Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Taking over Uber accounts through voicemail
(opens in new tab)
(blog.assetnote.io)
15 points
infosecau
4y ago
5 comments
Save
Share
5 comments
5 comments · 4 top-level
top
newest
oldest
zealsham
4y ago
· 1 in thread
I’ll say Uber rejected this due to highly unlikely user interaction required .
infosecau
OP
4y ago
There's not really much user interaction required. You just have to engage the victims cell phone when sending the OTP. The voicemail hack doesn't require any user interaction.
dns
4y ago
I know as shubs, this post interesting and good writeup. thanks! I follow you on twitter!
mechboy
4y ago
Uber will never know the severity of this bug until several user accounts got compromised by someone
fzionism
4y ago
Very interesting,
j
/
k
navigate · click thread line to collapse