Best Website Builders CompanyBest Website Builders Company
    What's Hot

    Future of Work: Flexibility and Wellness on center stage

    May 30, 2023

    NPS calculator: Amazing retirement with Rs 2 crore to Rs 6 crore in hand possible; here’s how

    May 30, 2023

    Crude oil rises on US debt deal, but rate hikes, OPEC+ talks curb enthusiasm

    May 30, 2023
    Facebook Twitter Instagram
    Facebook Twitter Instagram
    Best Website Builders CompanyBest Website Builders Company
    • Home
    • Web Builders
      1. Joomla
      2. WordPress
      3. CSS
      4. Web Design
      5. UX
      6. PHP
      7. View All

      For $50 you can host your website for life

      May 2, 2023

      California Department of Justice Investigating Shooting Involving CHP Officer in Glenn County Under AB 1506

      May 1, 2023

      Mariposa County Daily Sheriff and Reservation Report for Sunday, April 30, 2023

      May 1, 2023

      Top 10 Best Web Development Companies In India In 2023

      May 1, 2023

      Google Ads Sign Up – Easy Steps to Create Your Account

      May 17, 2023

      1Password puts users at ease after the horror of password change notifications

      May 3, 2023

      Samsung Galaxy S23 FE could feature a 50MP main camera, but we may have to wait until then

      May 3, 2023

      Titanfall director says Respawn is ‘looking forward to something new’

      May 3, 2023

      Implementing CSS with character and spirit: Union MoS Finance

      May 3, 2023

      Street Fighter 6’s unique character select screen animation really shows how much heart goes into the game

      May 3, 2023

      Make Google Chrome run faster with these 9 tips and tweaks

      May 3, 2023

      🅰️ New Angular 16 Goes Big in 2023: Everything You Need to Know | Vitaly Shevchuk | Oct 25, 2017 May 2023

      May 3, 2023

      18-Wheeler Accidents: Fatalities and Injuries

      May 6, 2023

      What Comes First in Website Development — Design or Copy?

      February 2, 2023

      Modern Campus Honors Best Higher Education Websites of 2022

      February 2, 2023

      Premier SEO Consultant in Las Vegas, Nevada with Unparalleled Customer Service

      February 2, 2023

      The role of artificial intelligence in improving the user experience in online casinos.

      May 3, 2023

      Microsoft enhances user experience with Windows 11 ‘smart opt-out’ and improved emergency notifications

      May 3, 2023

      Nigeria’s Nestcoin Launches New Digital Financial Platform For Africans

      May 3, 2023

      ibi WebFOCUS 9.2 is ready for Modern Business Intelligence, the Cloud, and Driving User Experience – PCR.

      May 3, 2023

      Anthony Carrigan Reflects on That ‘Barry’ Scene from Season 4 Episode 4

      May 1, 2023

      TikToker Kat Abu is very happy that Tucker Carlson has been fired

      April 28, 2023

      How ‘Single Drunk Female’ Season 2 Tackled Emotional Sobriety

      April 24, 2023

      Trans-Missouri Residents Affected by Attorney General Order

      April 24, 2023

      Creating and Adding a Google Account: A Step-by-Step Guide

      May 2, 2023

      How i Create New Google Account

      February 7, 2023

      CWT powers tools for meeting and event planners

      January 31, 2023

      Best Website Builder – Website Builders

      January 24, 2023
    • Realtoz
      • Our Other Sites
    • More News
    • Investments
    Best Website Builders CompanyBest Website Builders Company
    Home»UX»SMS pumping attacks and how to mitigate them
    UX

    SMS pumping attacks and how to mitigate them

    websitebuildersnowBy websitebuildersnowMarch 24, 2023No Comments5 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Kyle Johnson

    To

    Not all cyberattacks penetrate IT environments and steal information. Some attacks are still financially backed and focus instead on fraud. One such fraud-based attack is SMS pumping.

    What is SMS pumping?

    In SMS pumping attacks, malicious actors take advantage of SMS systems connected to online forms and web apps. For example, when a user requests a download link or a one-time passcode (OTP). The attacker uses a bot to automatically fill a premium rate phone number into an online form connected to her SMS system. These numbers charge higher telecom rates, thus giving more money to the mobile network operators (MNOs) who manage these specific numbers. The attacker is profiting by either unknowingly exploiting her MNO or cooperating with her malicious MNO to receive a portion of the proceeds from premium her rate phone numbers. increase.

    SMS pumping attacks are also known as SMS artificially increased traffic, SMS OTP scam again artificially generated traffic.

