21 May, 2013
News Channel – Mind Processors
times-of-indiabbc-news
cnet-newsyahoo-newsApple-newsgoogle-newsmsnbc-newscnn-newsfox-news
Skip to content
  • Home
  • Technology
    • Gadgets
    • Hardware
    • Software
    • Innovations
    • Linux
    • Open Source
    • Science
    • Telecom
    • Wireless
  • Business Tech
    • Eco-Bizz
    • Global Leaders
      • Apple
      • Google
      • Intel
      • Microsoft
      • Yahoo
    • Research
    • Politics & Law
  • Mind Processors
  • Gaming
    • News & Features
    • Playstation
    • X-Box
    • PC
    • Reviews
  • Security
  • Web
    • Social Media
  • Video
  • More
  • Subscribe
Follow @mindprocessors
Web Hosting Mindprocessors

Facebook ID theft threat impacts all iPhones, Dropbox

Posted on April 7, 2012 by Source: news.cnet.com
Tweet

The Next Web, re-creating a U.K. developer’s hack, says it has confirmed his findings: Facebook vulnerability affects all iPhones, not just jailbroken handsets.

Although Facebook says that a vulnerability allowing someone to access another user’s account only affects jailbroken iPhones, two reports say that’s not the case.

U.K. app developer Gareth Wright and The Next Web have separately confirmed that the issue, which originates from Facebook’s iPhone application, actually affects any iPhone, and not just those that have been jailbroken.

facebooklockedWright announced his findings earlier this week. He claims that Facebook’s iPhone application includes a vulnerability that fails to encrypt log-on credentials when a user accesses the social network from its mobile application. Wright said that he then came across a Facebook access token in the Draw Something game, which he copied, and after using the Facebook Query Language, extracted the information contained within.

“Sure enough, I could pull back pretty much any information from my Facebook account,” he wrote. He went on to say that the app’s property list contained all the information needed to allow someone else to access a person’s Facebook account, send private messages, and do whatever else they wanted on the site.

In a statement to CNET yesterday, Facebook said the issue only affects jailbroken devices.

“Facebook’s iOS and Android applications are only intended for use with the manufacture provided operating system, and access tokens are only vulnerable if they have modified their mobile OS (i.e. jailbroken iOS or modded Android) or have granted a malicious actor access to the physical device,” the social network said in a statement.

In addition to Wright, The Next Web, which re-created the hack, confirmed that it “does not require a jailbreak.”
But the blog also went one step further and found that Dropbox also suffers from the same flaw, leaving the application open to a so-called “plist,” or property list, hack.

“We copied the .plist from one device with the app installed and logged in, over to another which had a fresh installation of Dropbox on it,” The Next Web said. “The profile copied and it worked seamlessly, as if we had logged on ourselves, which we had not.”

One other interesting tidbit from the findings on Dropbox: the hack will even work on an iPhone protected by a passcode.
Neither Facebook nor Dropbox immediately responded to CNET’s request for comment on these latest developments.

Related Post

  • iPhone under assault from big-screen rivals
  • The Internet is a surveillance state
  • What Facebook Likes reveal about you
  • Showing Broader Ambitions, Dropbox Acquires Mailbox
  • Hands-off with the Samsung Galaxy S IV
  • Posted in Facebook and tagged Android, Dropbox, Facebook, iOS, Iphones, Mobile Application, social network.Bookmark this post.

    One Response to Facebook ID theft threat impacts all iPhones, Dropbox

    1. dirt bike games says:
      April 7, 2012 at 6:27 pm

      Hi there, I discovered your site by the use of Google at the same time as searching for a similar matter, your site got here up, it appears great. I’ve bookmarked to my favourites|added to bookmarks.

    CompUSA
    • Recent Posts

      • Planck satellite: Esa to release maps of ancient light
      • Nvidia unveils virtual graphics server in push beyond PCs
      • Google Maps climbs world’s tallest mountains
      • Congress hears options for asteroid defense: Pay now or pray later
      • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Subscribe News


    • Recent Comments

      • Kirk on Groupon launches credit card payment business to compete with Paypal
      • Green Bay Packers on Steve Jobs better career role model than Obama: Survey
      • MBT Women Shoes on HR checking candidates’ background on FB, Twitter, Google
      • sexleksaker on Facebook suspends photo tag tool in Europe
      • cbn grinding wheels on Aquarium releases 655-pound sea turtle off Cape Cod after treatment
    • Archives

      • March 2013
      • February 2013
      • January 2013
      • December 2012
      • November 2012
      • October 2012
      • September 2012
      • August 2012
      • July 2012
      • June 2012
      • May 2012
      • April 2012
      • March 2012
      • February 2012
      • January 2012
      • December 2011
      • November 2011
      • October 2011
      • September 2011
      • August 2011
    • Tags

      Amazon American Android Anonymous Apple AT&T BlackBerry California China computer Earth email Europe Facebook Gmail Google+ India Internet iOS iPad iPhone Japan London Mark Zuckerberg Microsoft Microsoft' mobile NASA New York Samsung smartphone smartphones social network Software Sony space Steve Jobs tablet tablets Twitter U.S. Windows Windows 8 Yahoo YouTube
    Latest News:-
    • Planck satellite: Esa to release maps of ancient light
    • Nvidia unveils virtual graphics server in push beyond PCs
    • Google Maps climbs world’s tallest mountains
    • Congress hears options for asteroid defense: Pay now or pray later
    • New Lizard Species Look Like Evil Dinosaur Hybrids
    • Curiosity breaks rock to reveal dazzling white interior

    Categories

    • - Business Tech
    • - Security
    • - Technology
    • - Gadgets
    • - Gaming
    • - Global Leaders
    • - Web

    Official Connections

    • - TheQueries.com
    • - Blog.MindProcessors.com
    • - Forum.MindProcessors.com
    • - Blog.AbhilashShukla.info
    • - MindProcessors.com
    • - Web.MindProcessors.com

    Disclaimer

    • Our news channel is intended to provide quality news from top online news providing companies. This channel is a collection of quality and best news at one place. The news and the logos of other providers are completely their own property.

    Where else we are

    • - Connect with us on FaceBook
    • - Follow us on Twitter
    • - Subscribe to our Youtube Channel
    • - Connect via LinkedIn
    • - Find us on Google+
    © 2011 Mind Processors Technologies, All rights reserved.
    • About us
    • Contact Us
    • Careers
    • Privacy Policy
    • Terms & Conditions
    • Sitemap