30.10.2013 16:35 Uhr, Quelle: Macworld UK

Many iOS apps found open to hijacking on public Wi-Fi

An Israeli startup has discovered a vulnerability in many iOS apps that attackers could secretly exploit over a public Wi-Fi network to send their own data to an Apple iPhone or iPad.[Apple's iOS 7 gives security pros a lot to like]Skycure discovered the "coding pitfall," which it calls HTTP Request Hijacking, while investigating a bug in its mobile security product. Further investigation uncovered the widespread flaw that could be used to send malicious links or fake news to a news app.The exploitation would start with a man-in-the-middle attack over a public Wi-Fi network. An attacker would first have to gain access to the HTTP traffic between the app and the server that receives its requests and sends back data.When the app asks for information, the attacker would have to capture the request and return what is called a 301 redirection that would essentially tell the app to ge

Weiterlesen bei Macworld UK

Digg del.icio.us Facebook email MySpace Technorati Twitter

JustMac.info © Thomas Lohner - Impressum - Datenschutz