HackerSecret.com - The Most Authoritative Site in the World on the Hacking Tools and Techniques, Penetration Testing and CyberSecurity

  • Home
  • Visit Our Shop
  • Download the free App
  • Contact us for Info
VISIT OUR SHOP! CLICK HERE !

My hacked (for apps) iPhone & an iPod Touch at the Apple Store

  • 0
Wednesday, 19 June 2019 / Published in Hacker

My hacked (for apps) iPhone & an iPod Touch at the Apple Store
location hacking software
Image by Steve Rhodes

AppleAppsHackediPhoneiPodStoreTouch

Android Apps uses a novel technique to by-pass 2FA and steal Bitcoin

  • 0
Wednesday, 19 June 2019 / Published in Hacking

Expert discovered a new technique bypassing SMS-based two-factor authentication while circumventing Google’s recent SMS permissions restrictions

The popular security expert Lukas Stefanko from ESET discovered some apps (namedBTCTurk Pro Beta and BtcTurk Pro Beta) impersonating the Turkish cryptocurrency exchange, BtcTurk, in the attempt of stealing login credentials.

by-pass 2FA and steal Bitcoin

In order to steal the 2FA OTPs the apps read the credentials that appear in 2FA notifications from the service, instead of intercepting the SMS messages delivering them,

Stefanko explained that the new increasing interest in Bitcoin is associated with the growth of its price.

“When Google restricted the use of SMS and Call Log permissions in Android apps in March 2019, one of the positive effects was that credential-stealing apps lost the option to abuse these permissions for bypassing SMS-based two-factor authentication (2FA) mechanisms.” wrote the expert.

“We have now discovered malicious apps capable of accessing one-time passwords (OTPs) in SMS 2FA messages without using SMS permissions, circumventing Google’s recent restrictions.”

When the apps are executed for the first time they request ‘notification access’ permission that is used to read the notifications displayed by other apps installed on the device, dismiss those notifications, or click buttons they contain.

Once the permission is granted to the apps, they will display a fake login message asking for the user’s BtcTurk login credentials. Once the users will provide the credentials, the apps display a false error message.

“Opss! Due to the change made in the SMS Verification system, we are temporarily unable to service our mobile application. After the maintenance work, you will be notified via the application. Thank you for your understanding.” reads the message (Translated from Turkish).

In the meantime, the login credentials for the services are sent back to the attacker’s server. 

At this point, the rogue apps leverage the notifications access permission to read all incoming notifications and select the ones related to applications of interest. The apps read the notifications associated with apps whose names contain the keywords, gm, yandex, mail, k9, outlook, SMS, and messaging. These notifications are sent to the attacker, who select the ones containing the one-time passwords used in 2FA.

“The displayed content of all notifications from the targeted apps is sent to the attacker’s server. The content can be accessed by the attackers regardless of the settings the victim uses for displaying notifications on the lock screen. The attackers behind this app can also dismiss incoming notifications and set the device’s ringer mode to silent, which can prevent victims from noticing fraudulent transactions happening.” continues the expert.

At this point, it is easy for the attackers to impersonate the victims while attempt to access the services. Any 2FA OTP can be dismissed from the victim’s phone and sent to the attacker, the attacker with this scheme has access to login credentials and OTP and can use them to access the account.

Experts at ESET are warning of the rapid spread of this technique that was recently observed in attacks against users of the Turkish Koineks exchange. ESET believes that the threat actor behind the attacks was the same.

“Just last week, we analyzed a malicious app impersonating the Turkish cryptocurrency exchange Koineks(kudos to @DjoNn35 for bringing that app to our attention). It is of interest that the fake Koineks app uses the same malicious technique to bypass SMS and email-based 2FA but lacks the ability to dismiss and silence notifications.”

“According to our analysis, it was created by the same attacker as the “BTCTurk Pro Beta” app analyzed in this blogpost. This shows that attackers are currently working on tuning this technique to achieve the “next best” results to stealing SMS messages.”

Experts believe that crooks will start using this technique against target in other industries, including banks and financial institutions.

Pierluigi Paganini

(SecurityAffairs – SFA, hacking)

The post Android Apps uses a novel technique to by-pass 2FA and steal Bitcoin appeared first on Security Affairs.

