{"id":281,"date":"2014-04-30T13:40:33","date_gmt":"2014-04-30T13:40:33","guid":{"rendered":"https:\/\/www.varutra.com\/blog\/?p=281"},"modified":"2023-03-24T15:28:06","modified_gmt":"2023-03-24T09:58:06","slug":"how-secure-is-my-linkedin-account","status":"publish","type":"post","link":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/","title":{"rendered":"How secure is my LinkedIn account ?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"1080\" src=\"https:\/\/varutra-1a3b6.kxcdn.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy-1024x591.jpg\"  class=\"sh-overlay-item sh-table-cell ls-is-cached lazyloaded\" data-rel=\"lightcase\" title=\"LinkedIN Copy - Varutra Consulting\"><br \/>\n<a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/image11.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-370 size-medium\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/image11-300x211.jpg\" alt=\"Magnifying glass showing word BUG in software code\" width=\"300\" height=\"211\" \/><\/a><\/p>\n<p style=\"text-align: justify\">LinkedIn is a business-oriented Social networking service. One purpose of the sites is to allow registered users to maintain a list of contact details of people with whom they have some level of relationship, called <i>Connections<\/i>. Users can invite anyone (whether a site user or not) to become a connection. More details about LinkedIn can be found at <a href=\"http:\/\/en.wikipedia.org\/wiki\/LinkedIn\">http:\/\/en.wikipedia.org\/wiki\/LinkedIn<\/a><\/p>\n<p style=\"text-align: justify\">End of last year when I was checking my LinkedIn account I thought of giving a try to see how secure is my LinkedIn account. I noticed few very interesting but dangerous security issues.<\/p>\n<p style=\"text-align: justify\">Given below are few of the security issues I thought of sharing for learning purpose. Security issues mentioned below are only those, which have already got patched by LinkedIn recently.<\/p>\n<p><b><\/b><span style=\"text-decoration: underline\">Consider the following scenario:<\/span><\/p>\n<p style=\"text-align: justify\">Any valid LinkedIn user logs into his\/her account and can Change\/Add new Email address. Once user adds a new Email address, LinkedIn server sends a mail on the given (new) Email address with a message \u201cPlease confirm your email address\u201d.<\/p>\n<p>This looks like a normal process of adding a new Email Id. Isn&#8217;t it?<\/p>\n<p>But there is an issue here,<\/p>\n<p style=\"text-align: justify\">LinkedIn does not force user or wait for user to confirm the newly added Email address and instead allows access to the LinkedIn account with the new Email address immediately.<\/p>\n<p style=\"text-align: justify\">An attacker can send a crafted link to the victim ( i.e. valid LinkedIn account holder) for adding an arbitrary Email address to his\/her LinkedIn account. Attacker can send this crafted link on victim\u2019s valid Email Id. Here attacker can try to use CSRF attack vulnerability.<\/p>\n<p style=\"text-align: justify\"><i>For me it was not that simple to carry out CSRF attack, as it seemed that LinkedIn application was using adequate measures such as CSRF tokens. <\/i><\/p>\n<p style=\"text-align: justify\">After few analysis what was observed that if I know the server generated CSRF token of an authenticated session of victim then I can get this working and still carry out the attack on the victim.<\/p>\n<p style=\"text-align: justify\">There is one trick to collect User\u2019s CSRF token using Social Engineering technique, that is by asking victim user to show the Sign Out button, or some feature of LinkedIn etc. While she shows her logged in screens at that time quickly note down the CSRF token by either viewing the web page source or simply hovering the mouse pointer on Sign Out button as shown in the POC screenshot.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-288 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/1.png\" alt=\"1\" width=\"848\" height=\"488\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/1.png 848w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/1-300x173.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/1-768x442.png 768w\" sizes=\"(max-width: 848px) 100vw, 848px\" \/><\/a><\/p>\n<p style=\"text-align: center\"><em>Figure 1: Application shows complete link with CSRF token on the Sign Out Button<br \/>\n<\/em><\/p>\n<p style=\"text-align: justify\">Needless to say with Google Glass like technology where user can click photos on the fly will make this task very easy, as attacker just needs to view and take a snapshot of the screen showing the link with CSRF token, etc.