Tag Archive for: Allowed

iOS cookie theft bug allowed hackers to impersonate users

Apple has squashed a bug in its iOS operating system that made it possible for hackers to impersonate end users who connect to websites that use unencrypted authentication cookies.

The vulnerability was the result of a cookie store iOS shared between the Safari browser and a separate embedded browser used to negotiate “captive portals” that are displayed by many Wi-Fi networks when a user is first joining. Captive portals generally require people to authenticate themselves or agree to terms of service before they can gain access to the network.

According to a blog post published by Israeli security firm Skycure, the shared resource made it possible for hackers to create a booby-trapped captive portal and associate it with a Wi-Fi network. When someone with a vulnerable iPhone or iPad connected, it could steal virtually any HTTP cookie stored on the device. Skycure researchers wrote:

Read 1 remaining paragraphs | Comments

Technology Lab – Ars Technica

Report: Shoddy computer security allowed access for nebbing in Monroeville – Tribune-Review

Report: Shoddy computer security allowed access for nebbing in Monroeville
Tribune-Review
A follow-up report into an initial investigation of unauthorized computer access in Monroeville determined that poor computer security led to the breaches, officials said. The more-recent investigation, conducted by Corporate Security and

“computer security” – read more

Microsoft: Targeted phishing attacks allowed SEA to steal law enforcement documents

Since the start of 2014, the Syrian Electronic Army (SEA) has twice attacked Microsoft, accusing the Redmond giant of helping the government spy on and monitor our email as well as warning people not to use Microsoft email like Hotmail or Outlook. The first hack was via all of Skype’s social media accounts.
Ms. Smith’s blog

Facebook vulnerability that allowed any photo to be deleted earns $12,500 bounty

An engineer has discovered a vulnerability in Facebook that could have allowed for any photo on the site to be deleted without the owner’s knowledge.
Naked Security – Sophos