Categories: All

Man in the Cloud: Hackers Can Access Your Dropbox, Google Drive, OneDrive Files WITHOUT Password

SPR: Researchers have found a new way to hack into your cloud syncing accounts without any username or password by deploying a new “man in the cloud attack”. These attacks use “password tokens” and are harder to detect and control.
You must have read about the man-in-the-middle attacks that steal your data transiting between the two end points. Today, we are going to tell you about a new man in the cloud attack that allows the attacker to access your files in the cloud without passwords.
At the Black Hat security conference in Las Vegas, cyber security firm Imperva has published a new research that exploits a vulnerability in the design of cloud syncing services like Google, Box, OneDrive, and Dropbox.
This man in the cloud attack works by stealing the password token, a tiny file that is found in user’s devices. The password token saves the user from typing their password again and again. After obtaining this token using methods like phishing attack or a drive-by exploit, hackers can use it to access your account by fooling another new device. This man in the cloud attack could be used to steal/alter your files, and add ransomware or malware.
Amichai Shulman, CTO of Imperva, said that this type of man in the cloud attack can also affect businesses that are dependent on cloud-based services. He added that their research has revealed how easy it is for cybercriminals to hack cloud syncing accounts, and how difficult it’s to recover and detect such unauthorized authentications. He said, “recovery of the account from this type of compromise is not always feasible.”
Describing the man in the cloud attack, Shulman defended the cloud service providers and refrained himself from calling it a design flaw. He said that these services are secure, providing seamless file transfer, but it’s s trade-off between security and usability.
Even though many services offer 2-factor authentication, there isn’t any simple fix for the man in the cloud attack. These 2-factor notifications are delivered when an access is detected from a new computer or a new location, but people choose to ignore them. To themselves protect from these attacks, Imperva said that companies must invest more in monitoring and protecting data resources in the cloud.
Did you find this story helpful? Tell us in the comments below.
For more updates, subscribe to our newsletter.
spatsariya

Share
Published by
spatsariya

Recent Posts

How To View Your Instagram Reel History: 4 Ways

Quick Answer Instagram does not keep a history of the Reels you watch. The app…

14 hours ago

Can you Scale with Kanban? In-depth Review

What works well for one team becomes chaos when scaled to a department or company…

3 days ago

Type Soul Trello V2 Link (2025)

Inspired by the super-popular anime and manga series Bleach, Type Soul is a Roblox game…

5 days ago

Zerith H1: The First Humanoid Robot for Hotel Housekeeping

The hospitality sector is embracing a tech revolution with the introduction of the Zerith H1…

5 days ago

Asus Vivobook S14 OLED Review: A Real MacBook Alternative

The Vivobook S14 OLED delivers impressive value by combining a sleek, lightweight design with the…

6 days ago

How To Make Marriage in Infinite Craft?

Infinite Craft is a fun sandbox game that challenges players to create new items by combining…

6 days ago