Live data from Hacker News

How I Could Have Hacked Any Instagram Account

thezerohack.com

111–120 of 138 posts

Re: How I Could Have Hacked Any Instagram Account

#111

Earlier quoted context omitted.

the hijacking happens on the grey market because there is no reliable escrow agent and its already against the terms of service of IG you don't need this script to find the accounts, you would use it when you promised to buy or sell an account and hack the phone number based 2-factor to either assume control of the account without paying, or steal it back but if you did want to scale this up to stealing normal user's…

This isn't answering any of the questions I asked, except that you think "you won't get caught because nobody will take this seriously enough to investigate", which is true if nobody makes more than a couple thousand dollars doing this, but not true if someone manages to make, like, $100,000 doing it.

> but not true if someone manages to make, like, $100,000 doing it.

narrator: people make $100,000 doing it.

Your question? This one?

> How much are you going to pay for a script that lets you steal inactive Instagram accounts that you will then go on to sell on a grey market? You're

But this isn't what anybody is doing. Nobody is trying to do that. Nobody is lurking in the bushes for inactive accounts. People hijack ANY account they please, which usually has some nice level of attention on it. Assuming control of account properly leaves no trace of the account to the original owner. NOBODY would be able to distinguish a stolen account to a newly organically built meme account for sale. You nor an investigator would know if the current seller is the hacker too. Its impossible to answer your question for these reasons.

I'll try to answer it: I'd probably pay $500 because I don't really keep track of the dollar value of my cryptocurrency balances on Empire Market or Nightmare, since code and documents aren't illegal goods and Department of Justice has said time and time again that they aren't going after consumers even if my OPSEC was broken (I use Monero exclusively, not transparent cryptocurrencies like Bitcoin). I just kind of buy anything that looks somewhat interesting and somewhat exclusive. Otherwise I'd really just wonder why the code isn't on github already for me to just clone and move on.

Re: How I Could Have Hacked Any Instagram Account

#112

Earlier quoted context omitted.

This isn't answering any of the questions I asked, except that you think "you won't get caught because nobody will take this seriously enough to investigate", which is true if nobody makes more than a couple thousand dollars doing this, but not true if someone manages to make, like, $100,000 doing it.

> but not true if someone manages to make, like, $100,000 doing it. narrator: people make $100,000 doing it. Your question? This one? > How much are you going to pay for a script that lets you steal inactive Instagram accounts that you will then go on to sell on a grey market? You're But this isn't what anybody is doing. Nobody is trying to do that. Nobody is lurking in the bushes for inactive accounts. People hijack…

You'd pay $500 for it. Let's round that up to $1000, double what you said you'd pay for it. And: I'll buy that you could get that much for it! Now, this researcher got a $30k bounty from Facebook, so, to beat that on the black market, he'd have to sell a tool --- knowing full well what it'd be used for, and facing the daunting task of trying to talk a jury out of that obvious fact --- to thirty one people who will then do god knows what the fuck with it, all of which he will be an accomplice to.

This is a bad business plan. To see why, just Google "Marcus Hutchins".

Re: How I Could Have Hacked Any Instagram Account

#113
post #51

Earlier quoted context omitted.

He didn't really explain it, but I think what was going on is the rate limiting is done per account, and the race condition was a way to circumvent that. He has to make all the requests very quickly because the first thing all the requests are doing is determining if new requests for this account should be ignored. All the requests are received around the same time, they all make this check and decide they are valid…

I think you are dead on, yeah it’s the quick rate of large numbers of requests that avoid the per-account rate limiting. Curious how they resolved this— run all authentication requests for a given user serially and in a consolidated fashion at some point. Exclusive lock the relevant db record before checking the code and recording the failure?

Distributed rate limiting is hard. He could hit multiple front ends simultaneously before they have a chance to catchup to the correct counts.

Re: How I Could Have Hacked Any Instagram Account

#114
So a bit of a strongly worded title. I'm going to nitpick for a second.

First you need the device-id, second you need the code that will be sent via text.

The code sent via text is 6 digits meaning 10^6 == 1MM permutations. He shows how he can enumerate these using 1K IP's ultimately bruteforcing the reset code.

The Device ID is still not captured although I'm guessing they allow handwaving via a malicious app or something of that nature.

