Answer the question
In order to leave comments, you need to log in
I don’t understand how vk was hacked?
Greetings, today I discovered that someone logged into my VK account, and the account has double authentication, no notifications, no SMS, they posted some nonsense from my account. Several questions follow from this:
1) As far as I understand, my cookies were stolen, and through them I was authorized?
2) If these are cookies, for example, I change the password and end all sessions from my account, will the attacker be able to log in again like this?
3) As I understand it, all cookies were stolen from the browser in general, that is, the attacker has access to all accounts. Can I somehow reset these cookies so that the bandit does not get access to something else?
4) How to protect yourself from this?)
Answer the question
In order to leave comments, you need to log in
1. For two-factor authorization via SMS - a separate NORMAL! phone without OS (without android, ios, etc.).
2. Do not use public wi-fi networks (hotel, transport, cafes, etc.).
3. Do not use third-party browsers.
4. Do not give access to the client device to third parties.
5. Do not install any third party certificates.
6. Always check: which of the third-party applications / sites has access (and which one!) To perform various operations on the social network on behalf of your account without your participation (but from your permission, issued by you to the service / site earlier, when using any of them and at their request for this type of operation).
As far as I understand, my cookies were stolen, and they authorized me through them?
If these are cookies, for example, I change the password and end all sessions from my account, will the attacker be able to log in again like this?
Can I somehow reset these cookies so that the bandit does not get access to something else?
How to protect yourself from this?)
Most likely, an attacker either had access to your phone, or you registered on suspicious sites, or you accessed the network from an unknown WiFi source (for example, free hotspots).
From the definition:
A cookie is a small piece of data sent by a web server and stored on the user's computer. The web client sends this piece of data to the web server as part of an HTTP request every time it tries to open a page of the corresponding site.
Even stealing "cookies" or just simply a real clean public token will not help anyone to hack or log in through your account. Because the token is issued in conjunction with the ip address. The same token cannot be used for two sessions from different ip addresses.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question