• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Oppo Find N5 review: Stellar foldable has one big problem

July 30, 2025

The Naked Gun review: Charged with man’s laughter

July 30, 2025

Samsung Galaxy Tab S10 FE+ review: A Galaxy Tab S10+ for less?

July 30, 2025
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Security»Meta’s Account Center came with a 2FA-defeating bug
Security

Meta’s Account Center came with a 2FA-defeating bug

February 2, 2023No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Meta’s Account Center came with a 2FA-defeating bug
Share
Facebook Twitter LinkedIn Pinterest Email

Meta’s Accounts Middle characteristic had a bug that allow hackers brute drive SMS two-factor authentication, permitting them to bypass the extra safety (via TechCrunch). The vulnerability, which Meta says it fixed in December, was reported by Nepalese safety researcher Gtm Mänôz, who detailed the exploit in a Medium post earlier this month.

It was a big discover, as Meta appears to be placing an increasing number of give attention to its Accounts Middle characteristic, letting you handle settings and safety data from it, in addition to use it to modify to your different accounts. In accordance with Mänôz, the assault was comparatively easy; should you knew the cellphone quantity the opposite particular person used for two-factor authentication, you may hyperlink it to your individual account, which might take away it from the sufferer’s.

The factor that’s supposed to stop this can be a six-digit authentication code that will get despatched to the opposite particular person’s account or cellphone quantity, which you don’t have entry to. (For those who did, you wouldn’t want an exploit.) The bug Mänôz discovered, nevertheless, let an attacker guess that code nevertheless many occasions they wished — set a program or script to try this job, and it will ultimately guess proper.

Within the worst-case state of affairs (the strategy had completely different results based mostly on whether or not the particular person had totally or partially confirmed their contact information), this is able to completely flip off 2FA on the sufferer’s account. The truth that it was operating by Account Middle additionally defeated another safety measures; based on Mänôz’s submit, Fb wouldn’t normally allow you to add an already-registered e mail handle to your account, however this methodology bypassed that.

See also  If you want to use a security key with your Apple account, you’ll need two keys

Meta appears to have mounted the difficulty comparatively rapidly. Mänôz reported it on September 14th, 2022, and it was handled by mid-October after the corporate’s safety staff really found out find out how to check it. (In accordance with Mänôz, the Accounts Middle hadn’t rolled out for the staff’s accounts, and it disappeared from Mänôz’s account after he gave them the credentials so they may check with it.) Meta ended up paying Mänôz a $27,200 bug bounty for reporting the difficulty. Meta wouldn’t present an on-the-record assertion concerning the bug’s affect, however spokesperson Gabby Curtis told TechCrunch that it was caught throughout a small public check, and that there didn’t seem like proof that it was exploited earlier than being mounted.

Correction January thirtieth, 3:50 PM ET: A earlier model of this text acknowledged the bug affected email-based two-factor authentication, however Meta spokesperson Gabby Curtis says it solely impacted SMS-based 2FA. We remorse the error.

Replace January thirtieth, 3:50 PM ET: Up to date to notice the bug doesn’t seem to have been exploited.

Source link

2FAdefeating account bug Center Metas
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Master These New iPhone Control Center Features in iOS 18.5

May 30, 2025

Secure Your iCloud Account After Big Password Leak

May 22, 2025

Gemini app on iPhone adds Control Center, lockscreen widgets

March 3, 2025

Bug in macOS and iOS updates re-enables Apple Intelligence for some refuseniks

February 11, 2025
Add A Comment

Comments are closed.

Editors Picks

Credas appoint Geraint Rogers from Equifax as chief strategy officer

August 12, 2022

Teslagrad 2 is finally launching in spring 2023

August 25, 2022

Proxtera launches beta version of multi-currency exchange platform

November 2, 2022

New York City Bans TikTok on All City-Owned Devices

August 17, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Oppo Find N5 review: Stellar foldable has one big problem

The Naked Gun review: Charged with man’s laughter

Samsung Galaxy Tab S10 FE+ review: A Galaxy Tab S10+ for less?

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.