this post was submitted on 03 Aug 2024
18 points (95.0% liked)
Cybersecurity
5734 readers
75 users here now
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
Notable mention to [email protected]
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Dosen't Microsoft rate limit the attempts? In that case ypu can just select a random number, the trie to brute force it until the code send is the one selected.
It doesn't seem all that limited; I'll get 4-5 in a burst, then nothing for a couple of hours or a day or so, then 4-5 more, and so on.
Been ongoing for a couple of months now, and given it's a random 6 digit number, I don't think they're even remotely doing enough attempts to try to brute force it.
If Microsoft accepts, let's say, 3 attempts per code send, they already tried 1200 numbers (per your 400 emails), it's still short to the 10**6 random attempts on average (supposing that the codes are entirely random). If you email is part of a list of a thousand, they already had tried more that a million and got access to some of them.