<\/p>\n<p style=\"text-align: justify\">Let&#8217;s assume that attacker is successful in sending the crafted link to add a custom Email address on victim\u2019s LinkedIn account. Attacker can achieve this either by the trick we talked above or finding actual CSRF vulnerability in the application.\u00a0 And that\u2019s possible. In next blog I will discuss about how I found CSRF attack on LinkedIn.<\/p>\n<p>Now let us continue understanding other important security issues,<\/p>\n<p>The crafted CSRF link by attacker will be<\/p>\n<p><b><i>https:\/\/www.linkedin.com \/settings\/manage-email-submit?a ddEmail=custom_email_id&amp;csrfToken= ajax%3A0988969076258526585<\/i><\/b><\/p>\n<p style=\"text-align: justify\">On executing this link new Email address will get added into victim\u2019s LinkedIn account without her knowledge. Let us see what happens then,<\/p>\n<p><b><span style=\"color: #b40404\">LinkedIn adds new Email address without any confirmation from the user.<\/span><\/b><\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-287 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/2.png\" alt=\"Application has added new Email address\" width=\"865\" height=\"475\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/2.png 865w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/2-300x165.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/2-768x422.png 768w\" sizes=\"(max-width: 865px) 100vw, 865px\" \/><\/a><br \/>\n<em>Figure 2: Application has added new Email address.<\/em><\/p>\n<p style=\"text-align: justify\">Lets ask a question here &#8211; After adding a custom Email address (in this case &#x6b;&#x69;&#x73;&#x68;&#x6f;&#x72;&#x73;&#x6f;&#x6e;&#x61;&#x77;&#x61;&#x6e;&#x65;&#x30;&#x38;&#x40;<span class=\"oe_displaynone\">null<\/span>&#x67;&#x6d;&#x61;&#x69;&#x6c;&#x2e;&#x63;&#x6f;&#x6d;) by sending a crafted link to the victim, will LinkedIn still protect the victim by forcing him\/her to first confirm the new Email address and then only activate it?<\/p>\n<p style=\"text-align: justify\">Ideally any secure application should confirm by the account holder whether she had added any new Email address. But that was not the case with LinkedIn.<\/p>\n<p style=\"text-align: justify\">Without confirming the new Email address let us try to access the forgot password page and enters new Email address so that LinkedIn can send password reset token \/ code.<\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-286 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/3.png\" alt=\"3\" width=\"925\" height=\"244\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/3.png 925w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/3-300x79.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/3-768x203.png 768w\" sizes=\"(max-width: 925px) 100vw, 925px\" \/><\/a><br \/>\n<em>Figure 3: Accessing LinkedIn forgot password page<\/em><\/p>\n<p style=\"text-align: justify\">Shockingly, without confirming the newly added Email address, LinkedIn has sent the \u2018Password RESET\u2019 token on newly added Email Id. Bingo!!!<\/p>\n<p><b><span style=\"color: #b40404\">LinkedIn activates the new Email address <b>without getting any confirmation from the user<\/b> and sends password reset link .<\/span><\/b><\/p>\n<p style=\"text-align: justify\">As you must have observed that the password reset token was sent on newly added Email address meaning on attacker\u2019s Email address.<\/p>\n<p style=\"text-align: center\"><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-285 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/4.png\" alt=\"4\" width=\"865\" height=\"377\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/4.png 865w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/4-300x131.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/4-768x335.png 768w\" sizes=\"(max-width: 865px) 100vw, 865px\" \/><\/a><em>Figure 4: LinkedIn has sent a mail with password-reset token\/link.<\/em><\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-284 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/5.png\" alt=\"5\" width=\"865\" height=\"368\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/5.png 865w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/5-300x128.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/5-768x327.png 768w\" sizes=\"(max-width: 865px) 100vw, 865px\" \/><\/a><\/p>\n<p style=\"text-align: center\">\u00a0<em>Figure 5: Attacker can set new password and also reset all other recovery options and compromise the account completely.<\/em><\/p>\n<p style=\"text-align: left\">There was one more severe issue observed here.<\/p>\n<p>\u00a0<b><span style=\"color: #b40404\">User cannot remove arbitrary Email address from LinkedIn account, which was added by attacker.