Šta je novo?

Team Viewer hakovan! (click bait, al' istina izgleda)

dzonihsv

Čuven
Učlanjen(a)
18.11.2007
Poruke
7,145
Poena
725
http://www.theregister.co.uk/2016/06/01/teamviewer_mass_breach_report/
https://www.reddit.com/r/technology/comments/4m7ay6/teamviewer_has_been_hacked_they_are_denying

Citati...

Updated TeamViewer users say their computers were hijacked and bank accounts emptied all while the software company's systems mysteriously fell offline. TeamViewer denies it has been hacked.

In the past 24 hours, we've seen a spike in complaints from people who say their PCs, Macs and servers were taken over via the widely used remote-control tool on their machines. Even users with strong passwords and two-factor authentication enabled on their TeamViewer accounts say they were hit.

It appears miscreants gained control of victims' TeamViewer web accounts, and used those to connect into computers, where they seized web browsers to empty PayPal accounts, access webmail, and order stuff from Amazon and eBay.

"Hackers got everything from me," Doug, an Idaho-based Twitch streamer who was looking forward to celebrating his birthday today with his wife and two kids, told The Register.

"They remote connected in at 5AM MT, went into my Chrome and used my PayPal to buy about $3k worth of gift cards. And yes, I had two-factor authentication."

Over on Reddit, people were lining up with tales of their systems being compromised via TeamViewer, sparking fears the platform had been hacked. TeamViewer makes remote-control clients for Windows, OS X, Linux, Chrome OS, iOS and Android.

"I never expected this to happen, but it did," wrote Redditor Eric1084.

"When I sat down on my chair, I saw my mouse is moving across the screen. Of course, I immediately revoked remote control, and asked who [the hacker] is. At that point, he disconnected, and attempted to connect to my Ubuntu server, which has all my backups. Good thing I connected to [the server] right after he remote'd into my workstation. I revoked his permission before he tried to open Firefox. Immediately after, I started panicking, and thought he just stole all my passwords."

Another Redditor, famguy07, added: "I had the same thing happen to me tonight. Luckily I was playing Rocket League. I terminated [the connection] after less than 10 seconds. Once it clicked in my brain what had happened, I logged into my server and exited TeamViewer to deal with it later."

Pouring further fuel on the fire that TeamViewer had been infiltrated by criminals, at about 0700 Pacific Time (1500 in the UK) today TeamViewer suffered an outage lasting at least three hours, which knocked its website offline and left people unable to connect to their computers remotely.

It's claimed TeamViewer.com's DNS was screwed up during the IT snafu, thus stopping people from getting through to the Germany-based company's servers. We've heard that its DNS servers were pointing towards Chinese IP addresses at one point, but we haven't been able to verify that.

Sa reddit-a: On Friday I went to go get food from my kitchen and then I went to put something away in my room and when I came back PayPal was open and someone was trying to login so I went to go quit teamviewer and they panicked and quit the session. Even if they logged in to my PayPal account they would get nothing out of it since I'm broke. :D

Ja već neko vreme koristim AnyDesk (od bivših Team Viewer developera) i radi prilično bolje nego Team Viewer, tako da ako neko traži preporuku za zamenu TW-a...
 
Ja ne bih trčao pred rudu s tim. Nema nikakvog smisla cela priča.
 
Narocito kad krece sa Reddita.
 
Nije krenulo sa reddit-a, link do reddit-a je samo dodat pride (zarad dodatnih iskustava).

Nečega tu ima definitivno...
 
DDoS da. Hakovanje kako je rečeno nema smisla.
 
TV na računaru je klijent i kači se na specifične Teamviewer servere. Komunikacija je kriptovana. Ne postoji način da neko van tv mreže upadne u računar a da se to ne primeti u logovima tv servera. Jedino što može da se desi je da je neki od servera iz tv mreže na neki način napadnut, provaljen i da je preuzeta kontrola nad njim, te su napadači uspeli da preko tog servera upadnu na individualne računare korisnika.

Sent from my Nexus 6P using Tapatalk
 
Likovi kojima je ispraznjen PayPal su oni koji su zapamtili log in podatke u Chrome - u.. U svakom slučaju jedino još ostaje na koji način su im se uopšte nakacili na team viewer
 
Kriprtovano je direktno između korisnika, bez da serveri imaju pristup. Mogućnost je da su upali na servere onemogućili rate limiting i probili kratke pin-ove, ljudima koji ne menjaju default-e.
Ali opet bih pre rekao da je neka druga glupost u pitanju a da njih krive za to.
 
Anydesk koliko moze racunara da se poveze besplatno?
 
I kako stvari stoje krivi su korisnici sa lošim šiframa i šiframa koje koriste na više servisa/naloga. Dakle ako neko ima TV nalog, ne samo da ga je instalirao, stavite dobru šifru, ali ne šta misliš da je dobra nego stvarno dobra. I promeniti default za jačinu password-a u opcijama za ad-hoc povezivanje (to nije deo ovog "hakovanja" ali da ne bi posle bilo neko drugo).

Kao i obično loše prakse korisnika, koji onda krive kompaniju za svoju glupost.
 
Nazad
Vrh Dno