Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
当社は、ウェブサイトが正しく機能するために必要なブラウザCookieを使用しています。例えば、お客様がウェブサイトに再度アクセスした際に遵守できるよう、ウェブサイトデータ収集設定を保存しています。ブラウザの設定でこれらのCookieを無効にすることができますが、その場合、ウェブサイトが意図したとおりに機能しない可能性があります。
より関連性の高いブラウジング体験を提供したり、ウェブサイト上のコンテンツをパーソナライズするために、ユーザーの行動を理解するため。例えば、より関連性の高い情報を提供するために、どのページを訪問したかの情報を収集します。
当社のウェブサイトおよび他のウェブサイトでの広告をパーソナライズし、その効果を測定するため。例えば、当社のウェブサイトで訪問したページに基づいて、パーソナライズされた広告を表示する場合があります。