{"id":16514,"date":"2012-04-07T00:10:27","date_gmt":"2012-04-06T20:10:27","guid":{"rendered":"http:\/\/iphoneroot.com\/?p=16514"},"modified":"2012-04-07T00:10:27","modified_gmt":"2012-04-06T20:10:27","slug":"dropbox-and-facebook-ios-apps-are-vulnerable-to-credential-theft","status":"publish","type":"post","link":"https:\/\/jailbreak-iphone.ru\/en\/dropbox-and-facebook-ios-apps-are-vulnerable-to-credential-theft\/","title":{"rendered":"Dropbox And Facebook iOS Apps Are Vulnerable To Credential Theft"},"content":{"rendered":"<p><noindex><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/iphoneroot.com\/wp-content\/uploads\/2012\/04\/iphonefb.jpg\" target=\"_blank\" ><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16515\" src=\"http:\/\/iphoneroot.com\/wp-content\/uploads\/2012\/04\/iphonefb.jpg\" alt=\"iphonefb\" width=\"308\" height=\"600\" \/><\/a><\/noindex><\/p>\n<p>This week Gareth Wright <noindex><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/garethwright.com\/blog\/facebook-mobile-security-hole-allows-identity-theft\" target=\"_blank\" >reported<\/a><\/noindex> that Facebook&#8217;s app for iOS has a <a href=\"https:\/\/jailbreak-iphone.ru\/en\/tag\/security\/\" target=\"_blank\" class=\"slink\" title=\"security\" >security<\/a> vulnerability through which malicious users can access login credentials saved in a .plist file of the app. With a copy of that .plist file malicious users could automatically log into the affected user&#8217;s Facebook account on another device. Reportedly, the vulnerability also exists on Android devices.<\/p>\n<p><!--more--><\/p>\n<p>Wright describes several different ways in which your login credentials could be obtained by a malicious user, including hidden <a href=\"https:\/\/jailbreak-iphone.ru\/en\/tag\/applications\/\" target=\"_blank\" class=\"slink\" title=\"applications\" >applications<\/a> installed on shared PCs, customized apps, or modified speaker dock that could copy your plist.<\/p>\n<p><noindex><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/arstechnica.com\/apple\/news\/2012\/04\/facebook-says-ios-based-credential-only-works-on-jailbroken-devices.ars\" target=\"_blank\" >According to<\/a><\/noindex> Facebook, the issue only affects jailbroken or lost devices, as it requires physical access or installation of a custom app on the device. But Wright and <noindex><a target=\"_blank\" rel=\"nofollow\" href=\"http:\/\/thenextweb.com\/mobile\/2012\/04\/06\/security-hole-in-facebook-ios-app-doesnt-require-jailbreak-or-theft-and-dropbox-has-it-too\/\" target=\"_blank\" >The Next Web<\/a><\/noindex> pointed out that simply plugging into any device would be sufficient for malicious users to gather these files.<\/p>\n<p>The Next Web has confirmed that Dropbox for iOS is also vulnerable to this issue. Given that two such high-profile apps as Facebook and Dropbox are vulnerable to credential theft, it is likely that <a href=\"https:\/\/jailbreak-iphone.ru\/en\/category\/all\/other\/\" target=\"_blank\" class=\"slink\" title=\"other\" >other<\/a> apps are also affected by the issue.<\/p>\n<p>As many reports note, this method of gathering login credentials is not actively utilized in a malicious manner, and users can protect their data for the time being by not plugging their devices into shared computers and charging stations.<\/p>","protected":false},"excerpt":{"rendered":"<p>This week Gareth Wright reported that Facebook&#8217;s app for iOS has a security vulnerability through which malicious users can access login credentials saved in a .plist file of the app. With a copy of that .plist file malicious users could automatically log into the affected user&#8217;s Facebook account on another device. Reportedly, the vulnerability also [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,8],"tags":[901,55,903,57,1213,59,109,110,908,1161,117,993,162,187,854,734,598,599,1023,280,1183,283,771,1070,807,1101],"class_list":["post-16514","post","type-post","status-publish","format-standard","hentry","category-all","category-other","tag-ads","tag-android","tag-app","tag-apple","tag-application","tag-applications","tag-droid","tag-dropbox","tag-ebook","tag-ed","tag-facebook","tag-ios","tag-iphone","tag-jailbreak","tag-mobile","tag-news","tag-plist","tag-poi","tag-report","tag-security","tag-sed","tag-sim","tag-time","tag-1070","tag-807","tag-1101"],"_links":{"self":[{"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/posts\/16514","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/comments?post=16514"}],"version-history":[{"count":0,"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/posts\/16514\/revisions"}],"wp:attachment":[{"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/media?parent=16514"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/categories?post=16514"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jailbreak-iphone.ru\/en\/wp-json\/wp\/v2\/tags?post=16514"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}