Jump to content

HTTPS bug in IOS may open up vulnerability to eavesdropping

NOTE: in light of my last topic I am going to make this clear, this has NOTHING to do with apple, this DOES have to do with iOS, and  an open source API known as AFnetworking: go hear for more info http://AFNetworking

 

 

 


At least 25,000 iOS apps available in Apple's App Store contain a critical vulnerability that may completely cripple HTTPS protections designed to prevent man-in-the-middle attacks that steal or modify sensitive data, security researchers warned.

As was the case with a separate HTTPS vulnerability reported earlier this week that affected 1,500 iOS apps, the bug resides in AFNetworking, an open-source code library that allows developers to drop networking capabilities into their iOS and OS X apps. Any app that uses a version of AFNetworking prior to the just-released 2.5.3 may expose data that's trivial for hackers to monitor or modify, even when it's protected by the secure sockets layer (SSL) protocol. The vulnerability can be exploited by using any valid SSL certificate for any domain name, as long as the digital credential was issued by a browser-trusted certificate authority (CA).

sourcehttp://arstechnica.com/security/2015/04/24/critical-https-bug-may-open-25000-ios-apps-to-eavesdropping-attacks/.

 

to anyone useing an IOS device check your apps, this vulnerability means that anyone with a a valid certificate, example: someone with a valid certifacte can spoof  microsoft.com because AFNetworking fails to check the validity of  the server, and therfore anyone in say a unsecured wifi spot can spoof microsoft.com.

Desktop:ryzen 5 3600 | MSI b45m bazooka | EVGA 650w Icoolermaster masterbox nr400 |16 gb ddr4  corsiar lpx| Gigabyte Aorus GTX 1070ti |500GB SSD+2TB SSHD, 2tb seagate barracuda [OS/games/mass storage] | HpZR240w 1440p led logitech g502 proteus spectrum| Coolermaster quick fire pro cherry mx  brown |

 

Link to post
Share on other sites

its iOS. not IOS. Everytime I see IOS I think of a Wii/Wii U, as that is what they called the sections of memory on the Flash chip in the Wii. (was important to know for homebrew applications) (not a huge issue OP, it just bugs me)

 

But it really only affects open wifi networks. Which have multiple upon multiple other security risks. DO NOT use open/free wifi for doing anything important like making purchases with card #'s  or viewing bank account information, it can all easily be pulled up via a WLAN chip in monitor mode and Wireshark.

"If a Lobster is a fish because it moves by jumping, then a kangaroo is a bird" - Admiral Paulo de Castro Moreira da Silva

"There is nothing more difficult than fixing something that isn't all the way broken yet." - Author Unknown

Spoiler

Intel Core i7-3960X @ 4.6 GHz - Asus P9X79WS/IPMI - 12GB DDR3-1600 quad-channel - EVGA GTX 1080ti SC - Fractal Design Define R5 - 500GB Crucial MX200 - NH-D15 - Logitech G710+ - Mionix Naos 7000 - Sennheiser PC350 w/Topping VX-1

Link to post
Share on other sites

its iOS. not IOS. Everytime I see IOS I think of a Wii/Wii U, as that is what they called the sections of memory on the Flash chip in the Wii. (was important to know for homebrew applications) (not a huge issue OP, it just bugs me)

 

But it really only affects open wifi networks. Which have multiple upon multiple other security risks. DO NOT use open/free wifi for doing anything important like making purchases with card #'s  or viewing bank account information, it can all easily be pulled up via a WLAN chip in monitor mode and Wireshark.

my mistake I was having a hard time, lenovos  new drivers for the thinkpad are really aweful >.<

 

anyways this is pretty much common knowledge but people tend to do this anyways,unfortunatly

Desktop:ryzen 5 3600 | MSI b45m bazooka | EVGA 650w Icoolermaster masterbox nr400 |16 gb ddr4  corsiar lpx| Gigabyte Aorus GTX 1070ti |500GB SSD+2TB SSHD, 2tb seagate barracuda [OS/games/mass storage] | HpZR240w 1440p led logitech g502 proteus spectrum| Coolermaster quick fire pro cherry mx  brown |

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×