5 ms·
Whatsapp security hole allows changing status message of other users
- beerglass 15y agoRidiculous!
- fredley 15y agoAs a frequent WhatsApp user, I must say I find this more amusing than anything. I've never really understood what the status feature is for anyway.
- ch0wn 15y agoAs a frequent WhatsApp user I don't find this amusing at all. If this is how the engineers handle security issues, it might be time to convince my friends to switch to another messenger. It's not like there was no competition in that field.
- mike-cardwell 15y agoKik Messenger seems to have been doing very well recently.
- 982n389 15y agoDo you know if this can be used with Jabber and if the messages are sent on an encrypted connection to the server? If not, any good apps that do for Iphone or Blackberry?
- mseebach 15y agoI played a little with reverse engineering Kik a while ago. I'm not sure about the messages, but I was able to siphon off the plaintext password using ngrep. It's XMPP, btw.
- mike-cardwell 15y agoWhen they originally launched, they were not using SSL, and were using plain text authentication. Since then, they changed the authentication so it wouldn't be sent in plain text. Then they later added SSL. Then in the middle of last year, they updated their SSL setup so it actually did certificate verification. It took them a while to get there, but it's secure now.
- msh 15y agoUmm, I think a malicious user could write things in your status that could have negative consequences for you.
- 982n389 15y agoOf course, these security holes are not so hilarious to WhatsApp users who think their chats are encrypted on route to WhatsApp's servers :)
- jng 15y agoThe initial design of WhatsApp was as an app to share your status. Only later did they add messaging. Which is the functionality that actually made them take off. But they've never removed the statua part, even though nobody uses it.
- steipete 15y agoIt's not changing status anymore, did they already block the site's IP?
- BuddhaSource 15y agoIs this a Fraud site? Not working for me.
- richardburton 15y agoI could not change mine. If the leak is plugged would you be willing to explain where the hole is?
- chintan100 15y agoDid anybody have any success with changing someone else's status with this? If so, please post. I got the success message on site and restarted the app too on iPhone by killing it from the multitasking bar but my friend's status is still unchanged. Makes me doubt it is a fraud site as BuddhaSource mentioned.
- sssparkkk 15y agoSome more information about this can be found here: http://packetstormsecurity.org/files/108010/SA-20111219-1.txt http://packetstormsecurity.org/files/108010/SA-20111219-1.tx...
- yread 15y agoWow it seems there is no security at all: > By providing any WhatsApp registered telephone number and the text for the status update, it is possible to change a user's status. This action does not require any prior authentication or authorization > (on registration) The vendor has implemented bruteforce protection by locking a number after 10 tries. This step makes a successful attack on a specific number unlikely but an attacker bruteforcing X00 numbers can still guess X number(s) on average. > As published in the past several times already the XMPP traffic from WhatsApp is not encrypted. And they are planning to charge money for it? edit: perhaps even worse is their response to the security vulnerability seen in the timeline - they knew about the bug since 09-14
- thelicx 15y agoNot working for me.
- jaipilot747 15y agoWhat would the legal liabilities of this site be?
- alex1 15y agoThe site says the hole has been patched but I was just able to change my own status with this: curl -A "WhatsApp/2.6.7 iPhone_OS/5.0.1 Device/iPhone_4" --header "Accept-Language: en-us" --header "Accept-Encoding: gzip, deflate" --header "Connection: keep-alive" -d "cc=1&me=%2B1{10_DIGIT_NUMBER}&s={URL_ENCODED_STATUS}" https://s.whatsapp.net/client/iphone/u.php It did take some time to show up under my name, even after restarting the app.
- dopp 15y agodumb question - how exactly can I try this? I went to the site, but didn't find relevant information.
- startupcto 15y agoThere's a few ways that they can patch this. I'm assuming that there's some sort of auth process in place for their http calls and this could simply be a case where this particular endpoint missed the auth. Or they're simply blocking the whatsappstatus's ip and a fix would actually require both client side and server side changes. But honestly its just a messaging app and how many people really cares if "let's go grab a beer" is encrypted or not.