GE Investigations Blog

News and interesting articles from around the world.

Facebook ID theft threat impacts all iPhones, Dropbox

 Articles of Interest, Crimes & Criminal Activity (Organized Crime, Narcotics, Predators, Cyber Crime, Cyber Stalking, UnSolved), Firearms, Weapons & Personal Safety, National security, Terrorism, Cyber Terrorism & Related Crimes, Social Media, Technology & Digital Security  No Responses »
Apr 112012
 

 

Facebook ID theft threat impacts all iPhones, Dropbox

The Next Web, re-creating a U.K. developer’s hack, says it has confirmed his findings: Facebook vulnerability affects all iPhones, not just jailbroken handsets.

 

 

CNET News

by Don Reisinger
April 6, 2012 

 

Although Facebook says that a vulnerability allowing someone to access another user’s account only affects jailbroken iPhones, two reports say that’s not the case.

U.K. app developer Gareth Wright and The Next Web have separately confirmed that the issue, which originates from Facebook’s iPhone application, actually affects any iPhone, and not just those that have been jailbroken.

Wright announced his findings earlier this week. He claims that Facebook’s iPhone application includes a vulnerability that fails to encrypt log-on credentials when a user accesses the social network from its mobile application. Wright said that he then came across a Facebook access token in the Draw Something game, which he copied, and after using the Facebook Query Language, extracted the information contained within.

“Sure enough, I could pull back pretty much any information from my Facebook account,” he wrote. He went on to say that the app’s property list contained all the information needed to allow someone else to access a person’s Facebook account, send private messages, and do whatever else they wanted on the site.

In a statement to CNET yesterday, Facebook said the issue only affects jailbroken devices.

“Facebook’s iOS and Android applications are only intended for use with the manufacture provided operating system, and access tokens are only vulnerable if they have modified their mobile OS (i.e. jailbroken iOS or modded Android) or have granted a malicious actor access to the physical device,” the social network said in a statement.

In addition to Wright, The Next Web, which re-created the hack, confirmed that it “does not require a jailbreak.”

But the blog also went one step further and found that Dropbox also suffers from the same flaw, leaving the application open to a so-called “plist,” or property list, hack.

“We copied the .plist from one device with the app installed and logged in, over to another which had a fresh installation of Dropbox on it,” The Next Web said. “The profile copied and it worked seamlessly, as if we had logged on ourselves, which we had not.”

One other interesting tidbit from the findings on Dropbox: the hack will even work on an iPhone protected by a passcode.

“Dropbox’s Android app is not impacted because it stores access tokens in a protected location,” a company spokesperson told CNET in an e-mailed statement. “We are currently updating our iOS app to do the same. We note that the attack in question requires a malicious actor to have physical access to a user’s device. In a situation like that, a user is susceptible to all sorts of threats, so we strongly advise safeguarding devices.”

Facebook did not immediately respond to CNET’s request for comment on these latest developments.

 

Related stories

  • Facebook says ID theft threat only on jailbroken phones
  • iPhone security hole lets apps run unsigned code
  • Apple boots security guru who exposed iPhone exploit
  • CNET’s review of the Apple iPhone 4S

 

Originally posted at Apple

Don Reisinger is a technology columnist who has written about everything from HDTVs to computers to Flowbee Haircut Systems. Don is a member of the CNET Blog Network, posting at The Digital Home. He is not an employee of CNET.

 

Direct Link:   http://news.cnet.com/8301-1009_3-57410475-83/facebook-id-theft-threat-impacts-all-iphones-dropbox/

 

 

 Posted by GE Investigations at 21:28  Tagged with: claims that Facebook's iPhone application includes a vulnerability that fails to encrypt log-on credentials when a user accesses the social network, Dropbox, Dropbox also suffers from the same flaw, Facebook, Facebook ID theft threat impacts all iPhones, Facebook Query Language, Facebook says that a vulnerability allowing someone to access another user's account only affects jailbroken iPhones, Facebook's iOS and Android applications are only intended for use with the manufacture provided operating system, interesting tidbit from the findings on Dropbox: the hack will even work on an iPhone protected by a passcode, jailbroken iPhones, modified their mobile OS (i.e. jailbroken iOS or modded Android, not just jailbroken handsets., re-creating a U.K. developer's hack, Rooted Androids, Rooted Droids, says it has confirmed his findings: Facebook vulnerability affects all iPhones, The Next Web
< Blog Home

<< Main Site

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Tags

adware Android Anonymous Apple Arizona Brooklyn Cyber Attack cyber security Cybersecurity DEA Digital Security Drug Enforcement Administration Drugs exploit Exploits Facebook FBI Federal Bureau of Investigation G.E. Investigations Blog G.E. Investigations LLC GE Investigations Blog Google hack hacked hacker Hackers Hacking LAPD Law Enforcement Los Angeles Police Deparment LulzSec Malware Microsoft Narcotics New York City Police Department NYPD privacy social engineering Spyware trojan Twitter U.S.M.C. United States Marine Corps USMC virus

Categories

  • Announcements
  • Articles of Interest
  • Bail Recovery
  • Crimes & Criminal Activity (Organized Crime, Narcotics, Predators, Cyber Crime, Cyber Stalking, UnSolved)
  • FALLEN & INJURED HEROES
  • Firearms, Weapons & Personal Safety
  • G.E. Investigations Articles
  • Investigative
  • Law Enforcement
  • National security, Terrorism, Cyber Terrorism & Related Crimes
  • Science & Related Space Technology
  • Social Media
  • Technology & Digital Security
  • U.S. MARINES & Military
  • WANTED CRIMINALS & POI

Search

Archives

  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • February 2012
  • January 2012
  • December 2011
  • November 2011
  • October 2011

RSS Feed RSS - Posts

© 2012 G.E. Investigations Blog Created by Mercurius Creative, LLC! Suffusion theme by Sayontan Sinha