Raise your hand if you have an account on Facebook, Myspace, or any other social networking service? That's what I thought. Just about everyone. And, if you're anything like me and my group of friends then you have tons of nifty little applications on your profile. But are you really safe?
A group of computer researchers have developed an application for Facebook that will allow them to exploit any user who installs the application, without the users knowledge. The idea behind the exploit is to show a security flaw in social networks that could allow hackers to control the users of the social networks and utilize their computers for their own ends.
The researchers' application was the photo of the day application supposedly from National Geographic. Basically, once a use installed the application, they would be able to a daily picture from National Geographic - and they downloaded 3 pictures from another website without knowing about it.
The idea behind this particular attack (targeted at the researchers own servers) was to get as many people into the application as possible, and then flood the website that was being downloaded from. This is a very basic attack used for demonstration purposes, but if utilized by a malicious hacker, it could be much worse. And whats more, once the application was installed, the user was forced into the attack again every time they logged on - without their knowledge of course.
So the next time you find a nice little third party Facebook application, just remember that you could be getting recruited into a h4x07z cyber army... dun dun dunnnnn...
view the original Wired article.
Showing posts with label security flaws. Show all posts
Showing posts with label security flaws. Show all posts
Sunday, September 7, 2008
Saturday, September 6, 2008
Apple iPhone - A hack waiting to happen
As many of you probably know, Apple has a new phone out - the omnipotent iPhone. They've certainly spent enough money on their advertising to show everyone their newest brain child. It's supposed to be "twice as fast, half the price". Which of course is false, as this pamphlet leaked by Verizon shows, they're are quite a few things that it seems Apple may have been trying to cover up.
Now, I could care less about most aspects of the phone on that list (not that I'm going to buy one soon anyway - if I had that much money lying around, I'd be buying something much better than a cell phone all dressed up in pretty clothes), but there is one very interesting thing about the phone I found out today thanks to the Register. Apparently, the iPhones security isn't quite up to date either.
What does THAT mean you may ask. Well, that means that it is quite easy to hack the iPhone 3G. And, being the Hack Hut, we'll let you know just how to do it. Apparently, it is possible to gain access to a password protected and locked iPhone's 'favorites' section without the passcode. By simply tapping the "emergency call" button from the passcode screen, and then double-tapping the "home" button, it is possible to bypass the passcode portion of the iPhone. From the favorites, you can gain access to many other portions of the iPhone, such as the browser screen, the e-mail client screen, or the address book.
If you have an iPhone, I wouldn't be too worried yet. Before you sue the pants off of Apple for selling you a phone with faulty security features, you should know that this hack DOES NOT work on all iPhone 3G's. The iPhone must have a certain software version (which I will not be disclosing). Also, if you do happen to have the faulty software, I would bet my life on the fact that Apple will come up with a firmware update to protect the vulnerable phones from hackers, especially since they are trying to promote the iPhone as a business-friendly phone. Not when it's that vulnerable!
As with all other "hacking" tutorials you may find on this blog, if used improperly the information in this post can be illegal. You should only try this on your OWN iPhone, or get the permission of the owner of an iPhone. But if you give it a shot legally, please let us know how it went! Did it work for you?
Now, I could care less about most aspects of the phone on that list (not that I'm going to buy one soon anyway - if I had that much money lying around, I'd be buying something much better than a cell phone all dressed up in pretty clothes), but there is one very interesting thing about the phone I found out today thanks to the Register. Apparently, the iPhones security isn't quite up to date either.
What does THAT mean you may ask. Well, that means that it is quite easy to hack the iPhone 3G. And, being the Hack Hut, we'll let you know just how to do it. Apparently, it is possible to gain access to a password protected and locked iPhone's 'favorites' section without the passcode. By simply tapping the "emergency call" button from the passcode screen, and then double-tapping the "home" button, it is possible to bypass the passcode portion of the iPhone. From the favorites, you can gain access to many other portions of the iPhone, such as the browser screen, the e-mail client screen, or the address book.
If you have an iPhone, I wouldn't be too worried yet. Before you sue the pants off of Apple for selling you a phone with faulty security features, you should know that this hack DOES NOT work on all iPhone 3G's. The iPhone must have a certain software version (which I will not be disclosing). Also, if you do happen to have the faulty software, I would bet my life on the fact that Apple will come up with a firmware update to protect the vulnerable phones from hackers, especially since they are trying to promote the iPhone as a business-friendly phone. Not when it's that vulnerable!
As with all other "hacking" tutorials you may find on this blog, if used improperly the information in this post can be illegal. You should only try this on your OWN iPhone, or get the permission of the owner of an iPhone. But if you give it a shot legally, please let us know how it went! Did it work for you?
Subscribe to:
Posts (Atom)