Este sitio utiliza cookies propias y de terceros. Si continúa navegando consideramos que acepta el uso de cookies. OK Más Información.

WhatsApp Web vCard Vulnerability Exposed 200M Users

  • 0 Respuestas
  • 1096 Vistas

0 Usuarios y 1 Visitante están viendo este tema.

Desconectado R3v0lve

  • *
  • Underc0der
  • Mensajes: 80
  • Actividad:
  • Reputación 3
  • No se sale adelante celebrando éxitos sino superan
    • Ver Perfil
  • Skype: антисоціальна
  • Twitter: антисоціальна
« en: Septiembre 21, 2015, 02:43:37 am »
The vulnerability lies in the improper filtering of contact cards using the popular vCard format, thankfully WhatsApp reacted fairly fast on this.

    A vulnerability discovered in WhatsApp Web, the web-based extension of the WhatsApp mobile application, can be exploited by attackers to trick users into executing arbitrary code on their machines.

    Discovered by Check Point security researcher Kasif Dekel, the vulnerability can be exploited by simply sending a vCard contact card containing malicious code to a WhatsApp user. As soon as the seemingly innocent vCard is opened in WhatsApp Web, the malicious code in it can run on the target machine.

    This vulnerability allows cybercriminals to compromise the affected computer by distributing all types of malware, including ransomware, bots, and remote access tools (RATs), Check Point’s researcher explains.

    The underlying issue lies in the improper filtering of contact cards that are sent using the popular ‘vCard’ format. “By manually intercepting and crafting XMPP requests to the WhatsApp servers, it was possible to control the file extension of the contact card file,” the Check Point researcher explained in a blog post.

    An attacker can inject a command in the name attribute of the vCard file, separated by the ‘&’ character. Windows automatically tries to run all lines in the file, including the injection line, when the vCard is opened.

The vulnerability is fixed and has been since August 27th, which is rapid considering the vulnerability was only disclosed to them on August 21st. Public disclosure came this week on September 8th.

You can read the full report from Check Point here: WhatsApp “MaliciousCard” Vulnerabilities Allowed Attackers to Compromise Hundreds of Millions of WhatsApp Users

    This attack does not require XMPP interception of crafting, due to the fact that anyone can create such a contact with an injected payload, directly on the phone, Check Point notes. As soon as the contact is ready, the attacker only needs to share it through the WhatsApp client to unsuspicious users.

    Check Point also explains that WhatsApp failed to validate the vCard format or the contents of the file, and that even an exe file could have been sent this way. Even more, malware could have been attached to a displayed icon, opening a vast world of opportunity for cybercriminals and scammers

    Over the past several years, WhatsApp has grown to become one of the popular messaging services on mobile phones, with over 900 million users as of this month, and it has extended to the desktop as well, where it has over 200 million users.

    WhatsApp Web provides users with access to all of the messages that they have sent or received, including includes images, videos, audio files, locations and contact cards, and keeps all content synchronized with the phone, so that users can access it on both desktop and mobile devices.

    Additionally, the web-based interface allows users to view all of the sent or received attachments, as long as they are accessible through the mobile application, including images, audio and video files, location info, and contact cards.

It’s cute how they tried to come up with a catchy name too like HeartBleed or LogJam – they went with ‘MaliciousCard’.

It’s rather surprising more companies or bad guys aren’t going after messaging services as they have such immense user bases (Over 900 Million for WhatsApp). Or perhaps they are, and there’s a bunch of zero-days out there no one knows about yet. That is very possible.


 @R3v0lve es necesario citar la fuente de la noticia (o si la ignoras, que es información de la web). Edité tu post mencionando una de las posibles fuentes donde se encuentra la misma (nos evitamos justos reclamos).

Gracias, :)

« Última modificación: Septiembre 21, 2015, 03:45:23 am por Gabriela »
Ми повинні мати віру в себе. У цьому і полягає секрет. Навіть коли я був у дитячому будинку і ходили по вулицях у пошуках їжі, щоб жити, навіть тоді, я вважав найбільшим актором в світі. Без абсолютної впевненості, один приречена на провал.


¿Te gustó el post? COMPARTILO!

WhatsApp limita el reenvío de mensajes para combatir el "spam" y fake news

Iniciado por Ascendock

Respuestas: 0
Vistas: 480
Último mensaje Julio 28, 2018, 12:04:00 am
por Ascendock
WhatsApp prepara la opción "marcar como no leído"

Iniciado por Alejandro_99

Respuestas: 0
Vistas: 1331
Último mensaje Julio 05, 2015, 09:58:30 pm
por Alejandro_99
Descubren que el Hacking Team usaba Apps de Facebook y WhatsApp para robar info.

Iniciado por Mayk0

Respuestas: 0
Vistas: 1378
Último mensaje Agosto 10, 2015, 02:50:44 pm
por Mayk0
Cómo roban dinero a través de WhatsApp, Tinder, policías 'falsos' o tarjetas SIM

Iniciado por graphixx

Respuestas: 0
Vistas: 1553
Último mensaje Marzo 13, 2016, 09:13:25 am
por graphixx
¿Cómo evitar el doble tilde azul de WhatsApp y seguir leyendo los mensajes?

Iniciado por Alejandro_99

Respuestas: 0
Vistas: 1478
Último mensaje Noviembre 06, 2014, 01:44:47 pm
por Alejandro_99