whatsapp hack

Very serious vulnerability to WhatsApp leaves all private conversations exposed

A security researcher discovered one στο WhatsApp, την πλατφόρμα άμεσων μηνυμάτων που αγοράστηκε πρόσφατα από το . The vulnerability can be exploited by attackers to gain access to the private conversations of owners of devices running Android.

whatsapp-hack

Bas Bosschert, the researcher who discovered the vulnerability, said Facebook did not need to buy WhatsApp if its only goal was to read user conversations.

The expert found that any Android app that allowed her access to the device's SD card can easily access all of WhatsApp's private conversations.

All conversations are stored in a database file (msgstore.db) that you find on your SD card. Bosschert has developed a POC that demonstrates that any application granted access to the card can easily retrieve the database and send it to a remote .

According to Bosschert, in the later versions of WhatsApp, the database file is encrypted. However, this does not mean that private users' conversations are secure. It simply means that an attacker should decrypt the database to gain access to its contents.

The decryption key can be found through WhatsApp Xtract, an application that allows to backup their WhatsApp chats.

To see the POC and read more technical details visit the researcher's page.

Steals WhatsApp database (PoC)

 

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).