Jump to content

Hacker reveals Whatsapp’s big security Flaw

Ebenesh

whatsapp-SSL-flaw.jpg

 

Whatsapp is starting to pick up some big news this year, first the acquisition then the sudden blackout and now this.Bas Bosschert, an IT specialist from the Netherlands, claims that any app can look into the chat history of whatsapp. The fact that whatsapp backs up your data on the SD card means that any app with the permission to access your SD card can also access your whatsapp folder. The only thing the app has to be able to do is interpret the Backup file and after that it's just a matter of uploading your data to the app's server. The IT specialist has a blog post up that shows exactly how one can create such an app.
Bosschert said in an email to Business Insider,

"People would only see a loading screen when they started the game,They wouldn't notice that their WhatsApp database has been uploaded."

 

 

Security breaches such as the one outlined in Bosschert's post can be easily avoided by verifying an app's source and carefully reading an app's permissions before installing.

 

Source: Business Insider, Techalways

Link to comment
Share on other sites

Link to post
Share on other sites

And then they say "hacking is dangerous", yeah but thanks to these hackers, apps become more secure.

VIDEO GAMES                                  Max Power Build Log

Link to comment
Share on other sites

Link to post
Share on other sites

And then they say "hacking is dangerous", yeah but thanks to these hackers, apps become more secure.

Unfortunately,lots of hackers like this get to jail because they hack servers to reveal their security flaws.

i5 4670k @ 4.2GHz (Coolermaster Hyper 212 Evo); ASrock Z87 EXTREME4; 8GB Kingston HyperX Beast DDR3 RAM @ 2133MHz; Asus DirectCU GTX 560; Super Flower Golden King 550 Platinum PSU;1TB Seagate Barracuda;Corsair 200r case. 

Link to comment
Share on other sites

Link to post
Share on other sites

Bas Bosschert
CONSULTANT / SYSADMIN / ENTREPRENEUR

 

Steal WhatsApp database (PoC)

“Is it possible to upload and read the WhatsApp chats from another Android application?”

With this question my brother and I started an interesting conversation which ended in underneath proof of concept. The tldr answer is: “Yes, that is possible”.

 

http://bas.bosschert.nl/steal-whatsapp-database/#more-1

Link to comment
Share on other sites

Link to post
Share on other sites

whatsapp has always had horrible security

take a look at whatsAPI

 

just stop using it

If your grave doesn't say "rest in peace" on it You are automatically drafted into the skeleton war.

Link to comment
Share on other sites

Link to post
Share on other sites

I know that whatsapp stores my conversations on my memory card... But is it encrypted or something which prevents other apps from reading it?

Link to comment
Share on other sites

Link to post
Share on other sites

they are secured with truecrypt5 which can be brute forced.

mY sYsTeM iS Not pErfoRmInG aS gOOd As I sAW oN yOuTuBe. WhA t IS a GoOd FaN CuRVe??!!? wHat aRe tEh GoOd OvERclok SeTTinGS FoR My CaRd??  HoW CaN I foRcE my GpU to uSe 1o0%? BuT WiLL i HaVE Bo0tllEnEcKs? RyZEN dOeS NoT peRfORm BetTer wItH HiGhER sPEED RaM!!dId i WiN teH SiLiCON LotTerrYyOu ShoUlD dEsHrOuD uR GPUmy SYstEm iS UNDerPerforMiNg iN WarzONEcan mY Pc Run WiNdOwS 11 ?woUld BaKInG MY GRaPHics card fIX it? MultimETeR TeSTiNG!! aMd'S GpU DrIvErS aRe as goOD aS NviDia's YOU SHoUlD oVERCloCk yOUR ramS To 5000C18

 

Link to comment
Share on other sites

Link to post
Share on other sites

that is some security flaw, would that still be the case if your SSD was encrypted? 

Never trust a man, who, when left alone with a tea cosey... Doesn't try it on. Billy Connolly
Marriage is a wonderful invention: then again, so is a bicycle repair kit. Billy Connolly
Before you judge a man, walk a mile in his shoes. After that, who cares? He's a mile away and you've got his shoes. Billy Connolly
Link to comment
Share on other sites

Link to post
Share on other sites

And then they say "hacking is dangerous", yeah but thanks to these hackers, apps become more secure.

 

White hat 

Black hat

 

Look into it

Desert Storm PC | Corsair 600T | ASUS Sabertooth 990FX AM3+ | AMD FX-8350 | MSI 7950 TFIII | 16GB Corsair Vengeance 1600 | Seasonic X650W I Samsung 840 series 500GB SSD

Mobile Devices I ASUS Zenbook UX31E I Nexus 7 (2013) I Nexus 5 32GB (red)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×