<\/span><\/b><\/p>\n<p style=\"text-align: justify\">If victim comes to know that he\/she has not added the new Email address and wants to remove it then also he\/she cannot do it. Isn\u2019t it more shocking???<\/p>\n<p style=\"text-align: justify\">Application does not remove newly added Email address and force user\/victim to first complete the confirmation by log in to the account.<\/p>\n<p style=\"text-align: justify\">Now the biggest question here is how can victim user will confirm this new Email address, which he\/she has not added as well as has no access to that Email account also.<\/p>\n<p style=\"text-align: justify\">If user tries to remove this Email address from LinkedIn, application shows following message that the address has been removed but in reality IT WILL NOT. If user checks the email settings she will found that the Email address has not gone. So victim is helpless here.<\/p>\n<p><a href=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-283 size-full\" src=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/7.png\" alt=\"Secure Your Account\" width=\"865\" height=\"517\" srcset=\"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/7.png 865w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/7-300x179.png 300w, https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/7-768x459.png 768w\" sizes=\"(max-width: 865px) 100vw, 865px\" \/><\/a><\/p>\n<p style=\"text-align: center\">\u00a0<em>Figure 6: Application shows that the newly added Email has gone but it does not remove it in reality.<\/em><\/p>\n<p>\u00a0<b><span style=\"color: #b40404\">Insecure Password Reset Module<\/span><\/b><\/p>\n<p style=\"text-align: justify\">LinkedIn enables the password-reset link for 24 hours. Ideally as a best practice, on clicking the password reset link and successfully resetting the password, the link should become inactive. But even after resetting the password this link will be valid for 24 hours, which is dangerous in case of the account is compromised, and attacker has the password-reset link on his Email address.<\/p>\n<p style=\"text-align: justify\">This means if user comes to know that his account might be compromised with other Email address and if he\/she changes the password, still attacker can use the password-reset link to change the password again and take control of it.<\/p>\n<p style=\"text-align: justify\">When contacted LinkedIn they have accepted these issues and mitigated them. Few more issues are getting patched. Till then happy Social Networking.<\/p>\n<p>Read it on <a title=\"LinkedIn User Account Handling\" href=\"http:\/\/packetstormsecurity.com\/files\/127659\/LinkedIn-User-Account-Handling.html\" target=\"_blank\" rel=\"noopener noreferrer\">packet storm\u00a0<\/a><\/p>\n<p>Written By,<\/p>\n<p><em>Attack &amp; PenTest Team,<\/em><\/p>\n<p><em>Varutra Consulting<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>LinkedIn is a business-oriented Social networking service. One purpose of the sites is to allow registered users to maintain a list of contact details of&#8230;<\/p>\n","protected":false},"author":3,"featured_media":3386,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[140,261,266,267,57,272],"tags":[56],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.6.3 - aioseo.com -->\n\t\t<meta name=\"description\" content=\"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.\" \/>\n\t\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t\t<link rel=\"canonical\" href=\"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.6.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Varutra Consulting\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"How secure is my LinkedIn account ? | Varutra Consulting\" \/>\n\t\t<meta property=\"og:description\" content=\"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1300\" \/>\n\t\t<meta property=\"og:image:height\" content=\"750\" \/>\n\t\t<meta property=\"article:section\" content=\"Case Study\" \/>\n\t\t<meta property=\"article:tag\" content=\"linkedin account compromise insecure password reset\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2014-04-30T13:40:33+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-03-24T09:58:06+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"How secure is my LinkedIn account ? | Varutra Consulting\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"kalpadmin\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#article\",\"name\":\"How secure is my LinkedIn account ? | Varutra Consulting\",\"headline\":\"How secure is my LinkedIn account ?