PoC video of How to Hack Gmail and Bitcoin Wallet using SS7 flaw
A long time ago we published a report about how someone can hack WhatsApp with the SS7 by default. The standard SS7 exists for eons now with corrections, but GSM and telecom companies do not bother or trouble to repair their infrastructure against the standard.
Now a Cyber Security Company called Positive Technologies has released a video detail as anyone in any Gmail account can hack with a name and a phone number with the standard SS7. After the abduction of the Gmail account of the victim, the investigators then tried to steal a Bitcoin wallet with the same SS7 defect. Positive researchers sent their video to Thomas Fox-Brewster, an investigating reporter for Forbes, as well as details about hacking.
What is the SS7 error?
The vulnerability is found in the signaling system 7 or SS7, the technology used by telecommunication operators where the high-security message system and telephone calls depend. SS7 is a set of telephone signaling protocols developed in 1975 that make it possible to configure and dismantle the majority of the telephone calls from the public switched telephone network (PSTN). It also performs number translation, local number portability, prepaid billing, short message service (SMS), and other mass market services.
SS7 is vulnerable to piracy and this is known since 2008. In 2014, the media reported on a susceptibility to the SS7 protocol, according to which government agencies and non-governmental actors can track the movements of mobile phone users from virtually anywhere in the world with a success rate of about 70%. In addition, it is possible to listen in secret with the protocol to send calls and also to facilitate the decryption by requiring the caller of each caller to release a temporary encryption key to unlock the communication after it has been recorded. The researchers have created a tool (SnoopSnitch) that can warn if certain SS7 attacks occur against a phone and recognize IMSI microphones.
How to attach Gmail with SS7 standard
In the PoC video, the researchers used a phone number to open the Gmail Google Mail service. Once the e-mail account has been identified, the investigators have sent a password request to the Gmail servers. According to the protocol, Gmail sent the unique authorization codes to the victim's phone. Positive technology researchers then used SS7 to intercept the SMS text that contained the OTP. Once they got the OTP, the Gmail account of the victim hacked and resetting the password was easy. They immediately chose a new password and took over the Gmail account.
With these details they went to the Coinbase website. Again, the same mode is used, that is, to reset another password with the e-mail I hacked. Coinbase also sent an OTP to the victim's smartphone, which was hacked by investigators with the same SS7 defect. Once they had access to the office of the prosecutor, they were able to reset the victim's bitcoin portfolio and access all bitcoins in the portfolio.
"This hack would work for any resource - real money or virtual currency - that uses SMS for password recovery," said positive researcher Dmitry Kurbatov at Forbes. "This is a vulnerability in mobile networks, which ultimately means that it is a problem for everyone, especially those who use the mobile network to send security codes."
Access to SS7 hackers has also been facilitated with easily accessible IMSI receivers. Kurbatow said Forbes that there are many dark websites like Interconnector that sell SS7 services. "The risk lies in the fact that cybercriminals can buy potentially illegal access to the obscure web," said Kurbatov.
Now a Cyber Security Company called Positive Technologies has released a video detail as anyone in any Gmail account can hack with a name and a phone number with the standard SS7. After the abduction of the Gmail account of the victim, the investigators then tried to steal a Bitcoin wallet with the same SS7 defect. Positive researchers sent their video to Thomas Fox-Brewster, an investigating reporter for Forbes, as well as details about hacking.
What is the SS7 error?
The vulnerability is found in the signaling system 7 or SS7, the technology used by telecommunication operators where the high-security message system and telephone calls depend. SS7 is a set of telephone signaling protocols developed in 1975 that make it possible to configure and dismantle the majority of the telephone calls from the public switched telephone network (PSTN). It also performs number translation, local number portability, prepaid billing, short message service (SMS), and other mass market services.
SS7 is vulnerable to piracy and this is known since 2008. In 2014, the media reported on a susceptibility to the SS7 protocol, according to which government agencies and non-governmental actors can track the movements of mobile phone users from virtually anywhere in the world with a success rate of about 70%. In addition, it is possible to listen in secret with the protocol to send calls and also to facilitate the decryption by requiring the caller of each caller to release a temporary encryption key to unlock the communication after it has been recorded. The researchers have created a tool (SnoopSnitch) that can warn if certain SS7 attacks occur against a phone and recognize IMSI microphones.
How to attach Gmail with SS7 standard
In the PoC video, the researchers used a phone number to open the Gmail Google Mail service. Once the e-mail account has been identified, the investigators have sent a password request to the Gmail servers. According to the protocol, Gmail sent the unique authorization codes to the victim's phone. Positive technology researchers then used SS7 to intercept the SMS text that contained the OTP. Once they got the OTP, the Gmail account of the victim hacked and resetting the password was easy. They immediately chose a new password and took over the Gmail account.
With these details they went to the Coinbase website. Again, the same mode is used, that is, to reset another password with the e-mail I hacked. Coinbase also sent an OTP to the victim's smartphone, which was hacked by investigators with the same SS7 defect. Once they had access to the office of the prosecutor, they were able to reset the victim's bitcoin portfolio and access all bitcoins in the portfolio.
