Kevin Burke, a security expert, has been able to spot a security vulnerability on the website of Virgin Mobile USA which puts 6 millions accounts at risk.
TTJ Poll

After Note 7 Disaster what are your thoughts on Samsung Mobile?

View Results

Loading ... Loading ...
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)

Web security is a tricky thing and you have to take a lot of measures to secure your website, if you have one. Most prominent brands work diligently to keep their websites secure from any possible exploits. However, sadly this doesn’t seem to be the case with the site of Virgin Mobile USA.

Virgin Mobile USA

Virgin Mobile USA is, by no means, a small company. It boasts six million subscribers and is a prominent name in the US telecom industry. Kevin Burke, a security expert has now revealed that he has been able to find a very basic security vulnerability in Virgin Mobile’s website, a vulnerability which has put six million accounts of the subscribers at risk.

The vulnerability that Burke has found is that you can easily break into virtually anyone’s account using the website. All you need to know is the exact phone number. The password can’t be greater than six digits, a limit put by the official site when you sign up.

A well-known fact in the world of web security is that the smaller a password’s length is, the easier it is to guess. A 6-digit password means that there can only be 1 million password combinations for it. And to parse through a million possible passwords is a very easy task for even a basic programmer.

Burke says that using a Python code, he was able to test different password combinations and break into his own account using the Brute force technique. It is as simple as that and can be done to any of the six million Virgin Mobile USA accounts online.

Once you have broken into an account, you can read the entire log of SMS and calls, associate a different handset with that account, change the PIN, even purchase a new handset and change the mailing address. In brief, you are able to virtually screw up the life of the person who actually owns the account.

Burke wrote to Virgin Mobile USA, citing the vulnerability and asking them to take measures to resolve it. So far, the company hasn’t done anything whatsoever and so, Burke was forced to go public with this information.

Source: Kevin Burke

Buy Cheapest Related Product From

Can This Wearable Computer Make It To Our Wrists By 2020?

Ever Imagined A Digital Dinosaur? It’s Waiting In Kickstarter!
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On September 18, 2012(4 years, 1 month ago.)

You May Also Like:

What Do You Think?

Leave a Reply

Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.

Recent Search

Recent Tutorials

There is a high-risk XSS Vulnerability in W3 Total Cache, and we have got the guide to the fix for you.
Check out this tutorial to know how to install Apple watchOS 3 beta certificate on your Apple Watch and start enjoying the new version.
If you are trying to jailbreak iPhone, iPad or iPod on iOS 9.2 - 9.3.3 without using a computer or Apple ID, then check this video tutorial.
Pokemon Go users are complaining about the crashing and server issues. Check out the tutorial to solve error problems and thanks us later.
Turning off Wi-Fi Assist is a great way to save mobile data since it automatically starts using cellular data when Wi-Fi signal is poor .
If you want to secure your SIM card from others using it, then check out this tutorial to know how to set up the SIM Pin code on your iPhone.
CiderTV is a great alternative to control Apple TV from the Notification Center. Check out this tutorial to set up CiderTV on your iPhone.
Are you annoyed by the split screen mode on the iPhone 6 Plus or 6s Plus? Check out this quick tutorial to turn off split screen feature.
If you could not wait to installed the iOS 10 beta version on you iPhone and now struggling for the errors, then this tutorial is for you.
Siri might not understand the question you asked. But you can use Siri by editing the text that you asked & it will give an updated answer.
Close You Have To Login
Login With »Login With TwitterLogin With Facebook