whatsapp hack

Very serious vulnerability to WhatsApp leaves all private conversations exposed

A security researcher has discovered a security gap in WhatsApp, the instant messaging platform recently bought from Facebook. Vulnerability can be exploited by attackers to gain access to the private conversations of device owners running Android.

whatsapp-hack

Bas Bosschert, the researcher who discovered the vulnerability, said Facebook did not need to buy WhatsApp if its only goal was to read user conversations.

The expert found that every Android app that has allowed her to access the SD of the device can easily access all private WhatsApp chats.

All conversations are saved in a file data file (msgstore.db) found on the SD card. Bosschert has developed a POC which demonstrates that each application granted to it access card can easily retrieve the database and send it to some remote server.

According to Bosschert, in the later versions of WhatsApp, the database file is encrypted. However, this does not mean that private users' conversations are secure. It simply means that an attacker should decrypt the database to gain access to its contents.

The key froms can be found through WhatsApp Xtract, an application that allows users to backup their WhatsApp chats.

To see the POC and read more technical details visit the researcher's page.

Steals WhatsApp database (PoC)

 

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).