    About 6% of all SMS traffic from December 2021 to December 2022 was flagged as SMS pumping by Lanck Telecom. February 2023, Elon Musk claimed SMS pumping attacks cost Twitter $60 million annually. Twitter removed his two-factor authentication (2FA) by text except for verified Twitter Blue users due to these attacks. The move was intended to save money by limiting the use of 2FA SMS to subscription customers only.

    How to detect SMS pumping attacks

    An SMS pumping attack should first be detected when an unusual number of SMS notifications are requested, or when a spike in certain types of phone numbers requesting SMS notifications (such as premium rate numbers) is detected. is often

    Forrester Research analyst Andras Cser recommends that organizations pay attention to phone numbers used in password reset, registration, and similar web page forms to detect SMS pumping attacks. increase. “This includes understanding the device IDs and reputation of the sites that plug in these anomalous numbers,” he said.

    If you detect a spike in SMS notification requests, ask the following questions to clarify whether it is an SMS pumping attack.

    • Are the numbers from countries where the organization has few or no customers?
    • Is your request short term?
    • Are the phone numbers consecutive? For example, +1111111000 and +1111111001.
    • Is your web form only partially completed?
    • Is your conversion rate dropping?

    If the answer to any of these questions is yes, it could be an SMS attack.

    How to prevent and mitigate SMS pumping

    It’s important to prevent SMS pumping attacks from happening in the first place. You can also mitigate attacks to reduce their impact. Use the following prevention and mitigation methods:

    • Implement CAPTCHAs. Using an open source library called CAPTCHA or BotD on the signup page of a website helps organizations keep bots out. By forcing the attacker to manually submit the phone number, CAPTCHA significantly slows down the attack and reduces the value of the attack.
    • Rate limit the number of SMS messages that can be sent. Instead of allowing the system to send an unlimited number of SMS messages to the same phone number, use a product that allows you to rate limit the number of messages that can be sent over a period of time. “This may not prevent fraud, but it may deter [attackers] said Mike Gannon, product marketing manager at communications PaaS provider Soprano Design.
    • Delay validation retries. The user may need to resubmit their phone number in an OTP or similar form immediately after the first attempt. Instead of allowing multiple retries within seconds of each other, delay the time before you can send additional her SMS messages. This slows it down and frustrates attackers.
    • Use geographic authority. Anthony Graham, senior product marketing manager at cloud communications platform Plivo, recommends disabling sending messages to numbers from countries where the company doesn’t operate. This limits where attackers can use premium his-rate phone numbers, reducing potential fraudulent charges.
    • Please check the number before sending. Determines if the phone number submitted in the form is a regular mobile number rather than a premium rate. For example, the carrier lookup service of API communications platform Twilio and communications platform Dexatel reports which carrier provides the number and determines whether it is worthwhile for an organization to block that carrier. help you to
    • Request additional information from the user. Require users to provide information other than phone numbers in an online form. While this may affect her UX, it deters bad actors from targeting your organization and reduces your ability to easily use bots to generate traffic.
    • Remove 2FA SMS. Remove the option to send OTPs to 2FA SMS numbers if that is a viable solution. However, this is not always possible. OTP isn’t the strongest in terms of security, but it does have cost and his UX benefits.

    This was last published March 2023


    Dig deeper into application and platform security








    Source link

    Share this:

    • Tweet
    • More
    • WhatsApp
    • Print
    • Share on Tumblr
    • Mastodon

    Related

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleBob Metcalfe, The Man Who Discovered Network Effects, Isn’t Sorry
    Next Article Framework’s DIY laptop puts Apple and Microsoft to shame with upgradeable CPUs and makes me excited for the future
    websitebuildersnow
    • Website

    Related Posts

    The role of artificial intelligence in improving the user experience in online casinos.

    May 3, 2023

    Microsoft enhances user experience with Windows 11 ‘smart opt-out’ and improved emergency notifications

    May 3, 2023

    Nigeria’s Nestcoin Launches New Digital Financial Platform For Africans

    May 3, 2023
    Add A Comment

    Leave a Reply Cancel reply

    Post Your Ad Free
    Advertisement
    Demo
    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    This website provides information about CSS and other things. Keep Supporting Us With the Latest News and we Will Provide the Best Of Our To Makes You Updated All Around The World News. Keep Sporting US.

    Facebook Twitter Instagram Pinterest YouTube
    Top Insights

    Future of Work: Flexibility and Wellness on center stage

    May 30, 2023

    NPS calculator: Amazing retirement with Rs 2 crore to Rs 6 crore in hand possible; here’s how

    May 30, 2023

    Crude oil rises on US debt deal, but rate hikes, OPEC+ talks curb enthusiasm

    May 30, 2023
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2023 bestwebsite-builders. Designed by bestwebsite-builders.
    • Home
    • About us
    • Contact us
    • DMCA
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    x