Security researchers from Positive Technologies show us how a Facebook account can be hacked. All you need to know is the user's phone number.
As demonstrated in the video below, attackers can exploit the social network's password recovery feature to make it send a one-time password via SMS to the user.
In a previous post, we reported how hackers managed to exploit mobile devices that use the global SS7 network.
Signaling System 7 (SS7) is a global network that connects all telephone carriers around the world to a single hub. The exploit exploits a known security flaw in SS7, which has proven relatively difficult to fix due to the way Signaling System 7 works.
Currently, Signaling System 7 is used by all cellular networks in the world, so the vulnerability affects all devices from every provider around the world.
The researchers were able to exploit vulnerabilities in the SS7 network and obtain details about the victim's mobile device. They then "register" the victim on a fake roaming network. This allows them to receive all calls and SMS intended for the victim, including the SMS we mentioned earlier that comes from Facebook.
With this code, attackers can easily gain access to the victim's Facebook account and kick them out with a simple password change.
Security researcher Karsten Nohl told Forbes that creating simple rules in the SS7 firewall would solve 90% of Signaling System 7 security issues
Your Facebook account won't be at risk from this attack by using two-factor authentication provided by the company. Once you add the security feature, the password recovery feature stops sending passwords via SMS.
Since this attack is possible due to the vulnerability of the SS7 system and not through Facebook, it is very likely that it could also work to breach other online services that use the same password recovery mechanism.
Watch the video
https://www.youtube.com/watch?v=wc72mmsR6bM