"This hack would work for any resource - real money or virtual currency - that uses SMS for password recovery," said positive researcher Dmitry Kurbatov at Forbes. "This is a vulnerability in mobile networks, which ultimately means that it is a problem for everyone, especially those who use the mobile network to send security codes."
Access to SS7 hackers has also been facilitated with easily accessible IMSI receivers. Kurbatow said Forbes that there are many dark websites like Interconnector that sell SS7 services. "The risk lies in the fact that cybercriminals can buy potentially illegal access to the obscure web," said Kurbatov.
This comment has been removed by the author.
ReplyDeletei was lost with no hope for my wife was cheating and had always got away with it because i did not know how or always too scared to pin anything on her. with the help a friend IN PERSON OF PAIGE who recommended me to who help hack her phone, email, chat, sms and expose her for a cheater she is. I just want to say a big thank you to HACKINTECHNOLOGY@GMAIL.COM . am sure someone out there is looking for how to solve his relationship problems, you can also contact him for all sorts of hacking job..he is fast and reliable. you could also text +1 669 225 2253
ReplyDeleteThis comment has been removed by the author.
ReplyDeleteThis comment has been removed by the author.
ReplyDelete
ReplyDeleteHi everyone, I saw comments from people who had already got Blank ATM Cards from Mike Fisher. Honestly I thought it was a scam, and then I decided to make a request based on their recommendations. A few days ago, I confirmed in my door step to have received my blank card to withdraw 12,000 euros, which I requested for business. This is really good news and I am so happy that I advise all those who need a real HACKER should contact him and who are sure to reimburse to apply through their email (text or call) +1 315-329-6320 There are sincere Hackers
They are able to Delivered your Blank ATM Cards
Contact Mr Mike
E-mail: blankatm002@gmail.com
Telephone: +1(301) 329-5298
Are you in need of finance? we give out guarantee cash at 3% interest rate. Contact us on any kind of finance now: financialserviceoffer876@gmail.com whatsapp Number +918929509036 Dr James Eric Finance Pvt Ltd
ReplyDeleteAre you in need of finance? we give out guarantee cash at 3% interest rate. Contact us on any kind of finance now: financialserviceoffer876@gmail.com whatsapp Number +918929509036 Dr James Eric Finance Pvt Ltd
ReplyDeleteCredit Card Hack Software.
ReplyDeleteVery interesting article. Many articles I come across these days do not really provide anything that attracts others, but believe me the way you interact is literally awesome. I will instantly grab your rss feed to stay informed of any updates you make and as well take the advantage to share some latest news on Programmers ATM electronic
CREDIT CARD HACK SOFTWARE 5 magic ways of making money online that are used on ATM machine, online, Gas stations, POS, to withdraw money on daily basis from offshore anonymous account that can not be trace by any ATM system in any country as fraud. This system is widely used in the USA and Canada presently by musicians and street guys for making huge amount of money on daily basis buying luxurious cars, houses living an extravagant lifestyle. It was created by a group of RUSSIAN PROGRAMMERS and hackers base in the United States of America by cracking offshore accounts. l thought twice to bring these latest news to the public to be aware which many are not yet informed of these programmed ATM card hack software program.
Thank so much for allowing me to pass this news to enlighten the public on what is going on around the world through your superb platform .
You can call me Scott from Globex HI-Tech Programmer.
You can JOIN OUR Telegram Group …. https://t.me/hackersarena2021 for any new updates on Paperworks and Hacking services we provide. You can also share your own opinion regarding our services with other 5.8k Globex Documents members in this Telegram Group …. https://t.me/hackersarena2021
I really need to hack one of my friends facebook account because he dared me and said I couldn`t hack his account even if i tried pls i need someone to help me send to this gmail.account tomiemmanuelbabalola7@gmail.com
ReplyDeleteHello Everyone, to tell you the real truth, there are only a few hackers out there who know the dynamics about hacking, only a few of them are experienced and know how to hack anything. I have been very lucky to come across one of them whom I would describe as pretty good and very honest. He’ll do any of your hacking jobs ranging from phone hacks to social media hacks Bank hack bitcoin you name it. Contact him through his Email hack.truth77 at g mail . com make sure to let him know you got his contact here from me.
ReplyDeleteHello, I had 3 credit cards with great credit limits, Discover, Capital one and Chase -Amazon Prime. I had some missed payments and eventually got my cards maxed out, this affected my report; I read about this credit specialist known as Hack West Credit Repair, after due research and consultation I decided to employ his services, 6 days after he cleared my debts and raised my score to 796, that sounds like a magic right? Yea but he did and increased my credit card limits. I was able to get myself a home and also a new car with a very low interest rate. Thanks to HACKWEST @ WRITEME. COM. You can Whatsapp 424.307.2638
ReplyDeleteWe Facilitate Bank Guarantee (BG) & Standby Letter of Credit (SBLC)
ReplyDeleteInstrument Direct Mandate Provider of Fresh Cut Bank Instrument for
Lease/Purchase such as BG, SBLC,LC,DLC,EURO CLEAR.