Security Affairs

androidAppsBitcoinBypassNovelstealtechniqueUses

Seven Web Frameworks in Seven Weeks: Adventures in Better Web Apps (Pragmatic Programmers)

  • 0
Sunday, 16 June 2019 / Published in Hacker

Seven Web Frameworks in Seven Weeks: Adventures in Better Web Apps (Pragmatic Programmers)

Seven Web Frameworks in Seven Weeks: Adventures in Better Web Apps (Pragmatic Programmers)

Whether you need a new tool or just inspiration, Seven Web Frameworks in Seven Weeks explores modern options, giving you a taste of each with ideas that will help you create better apps. You’ll see frameworks that leverage modern programming languages, employ unique architectures, live client-side instead of server-side, or embrace type systems. You’ll see everything from familiar Ruby and JavaScript to the more exotic Erlang, Haskell, and Clojure. The rapid evolution of web apps demands innovat

Price List: £30.50

Only for today on Amazon: £12.39

AdventuresAppsBetterFrameworksPragmaticProgrammersSevenWeeks

Devs slam Microsoft for injecting tech-support scam ads into their Windows Store apps

  • 0
Sunday, 16 June 2019 / Published in Hacking

Redmond kinda just shrugs after advertising systems sling scareware pop-ups at users

Application makers are crying foul after some of their programs distributed via the Windows Store popped open tech-support scam ads on users’ desktops.…

The Register – Security

AppsDevsinjectingIntoMicrosoftScamslamStoretechsupporttheirWindows

RAMBleed picks up Rowhammer, smashes DRAM until it leaks apps’ crypto-keys, passwords, other secrets

  • 0
Friday, 14 June 2019 / Published in Hacking

Boffins blast boards to boost bits

Bit boffins from Australia, Austria, and the US have expanded upon the Rowhammer memory attack technique to create more dangerous variation called RAMBleed that can expose confidential system memory.…

The Register – Security

AppscryptokeysDRAMleaksPasswordspicksRAMBleedRowhammerSecretssmashesuntil
  • 1
  • 2
  • 3

Click here now to visit our Shop!

Click here now to visit our Shop!

Other 2300 users like you have already done it this year!

Choose the product you need here!

  • THE FIRST TRUE ANDROID SMARTPHONE FOR HACKING WITHOUT ROOT UNIQUE IN THE WORLD WITH ALL THE APPS !!! 499,99€ 229,99€
  • HACKER LIBRARY THE LARGEST COLLECTION OF BOOKS AND MANUALS ON HACKING + 100 !!! 49,99€ 19,99€
  • HACK SOCIAL THE GUIDE TO HACK ALL THE SOCIAL ACCOUNTS 49,99€ 19,99€
  • HACKER PACK FOR YOUR SMARTPHONE AND YOUR TABLET WITH ROOT GUIDE AND + 100 PROGRAMS !!! 49,99€ 19,99€
  • THE FIRST TRUE ANDROID SMARTPHONE FOR HACKING UNIQUE IN THE WORLD WITH ALL THE APPS !!! 549,99€ 249,99€
  • HACKER PACK FOR YOUR COMPUTER AND NOTEBOOK + 1000 PROGRAMS 5 GB OF STUFF !!! 49,99€ 19,99€

Our customers say

Annabel M. – Systems Engineer

 
Samuel D. – Ethical Hacker

 
Karola M. – Influencer

 
Marcus P. – Private Investigator

 
Rosemary S. – Housewife

 
Amit V. – IT Consultant

 
Matthew C. – Entrepreneur

 
Aisha B. – Computer Science student

 
Li W. – IT Analyst

 
Robert C. – Programmer

 

DOWNLOADED 1316 TIMES!

DOWNLOADED 1316 TIMES!

Download now Hacker Secret our free Android app.

CONTACT US NOW FOR IMMEDIATE SUPPORT!

Contact Us
Write your email address here
Write here how we can help you - we support you immediately for all your needs!

## Are you looking for products for hacking, computer security and penetration testing? Do you need to clean up your smartphone, your PC or your site from viruses and malware? Do you need to track down someone or retrieve urgent information? Do you want to buy devices already configured to experiment all the hacking techniques quickly and easily? Do you have special needs in software or hardware? ##

Contact us now … another 2300 users like you have already done it this year!

Click here now!

 

Search on the site

Latest posts

  • How to tell if someone is stealing your wifi

  • How to check saved passwords on Chrome

  • The Computer Security Day

  • What is digital forensics

  • How to install Metasploit in Termux?

All the techniques, products and services described or contained on this site are intendend for exclusive use of study and professional training and to test the security of own's computer network in accordance with the national legislations on access to computer and online systems. All the services provided on this site (penetration testing, social accounts hardening, Incident Response & CSIRT, MSSP, Cybersecurity Consultancy, etc.) can be provided only with prior written and documented authorization from the owners or their legitimate representatives in accordance with current national regulations .

TOP