PSA: TeamViewer users are being hacked [updated]

Releases and other announcements.
Please don't post support questions here
Forum rules
Section reserved for the team. You can reply to announcements here but not post new topics. Do not add support questions to threads here, use the appropriate support forum instead.
User avatar
xenopeek
Level 25
Level 25
Posts: 30193
Joined: Wed Jul 06, 2011 3:58 am

PSA: TeamViewer users are being hacked [updated]

Post by xenopeek »

TeamViewer users across all operating systems are reporting being hacked. The attackers access the victims' TeamViewer web accounts and through that gain access to their (unattended and unlocked) computers and use their web browsers to empty their PayPal accounts, access their webmail, and order stuff from Amazon or eBay. Some news sources:
http://news.softpedia.com/news/teamview ... 4758.shtml
http://www.theregister.co.uk/2016/06/01 ... ch_report/

The /r/teamviewer community on Reddit is blowing up over this. You can find more information in the threads there.

TeamViewer say they haven't been hacked. They say users have been careless with using the same password on multiple websites and if they have been attacked through TeamViewer, it would have been through their password having been stolen from another website.

Right now we don't have all the facts but as also Linux users are reporting having been hacked I would at this time urge caution and to remove TeamViewer from all your computers and devices. Make sure to grab the TeamViewer logs before you do this! On Linux run the command teamviewer --ziplog to create a zip of the TeamViewer logs, as you can't access those after removing TeamViewer. As more details come out you may be able to use these logs to confirm whether you have been hacked or not. If you have a TeamViewer account you may also use the tips in https://www.reddit.com/r/teamviewer/com ... _accessed/ to confirm whether you have been hacked or not.

If you want/need to continue to use TeamViewer, read the security best practices thread and follow up on that advice: https://www.reddit.com/r/teamviewer/com ... practices/

Update: BigEasy provided a link to a thorough walkthrough for securing TeamViewer: How to Lock Down TeamViewer for More Secure Remote Access

Update 2: TeamViewer have two new features to improve security of your account: Trusted Devices and Data Integrity

In short, similar to how Steam does this, when you sign in to your account from a device you've not signed in with previously—TeamViewer will send you an email on your account email with a link to authorize that device to be used. This should be an immediate stop to hackers gaining access to TeamViewer accounts.

The second new feature is less well explained; TeamViewer will monitor your account for "unusual behavior" and force a password reset if such behavior is detected.

In the announcement they also "underscore that TeamViewer account authentication uses the Secure Remote Password protocol (SRP) and therefore does not store any password-equivalent data." Looking up SRP on Wikipedia (https://en.wikipedia.org/wiki/Secure_Re ... d_protocol) explains that on the server a "cryptographic verifier derived from the password" is stored.

It does look like TeamViewer were correct in that the hacked users were using weak passwords or reused passwords. With the above two new features to improve security and taking note of the tips in How to Lock Down TeamViewer for More Secure Remote Access I would be fine with using TeamViewer again.
Image
Habitual

Re: PSA: TeamViewer users are being hacked

Post by Habitual »

Ouch.
Neil Edmond
Level 6
Level 6
Posts: 1348
Joined: Thu Dec 26, 2013 10:19 am
Location: N.E. AR USA

Re: PSA: TeamViewer users are being hacked

Post by Neil Edmond »

Oh no!
deleted

Re: PSA: TeamViewer users are being hacked

Post by deleted »

This is their press release:
Statement on Potential TeamViewer Hackers
-H
Habitual

Re: PSA: TeamViewer users are being hacked

Post by Habitual »

hinto wrote:This is their press release:
Statement on Potential TeamViewer Hackers
-H
pft. Sounds like the usual spin control rhetoric.
"Therefore it it is important to stress there are no TeamViewer hackers, but rather data thieves that will steal information from other sources"
So, TeamViewer information from "other sources"?
Sounds more like 0day to me.

Lock your workstations people.
User avatar
xenopeek
Level 25
Level 25
Posts: 30193
Joined: Wed Jul 06, 2011 3:58 am

Re: PSA: TeamViewer users are being hacked

Post by xenopeek »

I've deleted two off-topic comments. Kindly stay on topic about TeamViewer in this thread.
Image
User avatar
Fred Barclay
Level 12
Level 12
Posts: 4184
Joined: Sat Sep 13, 2014 11:12 am
Location: USA primarily

Re: PSA: TeamViewer users are being hacked

Post by Fred Barclay »

Thank you xenopeek!

I almost installed TeamViewer a year ago... got really uncomfortable with the idea and decided not to. Now I'm glad I didn't!
I wonder if something like firejail could have mitigated this? There isn't a teamviewer profile ATM but even a generic profile might have helped. :?

