Online accounts are inherently valuable resources both for the data they contain and the reputation they accrue over time. Unsurprisingly, this value drives criminals to steal, or hijack, such accounts. In this paper we focus on manual account hijacking account hijacking performed manually by humans instead of botnets. We describe the details of the hijacking workflow: the attack vectors, the exploitation phase, and post-hijacking remediation. Finally we share which defense strategies we found effective at Google to curb manual hijacking.
Handcrafted fraud and extortion: manual account hijacking in the wild
| Available Media | |
|---|---|
| Conference | Internet Measurement Conference (IMC) - 2014 |
| Authors | Elie Bursztein , Borbala Benko , Daniel Margolis , |
| Citation | BibTeX |
Related
anti-abuse
Ad injection at scale: assessing deceptive advertisement modifications
publications
S&P 2015
anti-abuse
Picasso: Lightweight Device Class Fingerprinting for Web Clients
publications
SPSM 2016
anti-abuse
Secrets, lies, and account recovery: lessons from the use of personal knowledge questions at google
publications
WWW 2015