\",\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2014\\\/04\\\/LinkedIN-Copy.jpg\",\"width\":1300,\"height\":750,\"caption\":\"LinkedIN - Copy\"},\"datePublished\":\"2014-04-30T13:40:33+05:30\",\"dateModified\":\"2023-03-24T15:28:06+05:30\",\"inLanguage\":\"en-US\",\"commentCount\":3,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#webpage\"},\"articleSection\":\"Case Study, Ethical Hacking, Security Advisory, Social Networking Security, Vulnerability Disclosure, Web Application Security, LinkedIn Account Compromise Insecure Password Reset\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"nextItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#listItem\"},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#listItem\",\"position\":2,\"name\":\"How secure is my LinkedIn account ?\",\"previousItem\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#listItem\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\",\"name\":\"Varutra\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Varutra-Found-e1612984024606.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/\",\"name\":\"kalpadmin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"kalpadmin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#webpage\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/\",\"name\":\"How secure is my LinkedIn account ? | Varutra Consulting\",\"description\":\"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/author\\\/admin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/wp-content\\\/uploads\\\/2014\\\/04\\\/LinkedIN-Copy.jpg\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#mainImage\",\"width\":1300,\"height\":750,\"caption\":\"LinkedIN - Copy\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/how-secure-is-my-linkedin-account\\\/#mainImage\"},\"datePublished\":\"2014-04-30T13:40:33+05:30\",\"dateModified\":\"2023-03-24T15:28:06+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#website\",\"url\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/\",\"name\":\"Varutra Consulting\",\"description\":\"Secure your digital world with our Cybersecurity services.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.varutra.com\\\/varutravrt3\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>How secure is my LinkedIn account ? | Varutra Consulting<\/title>\n\n","aioseo_head_json":{"title":"How secure is my LinkedIn account ? | Varutra Consulting","description":"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.","canonical_url":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"og:locale":"en_US","og:site_name":"Varutra Consulting","og:type":"article","og:title":"How secure is my LinkedIn account ? | Varutra Consulting","og:description":"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.","og:url":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/","og:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","og:image:secure_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","og:image:width":"1300","og:image:height":"750","article:section":"Case Study","article:tag":["linkedin account compromise insecure password reset"],"article:published_time":"2014-04-30T13:40:33+00:00","article:modified_time":"2023-03-24T09:58:06+00:00","twitter:card":"summary_large_image","twitter:title":"How secure is my LinkedIn account ? | Varutra Consulting","twitter:description":"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.","twitter:image":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","twitter:label1":"Written by","twitter:data1":"kalpadmin","twitter:label2":"Est. reading time","twitter:data2":"6 minutes","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#article","name":"How secure is my LinkedIn account ? | Varutra Consulting","headline":"How secure is my LinkedIn account ?","author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","width":1300,"height":750,"caption":"LinkedIN - Copy"},"datePublished":"2014-04-30T13:40:33+05:30","dateModified":"2023-03-24T15:28:06+05:30","inLanguage":"en-US","commentCount":3,"mainEntityOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#webpage"},"isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#webpage"},"articleSection":"Case Study, Ethical Hacking, Security Advisory, Social Networking Security, Vulnerability Disclosure, Web Application Security, LinkedIn Account Compromise Insecure Password Reset"},{"@type":"BreadcrumbList","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/#listItem","position":1,"name":"Home","item":"https:\/\/www.varutra.com\/varutravrt3\/","nextItem":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#listItem"},{"@type":"ListItem","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#listItem","position":2,"name":"How secure is my LinkedIn account ?","previousItem":"https:\/\/www.varutra.com\/varutravrt3\/#listItem"}]},{"@type":"Organization","@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization","name":"Varutra","url":"https:\/\/www.varutra.com\/varutravrt3\/","logo":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2021\/11\/Varutra-Found-e1612984024606.