Question: Can accounts be stolen by bots?

darknessSCENT

Newbie
Joined
Jan 30, 2015
Messages
27
Reaction score
3
Hi,
I was wondering if sites like Instaranker, Instajool etc. could steal your accounts if they wanted to, since you have to enter your Instagram username and password. You have to deactivate your two-factor authentification for them and I'm kinda afraid to do so since then they could take over my account with no problem. Any advice?
 
It depends - Some services only store your login session, which means they don't have access to your password.

Also, there are many ways to recover your account. And if all fails, you can always report your account hacked and submit the required documents to ig to recover your account.
 
Absolutely if they store your login details

Apps on Facebook are riddled with apps that you allow to post as you etc
 
It depends - Some services only store your login session, which means they don't have access to your password.

Also, there are many ways to recover your account. And if all fails, you can always report your account hacked and submit the required documents to ig to recover your account.

Absolutely if they store your login details

Apps on Facebook are riddled with apps that you allow to post as you etc
How can I find out if they're storing my password or not? I'm planning to settle with InstaRanker but I need assurance that they're legit.
 
since you have to enter your Instagram username and password. You have to deactivate your two-factor authentification for them

And you're still wondering? YES this is a thousand red flags. OAuth or GTFO.
 
A bot I use is able to use my account without needing the pin from 2-factor auth. I get smsses frequently yet somehow it's able to keep running on its own. Just thought this was interesting. I know it's the bot triggering the smsses because it's logged. Maybe this lets IG see who is using bots?
 
Two answers to questions asked above:

1) If a program asks you for your username and password, it's possible that the program administrators are caching/saving/hording your password, but I don't think it's likely or at the very least would be very sloppy coding work if they did so because they ought to be concerned that your pw could be stolen from them if they were hacked in turn, which would surely result in a greater loss to them if they are are a going concern (expecting to be in business for the long run) than anything they could gain by "stealing" your account.

In short, yes, it may be possible that your password could be being saved without your knowledge or consent. I don't think it's likely, though, and to address any concerns you have, read on...

2) Second, it's true that in many cases two-factor authentication has to be disabled for third-party programs including bots to be able to log into an account, but you can reenable two-factor authentcation after logging in. So long as Instagram does not think the third party program has logged out it won't prompt you (or the program) for the second factor. Two-factor auth is a very good thing to enable whenever possible, and if you do tha you help avoid the risk of losing an account by #1 above.

You may notice though that you get prompted for SMS or email verifications, though, which may be bot or proxy related. If you persistently get asked for SMS or email verification, look at your activity and try to think if it's maybe excessive or suspicious, and if not, it may be an issue with the bot or your proxy that is appearing suspicious -- includng, possibly, a hacking attempt.

I'd be more concerned about not being able to use two-factor auth, if that's an issue, than wondering if a program is saving my password without my knowledge, as really almost anything can be hacked if one is determined enough -- a bot program on my computer, a bot web service, or IG itself.
 
Last edited:
2) Second, it's true that in many cases two-factor authentication has to be disabled for third-party programs including bots to be able to log into an account, but you can reenable two-factor authentcation after logging in. So long as Instagram does not think the third party program has logged out it won't prompt you (or the program) for the second factor. Two-factor auth is a very good thing to enable whenever possible, and if you do tha you help avoid the risk of losing an account by #1 above.

You may notice though that you get prompted for SMS or email verifications, though, which may be bot or proxy related. If you persistently get asked for SMS or email verification, look at your activity and try to think if it's maybe excessive or suspicious, and if not, it may be an issue with the bot or your proxy that is appearing suspicious -- includng, possibly, a hacking attempt.

I'd be more concerned about not being able to use two-factor auth, if that's an issue, than wondering if a program is saving my password without my knowledge, as really almost anything can be hacked if one is determined enough -- a bot program on my computer, a bot web service, or IG itself.
Thank you very much for the intricate and helpful answer. The thing is, I tried using InstaRanker and disabled my two-factor auth when adding my account (as prompted), but re-activated it right after. When it started its activity (likes only), I got an IG text message with a code every time it liked something (it still worked).. What could that mean?

I wish I found something like Instagress again, every single similar alternative I've found had some weird bugs that would make it a nuisance to use. InstaRanker is the closest thing I've found but it's got that issue, damn.
 
Thank you very much for the intricate and helpful answer. The thing is, I tried using InstaRanker and disabled my two-factor auth when adding my account (as prompted), but re-activated it right after. When it started its activity (likes only), I got an IG text message with a code every time it liked something (it still worked).. What could that mean?

I wish I found something like Instagress again, every single similar alternative I've found had some weird bugs that would make it a nuisance to use. InstaRanker is the closest thing I've found but it's got that issue, damn.

You're welcome. :)

You wrote "I got an IG text message with a code every time it liked something (it still worked)" Sounds like it was a verification message, like one sent from IG website while trying to login where IG tsays "looks like something suspicious was happening with your account" and then you are asked to be sent a code by SMS or email. If you were on the IG website trying to log in you might see that message as I just typed it here.

Web-based bot services usually tell the user if they get a message like that to try to log into their account online or on the app and do whatever IG asks to verify the account or action. You might ask support for help with that, of course, I don't know exactly what they would need to do to authenticate their access or actions as authorized or legit.

I don't know of a web-based bot service that has ever asked users like me for that verification code or repeatedly provoked SMS verification. I'm not saying you never would be asked or never should give the code out to app support, only that when verification actions are asked for either the bot just tries to handle them theirselves or tells me to go to the app / bot or IG website and log in and do whatever is being asked for verification.

For clarification of course send the app / bot support people a detailed message asking for help. Their bot may be trying to handle error messages and not doing so very well, or they may be using proxies that are not working well and provoking verification actions. They may say you should use more conservative settings, and maybe you should, there's many interacting factors that can provoke verification messages like this. Normally the bot will notify you though somehow that verification is being prompted by IG because this kind of verification requires access to the account's contact email or phone which the bot won't have access to, only you would have access to that email or phone number.

If nothing else, you might try again doing whatever provokes the SMS message and at the same time look at a phone or tablet logged into the IG app and not doing likes or follow/unfollow/DMs, just try changng screens or viewing accounts, and see if you get a message asking if it was you logging into some other location. If you get that message, you want to say "yes its me" if you know the action was authorized by you. Don't -- do not -- say "it wasn't me" unless you really want to ban or block the access attempt, which may ban or block the bot from using that unfamiliar / distant / foreign IP address & location from being used by your account.

It should be safe to simply browse or refresh a screen on the app while the bot tries to do actions on your account so long as you aren't doing likes/follows/etc at the same time you are trying to log ino or do actions through the bot. That would be similar to a user being logged into IG through a phone connected by mobile data while being logged into a tablet on residental WiFi, as I'll describe in the next couple paragraphs.

I would tell the app, if it were me and I wanted to say the access was legit, that the login was "me" meaning authorized by me. If it seems like the location the app says you are in is absurdly far away, like in another country or thousands of miles away, I might still say "yes" if by timing I knew the access came from an app or bot I was using, but I would definatly tell the app/bot support that it's saying you are logging in from some location suspiciously far away and they may want to use a different proxy location or if you can change your proxy location / choice you may want to do so.

That's how IG prompts users if they say try logging into a phone using mobile data which may show a completely different IP and location which may be hundreds of miles away while a tablet -- for example -- running off residential WiFI is logged into an IP address that is physically right where you are. If you can do that successfully and say the action was authorized by you, that may be enough to get out of these verification prompts & SMSs at least for now.
 
Last edited:
Back
Top