cyber edition:. it’s a saturday night, i’m sitting in my company wardroom, trying to find a way...

30
Cyber Edition:

Upload: emma-craig

Post on 16-Jan-2016

219 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Cyber Edition:

Page 2: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend …

alternately titled

Use Two Factor Authentication for the love of everything holy please and thank you have a fantastic day

Page 3: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 4: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

THIS IS WHAT I HAVE BEEN TRAINING FOR MY ENTIRE

NAVAL CAREER

Page 5: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

15 Minutes Later …Hack hack hack hack

Hack hack hack hack

Page 6: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 7: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Alright honestly, that was faster than I expected

Page 8: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 9: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 10: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Time to continue my attempts to find the fight

A few hours and a disappointing loss later…

Page 11: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

But then…

• I was like hey, I should try to get money from google for this

• So I turn off two factor auth, reset the security settings to where they were originally

• Go to replicate what I did before

Page 12: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 13: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 14: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 15: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 16: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

That sneaky sonofabi-

• In the three minutes since I turned off two factor and set the default email back to his old one, this guy had reset his password and deleted the account

• But alas… google makes things too easy– *clicks account recovery link

Page 17: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Enter whatever email you want

Page 18: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

So the last message my friends got was early today, so that first one’s easy.The first messages came last month, lets assume this is a burner created specifically for this purpose

Page 19: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Whattt?!?!? NO questions?Are you f*#&%ing kidding me?

Page 20: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 21: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Implications

• Burner accounts on gmail are vulnerable– The only method of authentication for a password

reset is when the account was created and when it last contacted you

– Their algorithm and all of those other complicated questions are ignored if you havent used an account enough to populate it with data• Leaves just a shitty time based authentication

» After breaking in I checked the account creation date, I was off by 2 months and Google still said it was fine.

Page 22: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 23: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 24: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 25: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend
Page 26: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

• Guessing that guy is as freaked out as humanly possible

• Girls don’t want to press charges but will if he continues

• For now he’s locked out permanently• But back to Google…

Page 27: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

• Sent el Goog a message detailing what I did and why that’s really bad for the good guys too

• Their response -

Page 28: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Hi,

Thanks for your note. Account recovery is a complex problem. On the one hand, it's important that people who forget their passwords are able to legitimately recover their accounts. This needs to be carefully balanced so attackers aren't able to exploit the system. There are many, many signals that are used in this process, some of which are difficult to properly assess in small scale testing. In this instance, we believe the account recovery process is working as intended. If you disagree, please attempt the account recovery process on our test account, [email protected]. If you are able to recover this account, please let us know. Otherwise, thanks for your report, and good luck on your future bug hunting!

Regards,Yousef

Page 29: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

Damnit google.

• No sweet sweet google bucks for me

• Moral of the story, 2 factor authenticate everything, burner emails on gmail are inherently vulnerable, and google thinks that’s okay

• That’s probably the end of this adventure unless I go to Ars, but yay cyber

Page 30: Cyber Edition:. It’s a Saturday night, I’m sitting in my company wardroom, trying to find a way to watch Mayweather/Manny when I get a text from a friend

• Pew pew pew pew