English | Italian

"Researchers slurp unencrypted..." (Theme) The lastest total: 100+. you can read with page flip.

show list
related videos
Easily Recover Viber Calls & Messages from iPhone 6+/6/5S/5C/5/4S/4/3GS
How to Recover Viber Contacts from iPhone from/without iTunes, iCloud Backup
C3TEK DEMO Viber data summary
Viber Security Vulnerabilities: Images, Doodles, Location and Videos sent over Viber is unencrypted
G Data Internet Security for Android
Matrix Data Solution India
Continue »
Pop theme

John Cantlie,Republican Party,Ebola Virus,San Francisco Giants,Oscar Taveras,Ukraine gas,David Cameron,Nizami,Lloyds Bank,Marvel Comics

Related theme

same team,new haven,research whatsapp,location

Researchers slurp unencrypted Viber messaging data with ease

data viber received

2014-04-24 05:26:48

Combat fraud and increase customer satisfaction

Popular Whatsapp-like messaging service Viber is exposing users to man-in-the-middle and other attacks because it isn’t encrypting various data at rest and in transit, security researchers have warned.

The mobile app allows users to send each other messages, videos, images and “doodles”, share GPS location details and make voice calls.

However, researchers at the University of New Haven Cyber Forensics Research and Education Group (UNHcFREG) found a “serious security flaw” in the way Viber receives videos, images and doodle files; the way it sends and receives location data; and the way it stores data on its Amazon servers.

The team’s experimental network created a rogue access point utilising a Windows 7 PC’s Virtual Wi-Fi Miniport Adapter and a first smartphone connected to the same network.

It then connected a second smartphone outside the network via GSM and used it to exchange data with the first smartphone over Viber.

It said that with tools such as NetworkMiner, Wireshark, and NetWitness it was able to capture traffic sent over the test network.

Specifically, the team claimed that images, doodles and videos received are unencrypted; location data sent and received is unencrypted; and data is stored on the Viber Amazon servers in unencrypted format.

Further, it said user data stored on Viber's Amazon servers is not deleted immediately and that it can be easily accessed without any authentication mechanism – “simply visiting the intercepted link on a web browser gives us complete access to the data”.

The researchers added the following:

Anyone, including the service providers will be able to collect this information – and anyone that sets up a rogue AP, or any man-in-the middle attacks such as ARP poisoning will be able to capture this unencrypted traffic and view the images and videos received as well as the locations being sent or received by a phone.

UNHcFREG said it had already informed Viber of the security flaws but received no word back at the time of publishing. A video of the test (h/t The Hacker News) can be found here.

It recommended Viber ensure all data in transit is sent over an encrypted tunnel, that data is encrypted properly when saved and that it access to it must require authentication.

The Israeli-backed messaging service, based in Cyprus, was recently acquired for $900 million by Japanese e-commerce giant Rakuten in a bid to take the firm “to a different level”.

For the record, the same team of New Haven uni testers last week published research claiming a bug in Whatsapp's "location sending" feature. ®

SANS - Survey on application security programs

View Original Article: theregister.co.uk
Disclaimer statement: The point of this article or rights belongs to the authors and publishers. We take no responsibility for the content of this article and legitimacy.
Do you have any questions about this article, please contact the news source theregister.co.uk.
Or contact us


Write an article relevant this topic share on facebook share on twitter share on google plus share on oknews share on linkedin share on digg share on reddit share on newsvine share on pinterest share on netlog share on tumblr share on delicious send email print add to favorite

"Researchers slurp unencrypted..." IN THE COMMUNITY!



        No results related
      Share one Sentence

      Manage my submission

      [{"b":"b","i":"1293603","t":"Sweden recognises Palestinian state, draws Israeli anger - Yahoo News UK","a":1},{"b":"a","i":"1356567","t":"EmLogis Online Employee Scheduling Announces Two Tools to Help Reduce the Use of Sick Days","a":2},{"b":"b","i":"1293574","t":"Billboard Touring Awards Finalists Announced","a":3},{"b":"b","i":"1293577","t":"MEDIA ALERT - Ricoh and mindSHIFT Technologies to present at Commonwealth Legal's Technology in Practice international conference - Yahoo Finance Canada","a":4},{"b":"b","i":"1293578","t":"Tecogen to Hold Earnings Conference Call and Webcast on Thursday, November 13, 2014","a":5},{"b":"c","i":"1894242","t":"Tonawanda News to close in January","a":6},{"b":"e","i":"533808","t":"The Secret to Celeb-Worthy Winged Liner","a":7},{"b":"b","i":"1293590","t":"Change the Mascot Campaign Releases New Ad in MN in Advance of Washington \u2013 Vikings Game","a":8},{"b":"b","i":"1293557","t":"The Definitive History of Sexy Halloween Costumes","a":9},{"b":"a","i":"1356559","t":"LIVE: Ottawa Senators host Chicago Blackhawks","a":10},{"b":"a","i":"1356535","t":"Junior speedskaters off to face the best","a":11},{"b":"a","i":"1356548","t":"Chanticleer Holdings to Open Third South Africa Hooters Restaurant in Johannesburg","a":12},{"b":"b","i":"1293539","t":"Amnesty: Libyan militias committing war crimes","a":13},{"b":"b","i":"1293543","t":"A Headless Ranger? Mystery at Colonial burial site","a":14},{"b":"a","i":"1356502","t":"Review calls for sweeping changes across Nova Scotia's education system - Local - Cape Breton Post","a":15},{"b":"d","i":"973769","t":"Equality watchdog\u2019s consultation perverts family values, school heads say","a":16},{"b":"d","i":"973773","t":"Cantonese restaurants recognised in latest Michelin guide to Hong Kong","a":17},{"b":"a","i":"1356525","t":"MMAjunkie Radio (noon ET): Khabib Nurmagomedov, Alex Enlund, Jim Wallhead","a":18},{"b":"a","i":"1356479","t":"Daytona International Speedway Names Florida Hospital as a Founding Partner Of Historic DAYTONA Rising Project\r\n\t\t\t\t\t\t\t\t\t\t\tFlorida Hospital Becomes Official Healthcare Provider of Daytona International Speedway","a":19},{"b":"a","i":"1356484","t":"Table Trac, Inc. Signs Deal with Cool Casino Group For Costa Rica Casino at the RIU Guanacaste Hotel","a":20},{"b":"b","i":"1293515","t":"Celebrity dinner today in Kingsford - IronMountainDailyNews.com | news, sports, business, jobs - The Daily News","a":21},{"b":"f","i":"1170145","t":"San Francisco Giants claim third World Series","a":22},{"b":"b","i":"1293506","t":"AppDynamics Named a "Leader" in Gartner's Magic Quadrant for Application Performance Monitoring for Third Consecutive Year - Yahoo Finance UK","a":23},{"b":"b","i":"1293508","t":"Nobia AB: Agreement on Divestment of Hygena Signed - Yahoo Finance Canada","a":24},{"b":"b","i":"1293470","t":"Daytona International Speedway Names Florida Hospital as a Founding Partner Of Historic DAYTONA Rising Project - Yahoo Finance Canada","a":25},{"b":"a","i":"1356439","t":"SEC and FINRA Warn Investors About Penny Stock Scams Hyping Dormant Shell Companies","a":26},{"b":"e","i":"533756","t":"The Greatest: Remembering Muhammad Ali’s Rumble in the Jungle","a":27},{"b":"a","i":"1356418","t":"PetroMaroc Announces Private Placement - Yahoo Finance Canada","a":28},{"b":"a","i":"1356420","t":"Iran Has 16 Intelligence Agencies","a":29},{"b":"d","i":"973742","t":"French Finance Ministry Says Conditions Not Met to Hand Over Mistral to Russia: Agency","a":30},{"b":"d","i":"973743","t":"Ukraine Promises Russia to Find Funds to Pay for Winter Gas Supplies: Novak","a":31},{"b":"a","i":"1356375","t":"Family SUV models attract Wisconsin shoppers with comfort and capability - Yahoo Finance Canada","a":32},{"b":"b","i":"1293420","t":"Barrick Gold looking to cut debt to $7 billion as industry cuts costs - Yahoo Finance Canada","a":33},{"b":"b","i":"1293407","t":"Psychemedics Corporation Announces Record Revenues - Yahoo Finance Canada","a":34},{"b":"a","i":"1356379","t":"KVH Introduces Safety and Security Training Programs for Superyachts - Yahoo7 Finance Australia","a":35},{"b":"a","i":"1356380","t":"LIONSGATE'S ONLINE FITNESS CHANNEL BEFIT PARTNERS WITH TOP SECRET NUTRITION TO CREATE BRANDED NUTRITIONAL SUPPLEMENT LINE","a":36},{"b":"a","i":"1356344","t":"HARMAN Appoints Sandra E. Rowland as Chief Financial Officer, Effective January 1, 2015 - Yahoo Finance Canada","a":37},{"b":"a","i":"1356349","t":"SportsManias Names Tim Stephens VP of Strategic Partnerships\r\n\t\t\t\t\t\t\t\t\t\t\tFormer Deputy Managing Editor at CBSSports.com to Expand Partnerships with Local Newspapers, Media Companies and Sports Leagues","a":38},{"b":"b","i":"1293376","t":"Flow Services Launches as Global Sheet Wave Repair and Maintenance Specialists - Yahoo7 Finance Australia","a":39},{"b":"b","i":"1293392","t":"News Saint Seiya Soul of Gold Anime Teased for Next Spring","a":40},{"b":"a","i":"1356332","t":"S3 Partners Wins \u2018Best Technology Firm \u2013 Client Service\u2019 in HFM\u2019s U.S. Hedge Fund Services Awards - Yahoo Finance UK","a":41},{"b":"b","i":"1293398","t":"Four Years Of George Strait Vaqueros Del Mar Invitational Golf Tournament & Auction Totals $1.1 Million For Military Wounded In Action - Yahoo Finance Canada","a":42},{"b":"b","i":"1293371","t":"Rally Software Founder and CTO to Present at SIMposium 2014 - Yahoo Finance Canada","a":43},{"b":"c","i":"1894139","t":"About.Me Launches App That Aims To Replace The Business Card","a":44},{"b":"b","i":"1293352","t":"Anki Strengthens Its Leadership Bench With Entertainment Industry Veterans From Activision And EA - Yahoo Finance Canada","a":45},{"b":"b","i":"1293337","t":"New Bedford Declared America\u2019s Top Fishing Port: 2013 Landed Value at $379 Million Ranks City #1 for 14th Year in a Row","a":46},{"b":"b","i":"1293339","t":"Five things for Thursday , Oct. 30","a":47},{"b":"b","i":"1293343","t":"DOT Working to Drive Home City's New Speed Limit","a":48},{"b":"b","i":"1293350","t":"Other stories from today:","a":49},{"b":"b","i":"1293319","t":"ECB Hires Managers for ABS Purchases Due to Start Next Month","a":50},{"b":"b","i":"1293324","t":"Sweden's recognition to boost \u2018moderates\u2019","a":51},{"b":"b","i":"1293311","t":"Ontario Premier Kathleen Wynne happy that John Tory is new Toronto mayor - Yahoo News Canada","a":52},{"b":"f","i":"1170113","t":"Gazelle(R) Introduces Smarter Way to Buy Smart Devices; Launches Site to Sell Gazelle Certified Pre-Owned Phones and ...","a":53},{"b":"b","i":"1293300","t":"Dhaka tribunal to deliver verdict against Jamaat leader Mir Quasem on Sunday","a":54},{"b":"a","i":"1356252","t":"Breeders\u2019 Cup, NBC Sports Group reach unprecedented 