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#organizationLogo"},"image":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author","url":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/","name":"kalpadmin","image":{"@type":"ImageObject","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/d69b4bf504d3e2e3c6ad0c424e16bcb2?s=96&d=mm&r=g","width":96,"height":96,"caption":"kalpadmin"}},{"@type":"WebPage","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#webpage","url":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/","name":"How secure is my LinkedIn account ? | Varutra Consulting","description":"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#website"},"breadcrumb":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#breadcrumblist"},"author":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"creator":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/author\/admin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.varutra.com\/varutravrt3\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#mainImage","width":1300,"height":750,"caption":"LinkedIN - Copy"},"primaryImageOfPage":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/#mainImage"},"datePublished":"2014-04-30T13:40:33+05:30","dateModified":"2023-03-24T15:28:06+05:30"},{"@type":"WebSite","@id":"https:\/\/www.varutra.com\/varutravrt3\/#website","url":"https:\/\/www.varutra.com\/varutravrt3\/","name":"Varutra Consulting","description":"Secure your digital world with our Cybersecurity services.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.varutra.com\/varutravrt3\/#organization"}}]}},"aioseo_meta_data":{"post_id":"281","title":"How secure is my LinkedIn account ? | Varutra Consulting","description":"Is your Linkedin account is secure? Read some interesting but dangerous security issues found on Linkedin and discover what you need to do to manage security.","keywords":[],"keyphrases":"{\"focus\":{\"keyphrase\":\"Secure\",\"score\":88,\"analysis\":{\"keyphraseInTitle\":{\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseInDescription\":{\"score\":9,\"maxScore\":9,\"error\":0},\"keyphraseLength\":{\"score\":9,\"maxScore\":9,\"error\":0,\"length\":1},\"keyphraseInURL\":{\"score\":5,\"maxScore\":5,\"error\":0},\"keyphraseInIntroduction\":{\"score\":3,\"maxScore\":9,\"error\":1},\"keyphraseInSubHeadings\":[],\"keyphraseInImageAlt\":{\"score\":9,\"maxScore\":9,\"error\":0}}},\"additional\":[]}","primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"featured","og_image_url":"https:\/\/www.varutra.com\/wp-content\/uploads\/2014\/04\/LinkedIN-Copy.jpg","og_image_width":"1300","og_image_height":"750","og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"Case Study","og_article_tags":[],"twitter_use_og":true,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":"{\"article\":{\"articleType\":\"BlogPosting\"},\"course\":{\"name\":\"\",\"description\":\"\",\"provider\":\"\"},\"faq\":{\"pages\":[]},\"product\":{\"reviews\":[]},\"recipe\":{\"ingredients\":[],\"instructions\":[],\"keywords\":[]},\"software\":{\"reviews\":[],\"operatingSystems\":[]},\"webPage\":{\"webPageType\":\"WebPage\"}}","pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"open_ai":null,"created":"2021-10-27 15:18:10","updated":"2023-03-24 10:13:03"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.varutra.com\/varutravrt3\/category\/case-study\/\" title=\"Case Study\">Case Study<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tHow secure is my LinkedIn account ?\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.varutra.com\/varutravrt3"},{"label":"Case Study","link":"https:\/\/www.varutra.com\/varutravrt3\/category\/case-study\/"},{"label":"How secure is my LinkedIn account ?","link":"https:\/\/www.varutra.com\/varutravrt3\/how-secure-is-my-linkedin-account\/"}],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/281"}],"collection":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/comments?post=281"}],"version-history":[{"count":6,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/281\/revisions"}],"predecessor-version":[{"id":21233,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/posts\/281\/revisions\/21233"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media\/3386"}],"wp:attachment":[{"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/media?parent=281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/categories?post=281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.varutra.com\/varutravrt3\/wp-json\/wp\/v2\/tags?post=281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}