games

banggood 18% OFF Magic Cabin Hat Country LLC HearthSong 15% Off Your First Purchase! Code: WELCOME15 Stacy Adams

Friday, April 6, 2012

Facebook ID theft threat impacts all iPhones, Dropbox - CNET

facebook - Google News
Google News
Facebook ID theft threat impacts all iPhones, Dropbox - CNET
Apr 6th 2012, 15:22

Although Facebook says that a vulnerability allowing someone to access another user's account only impacts jailbroken iPhones, two reports say that's not the case.

U.K. app developer Gareth Wright and The Next Web have separately confirmed that the issue, which originates from Facebook's iPhone application, actually impacts any iPhone, and not just those that have been jailbroken.

Wright announced his findings earlier this week. He claims that Facebook's iPhone application includes a vulnerability that fails to encrypt log-on credentials when a user accesses the social network from its mobile application. Wright said that he then came across a Facebook access token in the Draw Something game, which he copied, and after using the Facebook Query Language, extracted the information contained within.

"Sure enough, I could pull back pretty much any information from my Facebook account," he wrote. He went on to say that the app's property list contained all the information needed to allow someone else to access a person's Facebook account, send private messages, and do whatever else they wanted on the site.

In a statement to CNET yesterday, Facebook tossed the issue aside, saying that it only impacts jailbroken devices.

"Facebook's iOS and Android applications are only intended for use with the manufacture provided operating system, and access tokens are only vulnerable if they have modified their mobile OS (i.e. jailbroken iOS or modded Android) or have granted a malicious actor access to the physical device," the social network said in a statement.

In addition to Wright, The Next Web, which recreated the hack, confirmed that it "does not require a jailbreak."

But the blog also went one step further and found that Dropbox also suffers from the same flaw, leaving the application open to a plist hack.

"We copied the .plist from one device with the app installed and logged in, over to another which had a fresh installation of Dropbox on it," The Next Web said. "The profile copied and it worked seamlessly, as if we had logged on ourselves, which we had not."

One other interesting tidbit from Dropbox's findings: the hack will even work on an iPhone protected by a passcode.

Neither Facebook nor Dropbox immediately responded to CNET's request for comment on these latest developments.

This entry passed through the Full-Text RSS service — if this is your content and you're reading it on someone else's site, please read the FAQ at fivefilters.org/content-only/faq.php#publishers. Five Filters recommends: Donate to Wikileaks.

You are receiving this email because you subscribed to this feed at blogtrottr.com.

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

No comments:

Post a Comment