Viber; No thanks

Researchers by UNH Cyber ​​Forensics Research & Education Group have discovered several vulnerabilities and bad security practices in a popular messaging application, the well-known Viber, threatening the privacy of 150 million active users of the service.

Viber

The results of their research as they published

Results Summary

  • received are unencrypted
  • Doodles received are unencrypted
  • Videos received are unencrypted
  • Location images sent and received are unencrypted
  • Data is stored on the Viber Servers in an unencrypted
  • Data stored on the Vibr Amazon Servers is not deleted immediately
  • Data stored on the Viber Amazon Servers can be easily accessed without any authentication mechanism (Simply visiting the intercepted link on a gives us complete access to the data)

The researchers found that user data is stored on the company's Servers, which are essentially Amazon servers. Data includes images, videos, and messages stored in unencrypted form and without any authentication mechanism. So attackers simply visit the link and have full access to the data.
Σε ένα βίντεο επίδειξης, οι ερευνητές απέδειξαν ότι το πώς η εταιρεία δεν κρυπτογραφεί δεδομένα, ενώ τα μεταφέρει μεταξύ των server που χρησιμοποιεί, κάτι που επιτρέπει σε κάποιον εισβολέα να "πιάσει" την κυκλοφορία και να πραγματοποιήσει επιθέσεις man-in-the middle.

Researchers have reported vulnerabilities in the application team before publishing their findings on their blog but have not received any response.
"It is important to let people know about these weaknesses, therefore we have chosen to present the results and the video of the research in this publication refer to blog their.

Watch the demo video

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).