Zouheir Abdallah revealed that a hacker already knows the victim’s credentials for Dropbox account that has 2FA authentication enabled, is able to hack it.
Few hours ago I was informed that Q-CERT team found a critical vulnerability in DropBox that allows a hacker to bypass the two-factor authentication implemented by the popular file sharing service.
Just a few days ago I have spoken of the necessity for SMBs to implement a two-factor authentication to improve security for resources and services exposed on the Internet. Principal service providers such as LinkedIn, Google and Facebook has already implemented a two-factor authentication process to protect the user’s account for violations and abuse.
The researcher Zouheir Abdallah revealed that an attacker already knows the victim’s credentials (username and password obtained with a Key-logger, cross-site shared password, due the adoption of a easy to guess password etc..), for Dropbox account that has two-factor authentication enabled, is able to hack that account following the described procedure.