Seguridad en Instagram: Posibles hackeos y medidas de prevención

  • Autor Autor jordan232323
  • Fecha de inicio Fecha de inicio
jordan232323

jordan232323

VIP
Kappa
Diseñador
Social Media
Verificación en dos pasos activada
Verificado por Binance
Suscripción a IA
Buenas me ha pasado con dos cuentas que me pertenecen, de la nada alguien les cambia el correo, contraseña, les pone una foto de anonymous, y le escribe DOPE


88212713_503052173745042_5628384165566087168_n.webp

e podido recuperar ambas cuentas porque tenia acceso a los correos con las que las cree, alguien tiene idea de que puede estar pasando?
 
Puede que hayas compartido tu contraseña con páginas de terceros
 
Aplicaciones que hayas bajado y que piden contraseñas
 
Revisar las aplicaciones que descargas algunas pueden ser key-logger
 
A mí lo que me pasa a veces es que empieza a seguir usuarios desconocidos. Tenía una cuenta que seguía a 3 usuarios y estuvo inactiva por 6 meses. Cuando fui a ver el perfil ya seguia a 10 usuarios... 😅
 
A mí lo que me pasa a veces es que empieza a seguir usuarios desconocidos. Tenía una cuenta que seguía a 3 usuarios y estuvo inactiva por 6 meses. Cuando fui a ver el perfil ya seguia a 10 usuarios... 😅

eso tambien me ha pasado
 
ojo con esto, da igual que tengas 2FA. El Evilginx(entre muchos otros) tiene para instagram. Configurarlo es medio complicado, pero una vez que lo tienes...


Phishing 2.0
Phishing 2.0 makes all of these mitigations obsolete. Phishing 2.0 is a far more sophisticated, far more evil attack.

evilginx

Image source: https://breakdev.org/evilginx-2-next-generation-of-phishing-2fa-tokens/
Phishing 2.0 uses a transparent reverse proxy to mount a man-in-the-middle (MITM) attack against all users in the same network segment. Its ultimate goal is not to capture usernames and passwords – those are just collateral – but the keys to the kingdom: the user’s session token.

While MITM attacks are nothing new (Citibank was attacked way back in 2006!), lately highly automated ‘script-kiddie level’ tools, such as Evilginx2 and Modlishka, have become publicly available. I must admit that I’m quite impressed by the hard work and the technical accomplishments behind the previous sentence. In order for Phishing 2.0 to work, the tools need to intimately integrate with the target site(s) and therefore utilise deep, complex URL rewriting techniques in HTML content and JavaScript – and all in real time!

In Phishing 2.0, instead of a fake page created by the attacker, the victim sees the real and unaltered PayPal page in their browser – only that the page is served by a transparent proxy decrypting and re-encrypting all data in real time. As the tools will automatically acquire a valid TLS certificate, the URL bar will have the padlock icon, but still needs a fake domain like ‘paybal.com’.

In order to direct traffic to the proxy, the attacker sets up a reverse proxy on the same network, and routes all traffic through it via traditional ARP poisoning etc. While Phishing 2.0 sounds quite hard to mount properly, the current tools hide the technical challenges in a way that most UI designers would be proud of.

To reiterate, using contemporary toolkits, the technically demanding Phishing 2.0 becomes Phishing for Dummies. There is no need to hand craft real-looking sites and e-mails. Script-kiddie level automated tools are freely available and, to top it all, shared, untrusted networks are increasingly common (WLAN).

Once set up, the Phishing 2.0 proxy will transparently intercept passwords, 2FA access tokens and session tokens. The impact is tremendous. The user doesn’t need to click on any links to end up at the fake site. The phishing site is no longer a copy – it is the real site, just accessed through a relay. There is no natural protection from using exotic languages like Finnish, so relying on the ‘spot the sketchy Google-translated sites’ offers no protection. As the site looks absolutely identical and shows the padlock on the address bar, it gives the victim a false sense of security.

SMS OTP, mobile authenticators, everything that the user puts in is intercepted by the attacker and stored for future use.
 
Hay programas que permiten espiar instagram Tal vez te convertiste en la víctima de uno de ellos.
 
Atrás
Arriba