How I Could Have Hacked Any Instagram Account
thezerohack.com
thezerohack.com
Also if I am reading it correctly, it sounds like the rate limiting was being done per-IP, which sounds strange. Why wouldn't Instagram just allow a fixed number of tries (some low limit, like 25) from any IP before invalidating the code? I don't really see a scenario where it makes sense to have per-IP rate limiting here. I guess they are probably just using the rate limiting features which are built in to whatever framework Instagram is using for their API.
It's still better than using the same number as you use for everything else, but it's important to understand the caveats.
"Google 2FA" is TOTP, an open standard, not a Google produced solution.
Seems to me that the main mistake was not rate limiting per account right? If you get 200k password requests for a single user something is severely wrong.
Or maybe they did and it didn't work, he makes reference to a race condition in the original post but doesn't elaborate.
The rate limiting for IPs is probably global (not related to the reset endpoint).
This could makes it very easy to perform a DOS attack against a user. You could constantly send failed attempts and make it impossible for the user to type in the real code before you invalidate it.
Not that mobile phone 2FA is actually secure. Fraudsters in the UK have discovered that it's possible to take over phone numbers rather easily because that relies on the phone companies' own systems which are (predictably) insecure.
SMS is old-school. That thing is going via the tower or it’s not going at all.
(This is just a hunch. Happy to be told I’m wrong!)
(IIRC, the 3G and LTE versions of the tunnel carry traffic at different layers of the protocol stack, but in both cases being able to handle SMS and similar non-Internet features is part of the goal. As is being able to handoff between wifi and cellular transports in the middle of a call — I have no idea how well that works in practice.)
If 2FA decides to kick in then, your account is effectively dead with most companies until you regain access to your old phone number.
"Hi I have a new SIM card, can you please activate it?
— Sure what's your number and IMSI?
— My number is ..., the IMSI is ...
— OK done"
And so, just like that, I took over someone else's phone number. Not on purpose, but the guy made a mistake punching in my number, didn't verify my identity, and ended up assigning someone else's phone number to my SIM card. I called the guy back after realizing that I wasn't getting calls and that the people I called thought I now had a new number.
Granted it was a while ago but the experience gave me a very low opinion of SMS for 2FA.
It's like every account on Instagram has an alternative six digit password.
Numeric values solve that problem.
edit: drunk typing
You can easily set up a launch configuration for EC2 that runs a script or program... But with a bit more work lambda will save a lot of money
That depends on your orchestration. AWS provide several tools for running Docker without having to maintain your own EC2 hosts.
> You can easily set up a launch configuration for EC2 that runs a script or program... But with a bit more work lambda will save a lot of money
You could do that via a launch configuration but that would be a pretty naff way of doing it. Baked AMI would be easier but personally I'd prefer ECS (Docker) or lambda. Cheaper, quicker to deploy, lower ramp up times.
Ultimately though, there's no wrong way to do this - just personal preference.
personally i would spin up a million lambda functions and just see what happens. each one def wouldn't get its own ip but maybe you would have good coverage?
Yep - my reason is normally "I'm planning a project that needs more instances"
I doubt they even look at that field to be honest
Re Amazon, I've done that too and the way it works is you start up an EC2 instance that does the work and sends back info. In my case I sent the info to an S3 bucket and then pulled all the info from that bucket elsewhere once all the machines finished. Ultimately you pay for what you use, and if you only use an hour across a ton of machines and use the cheapest machine it's pretty cheap.
FYI: luminati will give you unlimited bandwidth for like $1/IP/month.
I always find it weird that if I accidentally enter the wrong code, I get to try again instead of being sent a new one.
Beyond that, definitely should regenerate / resend. This is to confirm you own that phone number. It's not hard to get another
> I have used 1000 different machines (to achieve concurrency easily) and IPs to send 200k requests (that’s 20 percent of total one million probability) in my tests.
I'm just surprised nobody looked at a dashboard and said "huh this account is getting 200k requests", surely that should be raising red flags?
Sure IG gets 1000's+ requests a second, but they shouldn't be getting 1000's+ requests per second per user - especially on a login route.
I monitor 400 requests on our website - A massive spike in those would warrant investigation.
