May I Know your IBAN? Cracking the Short Message Service (SMS) as a Second Factor Authentication for Online Payments

Mohamamd Z. Masoud, Yousef M. Jaradat, Ahmad A. Manasrah, Ismael Jannoud, Mohammad Ahmad Alia · 2021

Short messages service (SMS) has been widely used for E-commerce authentications in the past years. It is utilized to authenticate users for Email password resetting process, authenticating online purchase process and even resetting the password of different E-government services. In this work, a new simple hacking process has been implemented to show that SMS authentication can be cracked simply if smartphones users' grant permissions to any App without even reading these permissions or thinking why this App requires these permissions. An android App has been written with an underlying service to listen to SMSs and forward them to another smartphone. The application has been distributed among 20 persons as an experiment. 90% of the persons have downloaded the App and 80% of them have granted the permissions without reading it. Therefor we can Emails passwords `phished it' simply.

Read the paper · More papers on PaperTik