website statistics

Kevin Burke, a security expert, has been able to spot a security vulnerability on the website of Virgin Mobile USA which puts 6 millions accounts at risk.
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading...

Web security is a tricky thing and you have to take a lot of measures to secure your website, if you have one. Most prominent brands work diligently to keep their websites secure from any possible exploits. However, sadly this doesn’t seem to be the case with the site of Virgin Mobile USA.


Virgin Mobile USA

Virgin Mobile USA is, by no means, a small company. It boasts six million subscribers and is a prominent name in the US telecom industry. Kevin Burke, a security expert has now revealed that he has been able to find a very basic security vulnerability in Virgin Mobile’s website, a vulnerability which has put six million accounts of the subscribers at risk.

The vulnerability that Burke has found is that you can easily break into virtually anyone’s account using the website. All you need to know is the exact phone number. The password can’t be greater than six digits, a limit put by the official site when you sign up.

A well-known fact in the world of web security is that the smaller a password’s length is, the easier it is to guess. A 6-digit password means that there can only be 1 million password combinations for it. And to parse through a million possible passwords is a very easy task for even a basic programmer.

Burke says that using a Python code, he was able to test different password combinations and break into his own account using the Brute force technique. It is as simple as that and can be done to any of the six million Virgin Mobile USA accounts online.

Once you have broken into an account, you can read the entire log of SMS and calls, associate a different handset with that account, change the PIN, even purchase a new handset and change the mailing address. In brief, you are able to virtually screw up the life of the person who actually owns the account.

Burke wrote to Virgin Mobile USA, citing the vulnerability and asking them to take measures to resolve it. So far, the company hasn’t done anything whatsoever and so, Burke was forced to go public with this information.

Source: Kevin Burke

Buy Cheapest Related Product From Amazon.com


Can This Wearable Computer Make It To Our Wrists By 2020?

Ever Imagined A Digital Dinosaur? It’s Waiting In Kickstarter!
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On September 18, 2012(3 years, 9 months ago.)

You May Also Like:

What Do You Think?

Leave a Reply




Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.


Recent Search

Recent Tutorials

If you could not wait to installed the iOS 10 beta version on you iPhone and now struggling for the errors, then this tutorial is for you.
Siri might not understand the question you asked. But you can use Siri by editing the text that you asked & it will give an updated answer.
Perhaps, you are new Apple user and you might have no idea how to change name of your iPhone. Check out this tutorial to change the name.
Check out this tutorial to lock Android phone using PIN code, Password or Pattern. Following the easy steps, you can secure your smartphone.
If you could not figure out yet, how to save and send GIF from your iPhone, then this tutorial is just for you.
Google released 'Ambient Display' feature with Android 5.x Lollipop. Check the tutorial to know how to turn off Android’s Ambient Display .
Have you recently got your 3D Touch iPhone 6s and struggling to delete apps? Go through the tutorial to learn how to delete or move the apps.
Just read this tutorial by yourself and from now on, we will show you, how you can make your iOS device read text loudly for you.
If you're still struggling to take selfie on iPhone then check it out to know how to take photos from far using iPhone's headset as a remote.
Even if your iPhone is locked, people can reply from the lock screen. Check out, how to turn off the quick reply message from locked screen.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook