MaCyber ​​​​hutsotsi anobira nharembozha kuti vasvike kunhamba dzenhare dzevanyoreri

MaCyber ​​​​hutsotsi anobira nharembozha kuti vasvike kunhamba dzenhare dzevanyoreri
Remote desktops (RDP) chinhu chiri nyore kana iwe uchida kuita chimwe chinhu pakombuta yako, asi iwe hauna kugona kwemuviri kugara pamberi payo. Kana kana iwe uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge uchinge rwakakura Cloud mupi Cloud4Y inopa iyi sevhisi kumakambani mazhinji. Uye handina kukwanisa kufuratira nhau dzekuti matsotsi anoba SIM makadhi abva pakuita chiokomuhomwe kuvashandi vekambani yenharembozha kuenda pakushandisa RDP kuti vawane mukana kune dhatabhesi remukati reT-Mobile, AT&T uye Sprint.

MaCyber ​​fraudists (mumwe angazeza kuvadaidza kuti hackers) vari kuramba vachimanikidza vashandi venharembozha kuti vamhanye software inovabvumidza kupinda mudura remukati rekambani uye kuba nhamba dzenharembozha dzevanyoreri. Ongororo yakakosha ichangobva kuitwa nemagazini yepamhepo Motherboard yakabvumira vatori venhau kuti vataure kuti makambani matatu akarwiswa: T-Mobile, AT&T uye Sprint.

Uku ndiko kumukira chaiko mumunda wekubiwa kweSIM kadhi (inobiwa kuitira kuti mascammers ashandise nhamba dzenhare dzemunhu anenge abatwa kuti awane maemail, masocial network, cryptocurrency account, nezvimwewo). Kare, matsotsi aipa vashandi venharembozha chiokomuhomwe kuti vachinje maSIM makadhi kana kushandisa social engineering kukwezva ruzivo nekuita semutengi chaiye. Ikozvino ivo vanoita zvehutsinye uye nehutsinye, vachibira muIT masisitimu evashandisi uye vachiita hutsotsi hunodiwa ivo pachavo.

Chitsotsi chitsva ichi chakasimudzwa muna Ndira 2020 apo maseneta akati wandei eUS akabvunza Sachigaro weFederal Communications Commission Ajit Pai kuti sangano rake ranga richiitei kuchengetedza vatengi kubva mukurwiswa kuri kuramba kuchiitika. Icho chokwadi chekuti ichi hachisi chekuvhunduka chisina chinhu chinoratidzwa neazvino bhizinesi nezvekubiwa kwemamiriyoni makumi maviri nematatu emadhora kubva kuaccount ye crypto kuburikidza neSIM swapping. Anopomerwa ndiNicholas Truglia ane makore makumi maviri nemaviri, akaita mukurumbira muna 23 nekubudirira kubaya nharembozha dzevamwe vane mukurumbira muSilicon Valley.

«Vamwe vashandiwo zvavo nemamaneja avo havana chavanoziva uye havana ruzivo. Vanotipa mukana kune data rese uye isu tinotanga kuba", mumwe wevapambi vakabatanidzwa mukuba SIM makadhi akaudza magazini yepamhepo pamusana pekusazivikanwa.

Sei basa iri

Hackers vanoshandisa kugona kweRemote Desktop Protocol (RDP). RDP inobvumira mushandisi kudzora komputa kubva kune chero imwe nzvimbo. Sezvo mutemo, teknolojia iyi inoshandiswa kune zvinangwa zverugare. Semuenzaniso, kana rubatsiro rwehunyanzvi runobatsira kumisikidza komputa yemutengi. Kana kana uchishanda mune cloud infrastructure.

Asi vapambi vakatendawo kugona kwesoftware iyi. Chirongwa chacho chinotaridzika chiri nyore: mubiki, akavanzika semushandi wetsigiro yehunyanzvi, anofonera munhuwo zvake uye anomuudza kuti komputa yake yakabatwa nesoftware ine njodzi. Kugadzirisa dambudziko, munhu akabatwa anofanira kugonesa RDP uye orega mumiriri wevashandi vevatengi vemanyepo achipinda mumotokari yavo. Uye zvino inyaya ye tekinoroji. Anobiridzira anowana mukana wekuita chero chinodiwa nemoyo wake nekombuta. Uye kazhinji anoda kushanyira bhangi repamhepo uye kuba mari.

Zvinosekesa kuti scammers vakachinja pfungwa dzavo kubva kuvanhuwo zvavo kuenda kuvashandi venharembozha, vachivanyengetedza kuti vaise kana kumisa RDP, vobva vasevha kure kure hukuru hwezviri mukati medhatabhesi, vachiba maSIM makadhi evashandisi vega.

Chiitiko chakadaro chinogoneka, sezvo vamwe vashandi venharembozha vane kodzero ye "kutamisa" nhamba yefoni kubva kune imwe SIM kadhi kuenda kune imwe. Kana SIM card rikachinjwa, nhamba yemunhu anenge abatwa nemhosva inoendeswa kune SIM card inodzorwa neanobiridzira. Uye ipapo anogona kugamuchira akabatwa-mbiri-yechokwadi makodhi kana password reset mazano kuburikidza neSMS. T-Mobile inoshandisa chishandiso kuchinja nhamba yako QuickView, AT&T ine Opus.

Sekureva kwemumwe wevanyengeri avo vatapi venhau vakakwanisa kutaura navo, chirongwa cheRDP chakawana mukurumbira. Splashtop. Inoshanda nechero telecom opareta, asi inoshandiswa kazhinji kurwiswa paT-Mobile uye AT&T.

Vamiririri vevashandi havarambi ruzivo urwu. Saka, AT&T yakataura kuti vari kuziva nezvechirongwa ichi chekubira uye vatora matanho ekudzivirira zviitiko zvakafanana mune ramangwana. Vamiriri veT-Mobile uye Sprint vakasimbisawo kuti kambani inoziva nzira yekuba SIM makadhi kuburikidza neRDP, asi nekuda kwezvikonzero zvekuchengetedza havana kuburitsa matanho ekudzivirira akatorwa. Verizon haina kutaura nezve ruzivo urwu.

zvakawanikwa

Ndedzipi mhedziso dzinogona kutorwa kubva pane zviri kuitika, kana iwe usingashandisi mutauro unonyadzisa? Kune rumwe rutivi, zvakanaka kuti vashandisi vave vakangwara, sezvo matsotsi akachinja kune vashandi vekambani. Kune rumwe rutivi, hapachina kuchengetedzwa kwedata. PaHabré nedzimwe nzvimbo akapinda mukati zvinyorwa nezve zviito zvehutsotsi zvakaitwa kuburikidza nekutsiva SIM kadhi. Saka iyo inonyanya kushanda nzira yekuchengetedza data rako kuramba kuipa chero kupi. Maiwe, zvinenge zvisingaite kuita izvi.

Ndezvipi zvimwe zvaungaverenga pane blog? Cloud4Y

CRISPR-inodzivirira mavhairasi anovaka "pokugara" kuchengetedza genomes kubva kuDNA-inopinda enzymes.
Bhangi rakakundikana sei?
The Great Snowflake Theory
Indaneti pamabharumu
MaPentesters ari kumberi kwecybersecurity

Nyorera kune yedu teregiramu-chiteshi kuti usapotsa chinyorwa chinotevera! Isu tinonyora kwete kanopfuura kaviri pavhiki uye chete pabhizinesi.

Source: www.habr.com

Voeg