do anyway. You can thank Vigo for providing you with the excuse.
Topics Cybersecurity
Best Amazon device deals: Fire TV sticks, Echo Show bundles, and more devices still on sale postGift idea for teens: Save 31% on the Canon Ivy 2 Mini Photo Printer at AmazonColleen Ballinger allegations: What's going on with the YouTuber's ukulele song response?Ghost People: On Pinocchio and Raising Boys by Sabrina Orah MarkWhat is an ADHD watch?Pornhub accused of abusing user data by #StopDataPornPassing Mary Oliver at Dawn by Summer BrennanWordle today: The answer and hints for November 30Best Amazon device deals: Fire TV sticks, Echo Show bundles, and more devices still on sale postI Have Wasted My LifeGift idea for teens: Save 31% on the Canon Ivy 2 Mini Photo Printer at AmazonHow to get your Spotify Wrapped 2023 if it's not showing upNYT's The Mini crossword answers for November 30Archive of Our Own is down, and it could be offline for weeksTesla will deliver the first Cybertrucks today. Here's how to watch.Spotify Wrapped 2023 date: When it comes out, how to view yoursPoetry Rx: This Is the Year by Sarah KayThe cherry emoji and 14 other emoji you can use to sextCooking with the Strugatsky Brothers by Valerie StiversTo Be At Home Everywhere by Drew Bratcher Kodak is using nostalgia to win its way back into your heart This pro baseball player is willing to go anywhere — except Oakland Social media users capture a hell of lightning storm over their city How to (virtually) attend the 'Rogue One' premiere Snoop Dogg's 2016 recap is a thing of beauty India announces its largest solar rooftop tender Donald Trump will still be involved with 'Celebrity Apprentice' after taking office Dinosaur tail found preserved in amber 'Jurassic Park' 'Fuller House': Kimmy and Stephanie talk sisterhood and Season 2 Now Vodafone too is offering free voice calls in India ‘DuckTales’ is diving back onto your TV in 2017 Al Gore will open Sundance with a follow How to fight back when your face becomes an out Everything that could go wrong with Amazon Go How to save all the personal data on your Note7 before Samsung bricks it An expert's advice for watching the imminent "blood moon" total lunar eclipse Kanye West was spotted sitting in a chair and doing stuff Airplane dating app is now boarding for all your in How DC's Young Animal imprint is changing comics PewDiePie just trolled everyone in the dumbest way possible
2.8767s , 10137.2734375 kb
Copyright © 2025 Powered by 【Bhawri (2021) Hindi Web Series】,Exquisite Information Network