Authentication · Offensive security · 3 min read
Next-level strategies for 2FA authentication bypass
Two-factor authentication raises the cost of an attack. It does not remove it, and here is where it gives.
Two-factor authentication adds a second barrier, and it is a good one. It is not a wall. This article walks through the techniques that get past 2FA in practice, where each one comes from, and what a defender can do about it.
Social Engineering
Social engineering entails deceiving a target into disclosing sensitive information that may be used in a cyber attack. This attack approach is typically used when the attacker has already obtained a victim’s login and password and wants to bypass other authentication requirements.
Phishing is one of the most frequent social engineering strategies to gain authentication credentials. In a phishing attack, a cybercriminal pretends to be a reliable source. It deceives an email recipient into disclosing personal information or clicking a malicious link in the email, resulting in their account being hacked.
Consent Phishing
Many apps use OAuth to request limited access to account data. A third-party app can ask for a user’s Google calendar without ever seeing their password or gaining access to the rest of the account.
Hackers may pretend to be legal OAuth login pages and seek any degree of access from a user using a contemporary attack tactic known as consent phishing. The hacker can update any MFA verification if given this access, allowing for a complete account takeover.
Brute Force
Brute force still works against MFA when the second factor is short. A four-digit PIN has ten thousand possibilities, and without rate limiting an attacker exhausts that in minutes. The first factor may be a strong password; the second one undoes it.
If successful, the hacker has breached one authentication factor, bringing them closer to breaching the account.
Exploiting Generated Tokens
Many online sites use authentication tools like Microsoft Authenticator and Google Authenticator to produce temporary tokens that may be used as authentication factors.
These systems often provide users with a list of manual authentication codes as a backup to prevent account lockouts.
Suppose this list is printed or kept in an insecure digital area. In that case, the cybercriminal may get it via physical theft or by leveraging weak data security procedures to gain access to the victim’s account.
Session Hijacking
Session hijacking (cookie snatching) happens when a cybercriminal steals a user’s login session via a man-in-the-middle attack. Session cookies are necessary for the user experience of online services.
When a user connects to an online account, the session cookie stores the user’s login credentials and tracks their session activities. The cookie stays active until the user logs out.
Session hijacking is possible when a web server does not mark session cookies as secure. If users do not return cookies to the server over HTTPS, attackers may steal them and hijack the session, circumventing MFA.
SIM Hacking
SIM hacking is when a hacker gains unauthorized access to a victim’s SIM card and compromises their phone number. SIM switching, cloning, and SIM jacking are all common tactics.
With complete control over the victim’s phone number, the hacker may receive and intercept SMS-generated one-time passwords (OTPs) used as an authentication element during a hacking attempt.
In short
- Point 1
- Most 2FA bypasses never touch the second factor. They steal the session after it was satisfied.
- Point 2
- SMS-delivered OTPs inherit the security of the mobile carrier, which is not yours to control.
- Point 3
- Backup codes are a second password, and are usually stored like a shopping list.
- Point 4
- Consent phishing defeats MFA entirely by asking the user to authorise the attacker.