EDIT: Did TV have to be running for you to be hacked, or was it simply being installed but not running enough for the crackers?
Image
"Once you can accept the universe as matter expanding into nothing that is something, wearing stripes with plaid comes easy."
- Albert Einstein
User avatar
Reorx
Level 12
Level 12
Posts: 4042
Joined: Tue Jul 07, 2009 7:14 pm
Location: SE Florida, USA

Re: PSA: TeamViewer users are being hacked

Post by Reorx »

Thanx for the "heads up" Xeno! :o
Full time Linux Mint user since 2011 - Currently running LM21C on multiple Dell laptops - mostly Vostro models.

Image Image Image
User avatar
xenopeek
Level 25
Level 25
Posts: 30193
Joined: Wed Jul 06, 2011 3:58 am

Re: PSA: TeamViewer users are being hacked

Post by xenopeek »

Fred Barclay wrote:I wonder if something like firejail could have mitigated this? [...]

EDIT: Did TV have to be running for you to be hacked, or was it simply being installed but not running enough for the crackers?
TeamViewer is used to view and control your graphical desktop from another device. firejail doesn't help against that.
And yes, TeamViewer would need to be running for the attackers to gain access. But as I understand it, once installed it would automatically run at startup by default. It's been a while since I last looked at it.
Image
killer de bug

Re: PSA: TeamViewer users are being hacked

Post by killer de bug »

xenopeek wrote: But as I understand it, once installed it would automatically run at startup by default.
It makes sense if you need to reboot a computer from distance. You would not be able to finish your work otherwise.
killer de bug

Re: PSA: TeamViewer users are being hacked

Post by killer de bug »

hinto wrote:This is their press release:
Statement on Potential TeamViewer Hackers
-H
:shock:

They made a statement on the 23rd of May about an attack ongoing in June?
BigEasy
Level 6
Level 6
Posts: 1288
Joined: Mon Nov 24, 2014 9:17 am
Location: Chrząszczyżewoszyce, powiat Łękołody

Re: PSA: TeamViewer users are being hacked

Post by BigEasy »

It can't be means it can't be. So, another idea required. Realistic.
Windows assumes I'm stupid but Linux demands proof of it
Cosmo.

Re: PSA: TeamViewer users are being hacked

Post by Cosmo. »

This statement is more current.
Laugh2
Level 4
Level 4
Posts: 276
Joined: Fri Aug 16, 2013 4:01 am

Re: PSA: TeamViewer users are being hacked

Post by Laugh2 »

Yes, thanks to Xenopeek for the info. For security reasons I'd be happy to swap to another program - but which one?

I use remote support software mostly to support my aged mum's system (LM 17.3) so we've benefited from LogMeIn and now Teamviewer. :D LogMeIn was great but they put up a pay wall so we swapped to Teamviewer.

Anyone know of good alternative to these two? :?:
Habitual

Re: PSA: TeamViewer users are being hacked

Post by Habitual »

Laugh2 wrote:Yes, thanks to Xenopeek for the info. For security reasons I'd be happy to swap to another program - but which one?

I use remote support software mostly to support my aged mum's system (LM 17.3) so we've benefited from LogMeIn and now Teamviewer. :D LogMeIn was great but they put up a pay wall so we swapped to Teamviewer.

Anyone know of good alternative to these two? :?:
NoMachines?
wmh

Re: PSA: TeamViewer users are being hacked

Post by wmh »

Thanks for sharing this information.
BigEasy
Level 6
Level 6
Posts: 1288
Joined: Mon Nov 24, 2014 9:17 am
Location: Chrząszczyżewoszyce, powiat Łękołody

Re: PSA: TeamViewer users are being hacked

Post by BigEasy »

Finally the article written with assistance of brain:
http://www.howtogeek.com/257376/how-to- ... te-access/
Windows assumes I'm stupid but Linux demands proof of it
User avatar
Moem
Level 22
Level 22
Posts: 16443
Joined: Tue Nov 17, 2015 9:14 am
Location: The Netherlands
Contact:

Re: PSA: TeamViewer users are being hacked

Post by Moem »

BigEasy wrote:Finally the article written with assistance of brain:
http://www.howtogeek.com/257376/how-to- ... te-access/
That sounded good until I got to "instead of just your email and password, you need your email, password, and the unique code generated by the authentication app on your cellphone".
No two factor authentication for me... :?

Really? They can't create a safe way to use their software that does not require the user to have a smartphone?
Image

If your issue is solved, kindly indicate that by editing the first post in the topic, and adding [SOLVED] to the title. Thanks!
killer de bug

Re: PSA: TeamViewer users are being hacked

Post by killer de bug »

Some users on Reddit complain that 2 factors authentication was bypassed.
BigEasy
Level 6
Level 6
Posts: 1288
Joined: Mon Nov 24, 2014 9:17 am
Location: Chrząszczyżewoszyce, powiat Łękołody

Re: PSA: TeamViewer users are being hacked

Post by BigEasy »

Moem wrote:Really? They can't create a safe way to use their software that does not require the user to have a smartphone?
Briefly about two-factor authentication:
https://en.wikipedia.org/wiki/Two-factor_authentication
Windows assumes I'm stupid but Linux demands proof of it
Post Reply

Return to “Releases & Announcements”