I think my bank uses letter is text-based 2FA.
It’s surprisingly cheap to get access to services which fan out your requests over millions of normal residential IPs, making them (I assume) hard to block.
Of course their use can be highly objectionable, as well as how they got the proxies installed in homes of people in the first place (semi-malware?)
This is a euphemism right? Like what they're really saying is that this service would make it possible to fake ad traffic right?
> Hackers and fraudsters use various schemes to fake ad traffic and, as a result, a vast number of ads are never seen by real people. Therefore, more and more companies use proxies to detect fraud, improve ad performance, and check advertisers’ landing pages anonymously.
They claim 30M residential IP addresses.. How would this be done otherwise?
There's no info on the site about "signing up" to be a proxy, just about using them..
> When these application vendors integrate the Luminati SDK, their users are offered the alternative to not watch these video ads in return for opting in to the Luminati network.
I would be interested in starting to try some of these programs, but a bit scared I'd be doing something illegal... Where is the line?
First you need the device-id, second you need the code that will be sent via text.
The code sent via text is 6 digits meaning 10^6 == 1MM permutations. He shows how he can enumerate these using 1K IP's ultimately bruteforcing the reset code.
The Device ID is still not captured although I'm guessing they allow handwaving via a malicious app or something of that nature.
Credit where credit is due, he cleverly enumerates them concurrently across 1K IP's and earned his bonus.
Interested how they fixed it...guessing adding a random session guid in the url and maybe increasing entropy && length of the secret.
Instagram had a limit on the number of times that the user could guess the code, but they had a race condition that let the limit be bypassed. The fix is for them to fix the race condition.
A 0day RAT for android was hitting about 500 devs per second before getting fixed.
You can simulate that by running a loop that generates a random 4-digit number in each iteration and randomly guessing it.
On average, you will guess the number after 10,000 iterations. It doesn't help that you regenerate the number each time. Your chance is still 1/10,000.
https://code.fb.com/production-engineering/legacy-support-on...
The user will need to use a different way to authenticate if they can't enter the correct code in 5 tries
[Obvisouly, there are ways just easy to screw up]
Facebook should know better.
I take my hat of for you mister (or miss) mod :)
should be
"Because the market has decided that hacking top tier instagram accounts is worth a low seven figures, here is your $1,000,000 payout to save you the time, effort and liability of monetizing this yourself"
accounts are basically worth an additional $100 for every 5,000 followers, multiplied by engagement percent. ie. 1% engagement account with 5,000 followers would be worth around $100, 2% with 5,000 followers worth around $200. forget accounts with high heat (A and B-list celebrities), people flip meme and inspirational accounts ALL DAY. (this a simplistic scale from how I've seen the opening bids be set, and the negotiations I've had).
when when you aren't flipping and suddenly rebranding accounts, you get ROI by doing promos which have a fairly fixed cost. $10 to post about someone else or tag them in a story. the better your account is, the more you can charge and the less time you have to show someone. with stories you can stack promos all day and break even on an account in a week.
you get ROI to break even very quick.
(a hacker or phish may try other things like scamming D-list model's thirsty followers in Direct Messages.)
> maybe you could make a few hundred dollars promoting some crpyto thing
false. you'll get 2% of the entire currency pre-mined and minted straight to you, 3% of the funds raised, and upfront fees in the low five figures.
and if the crypto is post-launch, you'll get upfront fees, a lot less tokens, and then the hundreds of thousands you'll make pumping it if people bite. otherwise, you have to buy yourself and hope you can pump it, and if you are poor thats the only way you'll wind up with "just a few hundred dollars promoting some crypto thing"
yeah leave this to the pros and imagine people are still just buying fake followers or something relevant half a decade ago.
honestly, I feel like Facebook should be acting as an escrow agent and taking a cut of the promos and account sales. Would be safer for participants and lucrative for FB.
you don't need this script to find the accounts, you would use it when you promised to buy or sell an account and hack the phone number based 2-factor
to either assume control of the account without paying, or steal it back
but if you did want to scale this up to stealing normal user's accounts, stealing instagram accounts is merely a factor of changing the email address twice and then the account name. after which the original owner knows their account got stolen but has no record of the account lol, because they don't know the account ID, just the old username and email address which is super gone and doesn't match any record. you won't get caught primarily because there are too many barriers of entry for someone to take it seriously enough to investigate.
narrator: people make $100,000 doing it.
Your question? This one?
> How much are you going to pay for a script that lets you steal inactive Instagram accounts that you will then go on to sell on a grey market? You're
But this isn't what anybody is doing. Nobody is trying to do that. Nobody is lurking in the bushes for inactive accounts. People hijack ANY account they please, which usually has some nice level of attention on it. Assuming control of account properly leaves no trace of the account to the original owner. NOBODY would be able to distinguish a stolen account to a newly organically built meme account for sale. You nor an investigator would know if the current seller is the hacker too. Its impossible to answer your question for these reasons.
I'll try to answer it: I'd probably pay $500 because I don't really keep track of the dollar value of my cryptocurrency balances on Empire Market or Nightmare, since code and documents aren't illegal goods and Department of Justice has said time and time again that they aren't going after consumers even if my OPSEC was broken (I use Monero exclusively, not transparent cryptocurrencies like Bitcoin). I just kind of buy anything that looks somewhat interesting and somewhat exclusive. Otherwise I'd really just wonder why the code isn't on github already for me to just clone and move on.
This is a bad business plan. To see why, just Google "Marcus Hutchins".
Now back to the practical reality: You wouldn't get caught selling it on darknet. You would just post in the forum and 31 people would buy it for $1,000 in a few days. Have you even used darknet? Have you ever used Monero? Have you ever done an obligatory cleaning of bitcoin just because you dont know what THEY did with it? You are trying to support your position so hard by making all of this stuff sound so unfeasible when its exactly what goes on every day.
You would sell it for a premium JUST BECAUSE the earliest clients will do "god knows what the fuck with it". That would be the literal sales pitch! Accomplice? Ehhh maaaaybe but not really a concern.
and even with all that, you're missing how much the customers would make. these are the ones incurring the most liability and they use clearnet and still wouldn't face real consequences.
you're missing how the exploiter would do it themselves before considering selling copies of it, which is what I was alluding to. the exploiter would already understand how to control and monetize instagram accounts and make several hundred thousand dollars, or millions over time. A 500k follower meme account with 3% engagement could make $1,000 per week from promos if you worked at it, and be sold for a revenue multiple. Take a bunch of those. Rinse, repeat.
you're inventing viable business plans trying to argue with me, its wild.
1) Higher a lawyer and threaten a lawsuit. 2) If you have the ID you can hire a hacker to get it back.
Its lazy to derail a discussion with “I didnt see it so SOURCE! Ha Im so right about everything your whole argument is invalid”
instead of
“oh thats a problem what can we do about that” especially when unsubstantiated nonsense isn't really a big problem here, while completely misunderstanding problems and solutions is what this forum gets laughed at about
Also it wouldn't be temporary access lol. When you take over an instagram account you change the email address and the username twice, the person you took it from gets the alert email for the first change, the second email gets the alert for the second change to the third email address. The original owner doesn't know what/where the account is anymore.
It's temporary access because you can trivially write a tool that goes through Facebook's audit logs to find out which accounts have likely been taken over using this tool, which is something Facebook would certainly do if there was evidence that people had been exploiting it at any kind of scale.
A big chunk of my last year has been in ATO detection and mitigation and I think you'd be surprised what kind of dumb stuff generates serious investigations from companies with far fewer security team resources than Facebook.
>In a real attack scenario, the attacker needs 5000 IPs to hack an account. It sounds big but that’s actually easy if you use a cloud service provider like Amazon or Google. It would cost around 150 dollars to perform the complete attack of one million codes.
no, it does not have nearly that many. I think they only have 100 or so. IPs are expensive. It would probably cost thousands of dollars to pull this off.
No, that is wrong. AWS has millions.
> IPs are expensive. It would probably cost thousands of dollars
Not if you rent them for 10 minutes each, not.
AWS has _millions and millions_ of IPv4 addresses and an unfathomably large amount of IPv6 addresses.