Working Principle
Reading location beacons with the code to restore access to the target account
The main security vulnerability is the mechanism of password recovery via SMS. This method allows to intercept a data packet through the SS7 transmission protocol vulnerability and obtain the login and authorization password. To crack the password, DeviceLocator uses a certain sequence of actions leading to the identification of the phone number tied to the account. The software then initiates a password recovery procedure via a passcode with an access code and intercepts the sent message. Using the received code, the application passes authorization to the account on the virtual device.
| likelihood | severity | incidents | |
|---|---|---|---|
|
SIM swap
|
|
|
3.4k takeovers |
|
Phishing
|
|
|
8.7k reports |
|
Signal loss
|
|
|
2.1k incidents |
|
Location history
|
|
|
1.2k exposures |
|
Weak recovery
|
|
|
4.0k attempts |
|
Credential stuffing
|
|
|
2.8k compromises |
|
Malicious clients
|
|
|
1.5k downloads |
|
Social engineering
|
|
|
6.0k reports |
|
Metadata leakage
|
|
|
12k records |
|
Device compromise
|
|
|
420 incidents |
我们使用网站正常运行所必需的浏览器Cookie。例如,我们存储您的网站数据收集设置,以便在您返回我们的网站时遵守这些设置。您可以在浏览器设置中禁用这些Cookie,但如果这样做,网站可能无法按预期运行。
为了了解用户行为,以便为您提供更相关的浏览体验或个性化我们网站上的内容。例如,我们收集有关您访问哪些页面的信息,以帮助我们提供更相关的信息。
用于个性化和衡量我们网站和其他网站上广告的有效性。例如,我们可能会根据您在我们网站上访问的页面向您展示个性化广告。