The 5 Factors of MFA and How Hackers Bypass Multi Factor Authentication


HELLO FRIENDS

WELCOME TO MY CYPHER LOG

   Hello guys, Today I have learned an important topic which is Multi factor authentication and Biometrics. I seriously thought that MFA can be 100% safe to prevent us being a victim of cyber attacks, yeah actually it's safe but attackers find their own way to get what they want, so let's see more about those attacks in this blog.

MULTI FACTOR AUTHENTICATION

     When we buy our phone there is an option to keep our data much more safe which is Multi factor authentication.
Actually multi factor authentication is keeping two or more factors to get logged into our account. There is another one too which is two step verification like typing passwords in two different types. Multi factor authentication is different from that here we need to have two security types like having a password and fingerprint.
So don't confuse between these two.


Ok let's see the 5 factors of multi factor authentication.

THE 5 FACTORS OF AUTHENTICATION

KNOWLEDGE

     Actually this is the basic one which we all have in every account and mobiles too.
Yeah you guessed right which is password or PIN. This comes under the Knowledge.

POSSESSION

    This factor is having  something to prove who you are, like if we ever forget our passwords and need to login to our account and there will be an option which is the code will send in an authenticator app and we can only access it If we have the mobile. Or take a smart card as an example.

INHERENCE

    In this we need to use our biometrics which are fingerprint or face ID or voice recognition too. We all have this on our mobile.

LOCATION

     It is mainly used in some confidential areas, it actually works if you are in the exact location where you really need to access that. It is called geofencing.
Let's take an example, you're a government investigator and you need to login to your professional account which has the confidential records of people and government, now there is a geofencing so you can only access it when the gps confirmed you're in the place where you need to be.

ACTION

    Action is nothing but doing some gesture or specific swipe pattern to get you in.
Now we are going to see about the most important part which is how attackers bypassing the MFA

BYPASS MFA

    As I said in the intro of this blog there are some ways the attackers use to get into our account even if we have MFA. Let's see about that.

MFA FATIGUE

      We can call it also as an prompt bombing.
We people can easily trigger if something happens continuously, that's the strategy attackers using here. This falls under social engineering we have already covered about this topic you can know more about that in our blog.
Attackers will trigger hundred of MFA push notifications on a random time and when we see that we have the urge to stop that in any way, by this there is a possibility of getting approval from us. This is how it works.

SIM SWAPPING

   The attacker socially engineers the victim's mobile carrier into transferring the victim's phone number to the new SIM card by this the attacker can get the SMS which the victim gets.

AiTM - Adversary in the middle

   Actually it will come under Phishing, I have also covered this topic in my past blog so you can check that out to know more about phishing.
The attacker creates a perfect fake login page of a legitimate site, and we are all always in an urge to login without checking anything, that is the vulnerability attacker is looking for. After we enter the password in that fake login page it would automatically redirect us to the legitimate site by which this attacker steals the live session cookie of the victim.


So that's it guys these are ways attackers can use to login to the account of victims. I hope you guys understood it well. Let's see in the next interesting topic and stay tuned... 

THANK YOU

Comments

Popular posts from this blog

Day 2: Understanding the CIA Triad, AAA

Cryptography Basics: Encryption Types & Hashing Explained

Cyber Security Day 4: Understanding Layered Security & Defence in Depth