HomeSecuritySS7: Vulnerable protocol unlocks Facebook accounts

SS7: Vulnerable protocol unlocks Facebook accounts

“How can I hack a Facebook account?” Many want to learn the answer to this question. There are many ways for someone to get into another person's account, but now researchers are demonstrating a new method by which anyone can access someone's account simply by knowing their mobile phone.

There are about 1 billion Facebook users at this moment, which is roughly one sixth of the world’s population. A large proportion of users have linked a phone number to their Facebook account, which makes them vulnerable to the SS7 protocol vulnerability.

hack facebook ss7 protocol

Through the SS7 network, hackers can get into your account via a relatively simple process, as long as they know how to use the vulnerability. It is important to note that SS7 has no relation to Facebook itself, as it is a protocol used by mobile phone companies, and its initials come from Signaling System Number 7.

So how do we hack and what can we do with this protocol? The SS7 flaw can be used in many ways ranging from monitoring calls to sending and receiving unauthorized SMS messages. But with the latest discovery, it can be used to steal social media accounts that have been linked to a phone number. Signaling System 7 is used by 800 telephony providers to carry internal information such as billing information, roaming options and more. The bad thing about SS7, however, is that it trusts all the messages it receives, without checking where they came from. Thus, hackers can trick their victims' devices, redirecting their messages to their own devices (the Hacker).

It was recently announced that applications such as WhatsApp and Telegram , which offer end-to-end encryption, can be hacked in the same way as they use their phone numbers to register new users, and Facebook is following suit.

The hackers must initially click the “Forgot password” option on the Facebook page. When they reach the next page, they must enter a valid email address or a phone number. At this point, exploiting the SS7 vulnerability, the hacker, after entering the victim's phone number, can see the One time passcode that arrives on the victim's device via SMS, and change the password.

Researchers report that this particular flaw can be exploited in all services that use phone numbers for password recovery purposes.

However, the following methods help users stay safe from this vulnerability:

  • Use 2FA systems that do not require SMS messages.
  • Do not disclose your phone number in your accounts.
  • Do not click on links you do not recognize.
  • Prefer services that do not use a phone number, but use end-to-end encryption.

Here is a video that shows how the vulnerability works

[su_dailymotion url=”https://www.dailymotion.com/video/x5762ig” quality=”1080″]

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS