How Hackers Can Hack Your OTP (One Time Password) !!!

How Hackers Can Hack Your OTP (One Time Password) !!!

 

Let's take the example of PayPal for this. Assume you got a PayPal account and want to sign in. After entering your password, you receive an OTP for login on to your device. You enter the code and get access. (method)

 

What is OTP SMS, and how does it work?

A one-time Password (OTP) is a password that is valid for one time. OTP is a string of characters or numbers automatically generated to be used for one single login attempt. It can be sent to the user's phone via SMS.

 

Use cases of OTP are:-

OTP On Call: Voice-based OTP is a two-factor authentication tool that allowbusinessessses to facilitate miscall-based based OTP generation for their potential customers.

Transactional SMS:- Send Alerts, OTP, Notification, SMS within 10 seconds anywhere. Transactional routes can only be used for sending transactional SMS such as OTP's and alerts to your registered users.

Promotional SMS:- Send Alerts, OTP, Notification, SMS within 10 seconds anywhere configured by default for all new accounts; promoted SMS is generally used for sending any offers or promotions of new and existing customers.

Methods of delivering the OTP

 

Ok, Let's Back to the point now !!

Suppose Now, I'm a blackie, and I want your riches luring in your wallet. I do know your password, but I want to bypass the OTP checkpoint. I wish to intercept it off your phone and grab it. Here's what I can try:

 

Interception. If I use WireShark for sniffing your traffic, I'll get encrypted UDP packets sent to the PayPal server but will not get the SMS packets as it isn't connected to your network. Earlier, SS7 attacks allowed infiltrated hackers to even sniff SMPP (Simple Message Peer-to-Peer protocol) packets with SMS text in plain, but later got patched in modern OS releases. Sad.

 

SMS Forwarding. Sometimes, we unnoticeably press “Ok” to pop-ups on our screen when we're operating something. This can be dangerous, as I can send an SMS-forwarding request to your phone with a single pop-up. If you pressed “ok,” your SMSs will get redirected to me, and I can request the OTP on my own.

 

Spywares. These sneaky little bundles of spies can do the work for you. As soon as the victim requests an OTP, I'd get it simultaneously through the Spyware itself. Or I may request it on my own.

 

LDAP Request Smuggling. OTPs come to my phone by the Lightweight Directory Access Protocol (LDAP) server. If I find a way to get a Request Smuggling attack on PayPal, LDAP server, I can send bulk requests and steal legitimate requests and their corresponding codes. But hacking an Enterprise’s LDAP server isn't cake, of course.

 

SIM Cloning. If I'm obsessed with your wallet, I'll take more elevated steps of performing this attack. I'll call your ISP, impersonate your identity, reissue another SIM under your name, and then get the OTPs of your phone into mine.

 

If I'm rich enough, I can afford an IMSI Catcher or an RTL-SDR toto carry out the OTP's interceptionss rate, but I need to be close to your house to carry out anything of it in the end.

 

You see, I need to work hard as anything to get the OTP to access your account. Visualizing it might be easy, but implementing it is an attempt to break concrete from your hands.

 

Though, issuing payments over a cellular network is more preferred than WiFi. And giving your phone to someone random for a phone call is not preferred at all!

 

Thanks for Reading ...

Always be aware From this kind of 

Scams ... 

Enjoyed this article? Stay informed by joining our newsletter!

Comments
Potab - Sep 10, 2021, 6:38 AM - Add Reply

Great One 🖤🖤🖤

You must be logged in to post a comment.

You must be logged in to post a comment.

About Author