Do you play this online game? Alert! Hackers are targetting you
The vulnerability would also have allowed for a massive invasion of privacy as an attacker could listen to in-game chatter as well as surrounding sounds and conversations within the victim`s home or other location of play.
Nearly 80 million players of the popular online battle game Fortnite are at increased hacking risk, said researchers from cyber security firm Check Point who discovered vulnerabilities that can give hackers access into user accounts.
If exploited, the vulnerability would enable hackers purchase virtual in-game currency using the victim`s payment card details, the company said in a statement late Thursday.
The vulnerability would also have allowed for a massive invasion of privacy as an attacker could listen to in-game chatter as well as surrounding sounds and conversations within the victim`s home or other location of play.
"Fortnite is one of the most popular games played mainly by kids. These flaws provided the ability for a massive invasion of privacy," said Oded Vanunu, Head of Products Vulnerability Research for Check Point.
"Together with the vulnerabilities we recently found in the platforms used by drone manufacturer DJI, show how susceptible cloud applications are to attacks and breaches," said added Vanunu.
While Fortnite players had previously been targeted by scams that deceived them into logging into fake websites that promised to generate Fortnite`s `V-Buck` in-game currency, these new vulnerabilities could have been exploited without the player handing over any login details.
Fortnite is popular on all gaming platforms, including Android, iOS, PC via Microsoft Windows and consoles such as Xbox One and PlayStation 4.
In addition to casual players, Fortnite is used by professional gamers who stream their sessions online and is popular with e-sports enthusiasts.
To fall victim to this attack, a player needs only to click on a crafted phishing link coming from an "Epic Games" domain, to make everything seem transparent, though sent by the attacker.
Watch Zee Business Tweet video here:
#ZBizHeadlines | दोपहर 12 बजे की सुर्खियों पर एक नज़र। pic.twitter.com/HxJbkAoMs1
— Zee Business (@ZeeBusiness) January 18, 2019
Once clicked, the user`s Fortnite authentication token could be captured by the attacker without the user entering any login credentials.
According to the researchers, the potential vulnerability originated from flaws found in two of Epic Games` sub-domains that were susceptible to a malicious redirect, allowing users` legitimate authentication tokens to be intercepted by a hacker from the compromised sub-domain.
Check Point has notified Epic Games of the vulnerability which has now been fixed.
"Enforcing two-factor authentication could mitigate this account takeover vulnerability," said Vanunu.
Get Latest Business News, Stock Market Updates and Videos; Check your tax outgo through Income Tax Calculator and save money through our Personal Finance coverage. Check Business Breaking News Live on Zee Business Twitter and Facebook. Subscribe on YouTube.
RECOMMENDED STORIES
Power of Compounding: How many years will it take to reach Rs 3 crore corpus if your monthly SIP is Rs 4,000, Rs 5,000, or Rs 6,000
IRCTC Dividend 2024: Railway PSU announces 200% interim dividend - Check record date and other details
Power of Compounding: Salary Rs 25,000 per month; is it possible to create over Rs 2.60 crore corpus; understand it through calculations
Reduce Home Loan EMI vs Reduce Tenure: Rs 75 lakh, 25-year loan; which option can save Rs 25 lakh and 64 months and how? Know here
Top 7 Large and Mid Cap Mutual Funds with Best SIP Returns in 5 Years: No. 1 fund has turned Rs 15,000 monthly SIP investment into Rs 20,54,384; know about others
New Year Pick by Anil Singhvi: This smallcap stock can offer up to 75% return in long term - Check targets
PSU Oil Stocks: Here's what brokerage suggests on these 2 largecap, 1 midcap scrips - Buy, Sell or Hold?
12:40 PM IST