76 Popular Apps Vulnerable to Data Interception, Warns iOS Security Researcher - اخبار التقنية

ryan

العودة   ryan > اخبار التقنية

إضافة رد
 
أدوات الموضوع انواع عرض الموضوع
  #1  
قديم 02-07-2017, 03:40 PM
ahlam1399 ahlam1399 غير متواجد حالياً
Administrator
 
تاريخ التسجيل: Sep 2012
المشاركات: 3,727,761
افتراضي 76 Popular Apps Vulnerable to Data Interception, Warns iOS Security Researcher

Popular Apps Vulnerable Data Interception,At least 76 Popular iOS Apps have been found to be Vulnerable to Data inception, according to a report from a Security expert.

The discovery was made by app binary code scanning service verify.ly and published in a Medium post by Sudo Security Group CEO Will Strafach, who revealed that the Apps failed to make use of the Transport Layer Security protocol.

The TLS protocol secures communication between client and server. Without the protection, the Apps are susceptible to Data interception by an attacker with access to custom hardware such as modified smartphone, which can be used to initiate TLS certificate injection attacks. The interception is possible regardless of whether the developers chose to use Apple networking Security feature, App Transport Security.
The truth of the matter is, this sort of attack can be conducted by any party within Wi-Fi range of your device while it is in use. This can be anywhere in public, or even within your home if an attacker can get within close range.

There is ** possible fix to be made on Apple's side, because if they were to override this functionality in attempt to block this Security issue, it would actually make some iOS applications less secure as they would **t be able to utilize certificate pinning for their connections, and they could **t trust otherwise untrusted certificates which may be required for intranet connections within an enterprise using an in-house PKI. Therefore, the onus rests solely on app developers themselves to ensure their Apps are **t vulnerable.
Apps in the Vulnerable list included a number of Popular downloads like third-party Snapchat apps, the official app for Vice News, and banking Apps for banks based in Puerto Rico and Libya.

Strafach sorted the 76 Apps into low, medium, and high risk categories, and says he is reaching out to developers to fix the problems before disclosing the most high-risk Apps in the list. According to Strafach, more than 18,000,000 downloads of the Vulnerable app versions have been downloaded from the App Store.

Until the issues are dealt with, Strafach advises users of the Apps to avoid accessing them over Wi-Fi, as it's harder to exploit the vulnerabilities over a cellular network.

Tags: App Store, security

Discuss this article in our forums

Popular Apps Vulnerable Data Interception, Popular Apps Vulnerable Data Interception,
Popular Apps Vulnerable Data Interception,

أكثر...

كلمات البحث

العاب ، برامج ، سيارات ، هاكات ، استايلات


رد مع اقتباس
إضافة رد


تعليمات المشاركة
لا تستطيع إضافة مواضيع جديدة
لا تستطيع الرد على المواضيع
لا تستطيع إرفاق ملفات
لا تستطيع تعديل مشاركاتك

BB code is متاحة
كود [IMG] متاحة
كود HTML معطلة

الانتقال السريع


الساعة الآن 03:15 PM


Powered by vBulletin® Copyright ©2000 - 2026, Jelsoft Enterprises Ltd. TranZ By Almuhajir
This Forum used Arshfny Mod by islam servant