EvilZone

Hacking and Security => Hacking and Security => : Nortcele October 29, 2014, 02:54:16 PM

: Insecuriy of Facebook Security questions....
: Nortcele October 29, 2014, 02:54:16 PM
Okay so this is something I presume most of you know about but this does make me rather worried/entertained about how easy it can be to access someones Facebook account my simply changing the password...

So when you forget your facebook password you are usually give the option to receive an Email or a Cal/Text to confirm your identity.

But if you dont have access to these (if you have set up a security question) you can clikc 'No longer have access to these' and you can input your answer and voila you have confirmed your identity.

Now this is where its gets fairly insecure, If the question is simply 'What street did you live on when you were 8 years old?' Its not difficult to do a search to find a home address and this is similar to many of the questions, with basic Social Engineering you can have access fairly easily.

There is a 24 hour wait but this usually is no problem.

Any thoughts on how insecure social media is?

[Will add pictures as proof of concept if requested]
: Re: Insecuriy of Facebook Security questions....
: Killeramor October 29, 2014, 03:13:41 PM
As all the Jocks say, "Pics or it didn't happen."
: Re: Insecuriy of Facebook Security questions....
: Nortcele November 02, 2014, 04:31:59 PM
I can't find the pics I had, if you have a look online I'm sure you will find what I'm on about
: Re: Insecuriy of Facebook Security questions....
: lady__godiva November 03, 2014, 09:35:38 AM
What you are talking about is true. It's up to the user choosing an answer which isn't easy to guess. You are talking specifically about Facebook, but this is something that actually happens on most websites. More over i find interesting the most admins won't allow you (correctly) to bruteforce the login username/password, but will overlook how security question can be bruteforced instead.

So yea, security question relies too much on the user itself, which is a negative thing.
: Re: Insecuriy of Facebook Security questions....
: FinalFrontier November 03, 2014, 01:58:03 PM
Fuck the system, my favorite teacher isn't PieCat
: Re: Insecuriy of Facebook Security questions....
: HTH November 03, 2014, 09:15:29 PM
Honestly guys this is nothing new, major, groundbreaking, etc. This was considered a skiddy fast n dirty way to access an email/facebook/etc like... 6-7 years ago? It still works of course because people need a way to reset account info, can you imagine if every idiot who forgot their password had to call facebook/google/apple directly? But it only gets you access to old info, you dont learn the password, and worst of all, it leaves tracks EVERYWHERE.

[hypothetical]
I mean yes, when I needed to reset an iphone my sister had bought in her infinte wisdom from some random pawnshop... and it was still password protected and had its old phone number.

I did simply reset the password to the email, so i could reset the password for apple ID, then clean up my tracks as best I could, and trusted that it was some dumb hick who would just assume he forgot his password.
[/hypothetical]
BUT, I wouldn't consider it for anyone who had even half a brain.
: Re: Insecuriy of Facebook Security questions....
: silenthunder November 04, 2014, 06:54:39 AM
LOL "I'll add pics if you ask"......"nevermind can't find them"
: Re: Insecuriy of Facebook Security questions....
: proxx November 04, 2014, 07:37:49 AM
Junk thread, closed.