Instagram 最新的“漏洞”是我见过最无厘头的。
The newest Instagram “exploit” is the goofiest I've seen

原始链接: https://www.0xsid.com/blog/meta-account-takeover-fiasco

最近出现了一个令人担忧的简单漏洞,攻击者通过操控 Meta 的自动化支持 AI,成功劫持了包括奥巴马白宫账号在内的多个高知名度 Instagram 账号。 这次攻击只需获取目标用户名,并将 VPN 设置为受害者的地理位置即可。黑客通过谎称自己是账号所有者,诱骗 AI 将密码重置码发送到他们指定的电子邮箱。该过程完全绕过了双重身份验证(2FA),并允许攻击者更改账号凭据,从而有效地将合法所有者拒之门外。AI 的验证过程极易被欺骗,有时仅凭一张受害者的深度伪造视频或动态照片即可得手。 这一漏洞催生了一个黑市产业,攻击者在其中拍卖高价值账号。虽然据报道 Meta 已经修复了该漏洞,但此次事件凸显了一项重大的安全失误:一家万亿美元级别的公司竟然依赖未经核实的 AI 支持协议,将访问便利性置于基本的账号安全之上。数周以来,这种“零认证”密码重置方法在几乎没有任何监管的情况下运行,使得用户在面对一个盲目信任任何请求重置者的人工智能系统时,毫无防御能力。

Hacker News 上近期的一场讨论揭示了 Instagram AI 支持系统中的一个重大安全漏洞。用户反映,攻击者可以轻易通过操纵平台的 AI 客服来劫持账号。 攻击者通过冒充账号所有者并声称其原始电子邮箱已被盗,诱导 AI 将验证码发送至攻击者控制的任意邮箱地址。评论者对此感到震惊:Meta 在没有足够的各种人工监督或基础身份验证的情况下,竟授予了自动 AI 代理对用户账号的高权限操作权限。 用户普遍认为,这种“漏洞”体现了安全架构上的重大失误。许多人指出,允许大语言模型(LLM)绕过双重验证(2FA)并修改敏感的账号恢复设置,制造了一个巨大的漏洞,这实际上证明了账号恢复仍是身份验证中最薄弱的环节。批评人士还指出,Meta 用一个更加“天真”的 AI 取代人工客服极具讽刺意味,并形容这种情况十分“业余”,且令用户对其账号安全深感不安。
相关文章

原文

Yesterday, a slew of Instagram accounts, including some high profile ones like the Obama White House account, seemingly got hacked. I've seen my share of exploits and takeover techniques, but this is the most unserious, "almost too stupid to be true" of them all.

The Takeover Flow

  • Step 01: Faking the Location & Initiating Support
    All the attacker needs to kick this off is your account username. Then, they hop on a VPN or proxy close to your city so Instagram's security algorithms don't suspect a thing. (You can quite easily get this from your public profile or "About" section or a hundred other ways.) Once it looks like the request is coming from the correct region, they tell the Meta support AI that the account is hacked and ask it to send the verification codes to an arbitrary email address they control.

  • Step 02: That's It
    Really, that's it. The first proper zero auth password reset I've seen in production. There appears to be no additional check as to whether the email being given is actually something the user has used before. Once the AI sends the security code to the attacker's email, the attacker passes it right back to complete the verification. The platform hands over a fresh password reset link, granting full ownership to the attacker.

Instagram's AI may or may not ask the attacker for a video selfie to prove identity. It's not particularly discerning at the moment, so something as simple as an AI animated public photo from the target's feed has been widely reported to work.

2FA Doesn't Help

In case you're wondering, because the system treats this high-privilege recovery flow as a total account reset by the "true" owner, the original 2FA gets thoroughly bypassed in the process.

Existing sessions are revoked and the password changed with no email, text, or push notification. The actual owner can't initiate recovery because the email and phone numbers now map to the attacker. There's no human to escalate to, it's just you arguing with a chat hoping to take control back while praying they don't do it again.

And if you're part of the A/B tested accounts on which the AI support option is active, tough luck, you can't even turn it off.

Black Markets Galore

Multiple black market Telegram groups have sprung up offering "account takeover" services at steep rates and quick turnaround times. Considering short handles are worth hundreds of thousands to even millions of dollars, it's not a surprise, really.

Accounts have been flipped, like hey, or been used for propaganda, like obamawhitehouse or ocmssf, the account of the Chief Master Sergeant of the U.S. Space Force. `

Patched Now

All the Telegram groups have quieted down as Meta seems to have patched it already, but it appears this particular method was active for weeks, if not months.

The very fact that a $1.5 trillion company lacks robust guard rails and their support AI will just change anyone's linked email if you ask it nicely enough is so terrifying, if it weren't so funny.

联系我们 contact @ memedata.com