Credit where credit is due, he cleverly enumerates them concurrently across 1K IP's and earned his bonus.

Interested how they fixed it...guessing adding a random session guid in the url and maybe increasing entropy && length of the secret.

Re: How I Could Have Hacked Any Instagram Account

#115
post #98

Earlier quoted context omitted.

And? How much are you going to pay for a script that lets you steal inactive Instagram accounts that you will then go on to sell on a grey market? You're not going to do it yourself, because when (not if) it's discovered how this happened, there will be an investigation, and you'll get caught, lose all the money you "earned" in legal fees, and (bypassing a login screen is textbook , right-in-the-strike-zone CFAA) spe…

the hijacking happens on the grey market because there is no reliable escrow agent and its already against the terms of service of IG you don't need this script to find the accounts, you would use it when you promised to buy or sell an account and hack the phone number based 2-factor to either assume control of the account without paying, or steal it back but if you did want to scale this up to stealing normal user's…

This is true , the only way I've seen accounts recovered:

1) Higher a lawyer and threaten a lawsuit. 2) If you have the ID you can hire a hacker to get it back.

Re: How I Could Have Hacked Any Instagram Account

#117

Earlier quoted context omitted.

> but not true if someone manages to make, like, $100,000 doing it. narrator: people make $100,000 doing it. Your question? This one? > How much are you going to pay for a script that lets you steal inactive Instagram accounts that you will then go on to sell on a grey market? You're But this isn't what anybody is doing. Nobody is trying to do that. Nobody is lurking in the bushes for inactive accounts. People hijack…

You'd pay $500 for it. Let's round that up to $1000, double what you said you'd pay for it. And: I'll buy that you could get that much for it! Now, this researcher got a $30k bounty from Facebook, so, to beat that on the black market, he'd have to sell a tool --- knowing full well what it'd be used for, and facing the daunting task of trying to talk a jury out of that obvious fact --- to thirty one people who will th…

Marcus Hutchins took a plea deal so we'll never know. The first article on the Washington Post was about why the charges such as "conspiracy to violate the CFAA" are a stretch. With that in mind, there basically isn't someone to Google, and no case law. Are we even still talking about the now-patched brute force guessing of a 2-factor code, because now you're gearing up to dissect a legal review that will fail any equivalency and has no case law whatsoever. Classic internet discussion.

Now back to the practical reality: You wouldn't get caught selling it on darknet. You would just post in the forum and 31 people would buy it for $1,000 in a few days. Have you even used darknet? Have you ever used Monero? Have you ever done an obligatory cleaning of bitcoin just because you dont know what THEY did with it? You are trying to support your position so hard by making all of this stuff sound so unfeasible when its exactly what goes on every day.

You would sell it for a premium JUST BECAUSE the earliest clients will do "god knows what the fuck with it". That would be the literal sales pitch! Accomplice? Ehhh maaaaybe but not really a concern.

and even with all that, you're missing how much the customers would make. these are the ones incurring the most liability and they use clearnet and still wouldn't face real consequences.

you're missing how the exploiter would do it themselves before considering selling copies of it, which is what I was alluding to. the exploiter would already understand how to control and monetize instagram accounts and make several hundred thousand dollars, or millions over time. A 500k follower meme account with 3% engagement could make $1,000 per week from promos if you worked at it, and be sold for a revenue multiple. Take a bunch of those. Rinse, repeat.

you're inventing viable business plans trying to argue with me, its wild.

Re: How I Could Have Hacked Any Instagram Account

#118

$30,000 for that? >In a real attack scenario, the attacker needs 5000 IPs to hack an account. It sounds big but that’s actually easy if you use a cloud service provider like Amazon or Google. It would cost around 150 dollars to perform the complete attack of one million codes. no, it does not have nearly that many. I think they only have 100 or so. IPs are expensive. It would probably cost thousands of dollars to pul…

Rather than guessing, you can check yourself: https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges....

AWS has _millions and millions_ of IPv4 addresses and an unfathomably large amount of IPv6 addresses.

Re: How I Could Have Hacked Any Instagram Account

#120

Why do they not lock the account after n number of tries say 5? The user will need to use a different way to authenticate if they can't enter the correct code in 5 tries

There was a limit, but a race condition allowed the limit to be bypassed.
Post reply on HN