Intermediaries/Consultants/Brokers are welcome to bring their clients
and are 100% protected We are direct to a provider for BG /SBLC Issuance
by HSBC London/Barclays London/Deutsche Bank Frankfurt. or any other AAA
rated Bank in Europe, Middle East or USA.
Our BG/SBLC Financing can help you get your project funded, loan
financing by providing you with yearly renewable leased bank
instruments. We work directly with issuing bank lease providers, For
further details contact us with the below information.
Name: Global Capital Asset
WHATSAPP +18506148697
E-mail: globalcapitalasset73@gmail.com
Do you need personal loan?
ReplyDeleteLoan for your home improvements,
Mortgage loan,
Debt consolidation loan,
Commercial loan,
Education loan,
Car loan,
Loan for assets.
ziploanfinance@protonmail.com
WhatsApp +91 8346 909 683
I wondered how I could boost my score after constantly getting ripped off by lenders, credit card companies and banks as a result of my low credit but TROVIAN CREDIT REPAIR came through, Am forever grateful. They turned my life around and now I can boast of having a home. They can get your credit report fixed and also increase your scores in less than 1 week, yes, I just said that!! Hit them up. Email: TROVIANCRDITREPAIR@GMAIL.COM / +1 (424) 307 4562
ReplyDeleteCyberz Phoenix is a Group of Multinational Hackers & Spammers. We make sure by all means necessary that our clients get the best of services on A PAYMENT.
ReplyDeleteRather than send money and trust a criminal to fulfill your deal. You'll get excellent customer service.
That's a 100% guarantee.
BEWARE OF FRAUDSTARS
if you have been a VICTIM,
Contact:
Telegram : @Cyberz_Phoenix
ICQ : @1001829652
WICKR : @cyberzphoenix for directives.
Here, it's always a win for you.
Without any Reasonable doubts, it is no news that Cyberz Phoennix offer one of the best services.
Amongst others, services we offer are listed as follows :
Fresh and valid USA SSN leads :
>> SSN+DOB
>> SSN+DOB+DL
>> Premium high score fullz (also included relative info)
TUTORIALS AVAILABLE FOR
SPAMMING
CARDING
CASHOUTS
MOBILE DEPOSITS
>APPLE PAY & ANDROID TAP CASH
>BANK TRANSFER
>HOW TO CASHOUT DUMPS+PINS
>MOBILE DEPOSIT
>SAFE SOCKS5 (USA)
>SMTP Linux Root
-->DUMPS+PINS
(How to use & create dumps with pins track 1 & 2)
>SERVER I.P's & proxies in bulk
>USA EMAILS Combo
>Fresh Leads for tax returns & w-2 form filling
>CC's with CVV's (vbv & non-vbv)
>USA Photo ID'S (Front & back)
>Payment mode BTC, ETH, LTC, & USDT
Contact:
Telegram : @Cyberz_Phoenix
ICQ : @1001829652
WICKR : @cyberzphoenix
ReplyDeleteCONTACT US FOR ALL KINDS OF HACKING JOBs @ We offer professional hacking services,we offer the following services;
-University grades changing
-Bank accounts hack
-Erase criminal records hack
-Facebook hack
-Twitters hack
-email accounts hack
-Grade Changes hack
Contact us on whatsapp + 1 681 532 3704
Email- n17833408@gmail.com
I just have to introduce this hacker that I have been working with him on getting my credit score been boosted across the Equifax, TransUnion and Experian report. He made a lot of good changes on my credit report by erasing all the past eviction, bad collections and DUI off my credit report history and also increased my FICO score above 876 across my three credit bureaus report you can contact him for all kind of hacks . Email him here support@wavedrive.tech go on their website wavedrive.tech for more details,Whatsapp No:+14106350697 if you want to chat them up,One thing i can assure you would not regret this at all he is 100% legit
ReplyDeleteWe Offer Swift MT760 BG/SBLC, FC MTN,Loan, Letter of Credit { LC }, MT103Etc.
ReplyDeleteN/B: Provider's Bank move first.
Let me know if you have any need for the above offers.
Thanks
Email: inquiry.trustedfinanceplc@gmail.com
Skype : inquiry.trustedfinance@gmail.com
Whatsapp: +16135085843
This comment has been removed by the author.
ReplyDeleteThis comment has been removed by the author.
ReplyDeleteI provide 100% working numbers for Whatsapp registration,
ReplyDeleteValid Passport/ID , Online banking login accounts,
100% working tracking numbers for all major companies, USPS, FedEx, UPS, DHL,for all countries.
Mobile: +1 (914) 278-7320
Mail: psoon043@gmail.com
Telegram: https://t.me/psoon