Jump to content

Someone accessing my Facebook account bypassing 2FA and notifications of foreign login attempt

StoneFire
Go to solution Solved by Spotty,

You were likely infected with malware that stole your browser's cookies that contain your session tokens for those websites. This would allow them to bypass logging in altogether as those cookies are what the websites use to authenticate you after you logged in. 

Changing your password should invalidate the old session tokens. If they still have access to your account they've either added an alternative login method (maybe to do with the phone number they added?) or the malware is still on your system and they were able to get the new tokens when you logged in to your account after changing your password.

 

59 minutes ago, StoneFire said:

PS, they never managed to change my passwords anywhere but I'm sure they were trying as they managed to add a foreign phone number to my facebook while I was already on top of the situation, so they were probably trying to exploit the weak ass security of using text based options.

Most websites require you to type your old password when setting a new password. If they did indeed steal your session cookies then they wouldn't have your password and would be unable to change it. 

Hello people,

I come to you as I'm in search of how the frigg someone manages to access my facebook account and managing to bypass my 2FA and my email notifications about logins from foreign devices.
I was a the victim of some malware and I'm well aware why my pc got compromised, but with my knowledge I can't fathom how they're able to do this with all these security measures in effect?
One thing could be if they simply have access through my own pc, but by digging around on facebook I was able to find foreign IPv6 addresses accessing my account and I don't have a such an address myself but instead an IPv4 one.
What keeps baffling me is even with the passwords changed on all of my accounts tied to my lastpass, and lastpass itself, and with the compromised pc been turned off for days they have still been able to log in.
They also managed to made a google ads account in from my google account which has the same security measures enabled and I was only notified of this when I got an email confirming the creation of my account.
PS, they never managed to change my passwords anywhere but I'm sure they were trying as they managed to add a foreign phone number to my facebook while I was already on top of the situation, so they were probably trying to exploit the weak ass security of using text based options.

Hopefully someone is able to share their insight so I can get a better understanding of HOW they're doing this.

Link to comment
Share on other sites

Link to post
Share on other sites

I think I'd delete the account first, then worry about how.

I don't badmouth others' input, I'd appreciate others not badmouthing mine. *** More below ***

 

MODERATE TO SEVERE AUTISTIC, COMPLICATED WITH COVID FOG

 

Due to the above, I've likely revised posts <30 min old, and do not think as you do.

THINK BEFORE YOU REPLY!

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, StoneFire said:

What keeps baffling me is even with the passwords changed on all of my accounts tied to my lastpass, and lastpass itself,

Wasn't lastpass recently compromised again? I wouldn't trust these fools to protect your passwords.

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Senzelian said:

Wasn't lastpass recently compromised again? I wouldn't trust these fools to protect your passwords.

I'm aware they had someone steal some source code, but even IF said insight in the code was used to access my lastpass they STILL need my authentication via my 2FA that I don't have via their platform. So your statement falls outside the scope of my question.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, StoneFire said:

So your statement falls outside the scope of my question.

Yeah I know it does. 

Is your 2FA reliant on a phone number, soft token, hard token, authenticator app? 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Senzelian said:

Yeah I know it does. 

Is your 2FA reliant on a phone number, soft token, hard token, authenticator app? 

Authenticator app and I try to never use any security measure relying on my phone number.

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, StoneFire said:

Authenticator app and I try to never use any security measure relying on my phone number.

I'm no security researcher, but I can tell you that even 2FA can be bypassed. Usually I'd say contact the support of the 2FA service that has failed, but you mentioned a Facebook and Google account, so I think there's a good chance that there is an issue with either your authenticator or your network.

 

 

 

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

You were likely infected with malware that stole your browser's cookies that contain your session tokens for those websites. This would allow them to bypass logging in altogether as those cookies are what the websites use to authenticate you after you logged in. 

Changing your password should invalidate the old session tokens. If they still have access to your account they've either added an alternative login method (maybe to do with the phone number they added?) or the malware is still on your system and they were able to get the new tokens when you logged in to your account after changing your password.

 

59 minutes ago, StoneFire said:

PS, they never managed to change my passwords anywhere but I'm sure they were trying as they managed to add a foreign phone number to my facebook while I was already on top of the situation, so they were probably trying to exploit the weak ass security of using text based options.

Most websites require you to type your old password when setting a new password. If they did indeed steal your session cookies then they wouldn't have your password and would be unable to change it. 

CPU: Intel i7 6700k  | Motherboard: Gigabyte Z170x Gaming 5 | RAM: 2x16GB 3000MHz Corsair Vengeance LPX | GPU: Gigabyte Aorus GTX 1080ti | PSU: Corsair RM750x (2018) | Case: BeQuiet SilentBase 800 | Cooler: Arctic Freezer 34 eSports | SSD: Samsung 970 Evo 500GB + Samsung 840 500GB + Crucial MX500 2TB | Monitor: Acer Predator XB271HU + Samsung BX2450

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×