![]() |
|
|||||||
|
|
أدوات الموضوع | انواع عرض الموضوع |
|
#1
|
|||
|
|||
At least 76 Popular iOS Apps have been found to be Vulnerable to Data inception, according to a report from a Security expert.The discovery was made by app binary code scanning service verify.ly and published in a Medium post by Sudo Security Group CEO Will Strafach, who revealed that the Apps failed to make use of the Transport Layer Security protocol. The TLS protocol secures communication between client and server. Without the protection, the Apps are susceptible to Data interception by an attacker with access to custom hardware such as modified smartphone, which can be used to initiate TLS certificate injection attacks. The interception is possible regardless of whether the developers chose to use Apple networking Security feature, App Transport Security. The truth of the matter is, this sort of attack can be conducted by any party within Wi-Fi range of your device while it is in use. This can be anywhere in public, or even within your home if an attacker can get within close range.Apps in the Vulnerable list included a number of Popular downloads like third-party Snapchat apps, the official app for Vice News, and banking Apps for banks based in Puerto Rico and Libya. Strafach sorted the 76 Apps into low, medium, and high risk categories, and says he is reaching out to developers to fix the problems before disclosing the most high-risk Apps in the list. According to Strafach, more than 18,000,000 downloads of the Vulnerable app versions have been downloaded from the App Store. Until the issues are dealt with, Strafach advises users of the Apps to avoid accessing them over Wi-Fi, as it's harder to exploit the vulnerabilities over a cellular network. Tags: App Store, security Discuss this article in our forums أكثر... ??????? ??????: 76 Popular Apps Vulnerable to Data Interception, Warns iOS Security Researcher || ??????: ahlam1399 || ??????: اسم منتداك
|
|
|