Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
당사는 웹사이트가 제대로 작동하는 데 필요한 브라우저 쿠키를 사용합니다. 예를 들어, 귀하가 당사 웹사이트로 돌아올 경우 이를 준수할 수 있도록 웹사이트 데이터 수집 설정을 저장합니다. 브라우저 설정에서 이러한 쿠키를 비활성화할 수 있지만, 그렇게 하면 웹사이트가 의도한 대로 작동하지 않을 수 있습니다.
보다 관련성 높은 브라우징 경험을 제공하거나 웹사이트의 콘텐츠를 개인화하기 위해 사용자 행동을 이해하기 위함입니다. 예를 들어, 보다 관련성 높은 정보를 제공하기 위해 어떤 페이지를 방문했는지에 대한 정보를 수집합니다.
당사 웹사이트 및 다른 웹사이트에서 광고를 개인화하고 효과를 측정하기 위함입니다. 예를 들어, 당사 웹사이트에서 방문한 페이지를 기반으로 맞춤형 광고를 표시할 수 있습니다.