10-year media rights extension","a":55},{"b":"b","i":"1293304","t":"KTVL Top Stories","a":56},{"b":"b","i":"1293265","t":"Mercedes, VW to Thwart Google\u2019s Car Inroads in Car Data","a":57},{"b":"a","i":"1356240","t":"Energy-efficient home trends for 2015 and beyond","a":58},{"b":"a","i":"1356195","t":"Collective agreement finalized between Lakehead Terminal Elevators Association and United Steelworkers","a":59},{"b":"a","i":"1356200","t":"Tribune Publishing Unveils Mobile App for Chicago Tribune; First in \n Suite of New Mobile Apps for the Company\u2019s Major Media Brands","a":60},{"b":"a","i":"1356206","t":"New Cloudyn Tool Wants To Bring Clarity To Cloud Billing","a":61},{"b":"a","i":"1356208","t":"Seismic Survey Reveals Salesforce1 Roll-Outs Slower Than Expected but Gaining Steam","a":62},{"b":"a","i":"1356210","t":"Video Explains How Dragon Age: Inquisition Lets You Carry Over Past Choices","a":63},{"b":"a","i":"1356186","t":"American Mustache Institute Launches Mustache Hall of Fame - Yahoo Finance UK","a":64},{"b":"f","i":"1170099","t":"Black Bean Deli starts serving at Amway today","a":65},{"b":"f","i":"1170083","t":"What's Trending: Could you live in 242 square feet & Harry Potter rapping?","a":66},{"b":"b","i":"1293245","t":"Warning: This Air Bag May Contain Shrapnel","a":67},{"b":"a","i":"1356168","t":"Water Tower Festival, 10K on tap","a":68},{"b":"e","i":"533731","t":"Is China \"Buying a Part of America's Soul\" with the Waldorf Astoria?","a":69},{"b":"a","i":"1356153","t":"Black Hat Trainings 2014 Coming to Nation's Capital in December\r\n\t\t\t\t\t\t\t\t\t\t\tRegister by Oct. 31 at Midnight EDT to Save $200 on Black Hat's Highly Technical Trainings in Washington, D.C., December 8-11","a":70},{"b":"a","i":"1356109","t":"Terry Brown challenges incumbent Phil Pavlov for 25th District State Senate seat","a":71},{"b":"a","i":"1356122","t":"Bosch looks to double sales in Apac by 2020 | Business Standard News","a":72},{"b":"a","i":"1356123","t":"Clarity Solution Group Recognized for Delivering Outstanding Big Data Intelligence","a":73},{"b":"c","i":"1894055","t":"A Headless Ranger? Mystery at Colonial burial site","a":74},{"b":"f","i":"1170080","t":"Kick Off: New LA club announcement | New York-Sporting KC tonight | FCD down Caps on late PK","a":75},{"b":"f","i":"1170027","t":"MotoGP: Casey Stoner Completes Honda Test","a":76},{"b":"f","i":"1170028","t":"Carnival Cruise Lines CEO Gerry Cahill To Retire","a":77},{"b":"f","i":"1170037","t":"New JPMorgan Chase & Co. Report Reveals Solutions to Fill Vital Healthcare and Technology Jobs in New York City","a":78},{"b":"f","i":"1170036","t":"JPMorgan Chase & Co UK Regulatory Announcement: New JPMorgan Chase & Co. Report Reveals Solutions to Fill Vital ...","a":79},{"b":"c","i":"1894028","t":"Featured Stories","a":80},{"b":"c","i":"1894029","t":"UK smart meters arrive in 2020. Hackers have ALREADY found a flaw","a":81},{"b":"f","i":"1170044","t":"Hatsune Miku: Project DIVA F 2nd \u2013 Japanese DLC Roster Coming to the West","a":82},{"b":"e","i":"533716","t":"Shake Shack’s Crinkle Fries Make Their Official, Triumphant Return Today","a":83},{"b":"c","i":"1894019","t":"Candlelight vigil to mark two months since woman went missing in Plano","a":84},{"b":"d","i":"973588","t":"The nuclear attack on the UK that never happened","a":85},{"b":"c","i":"1894010","t":"Amnesty: Libyan militias committing war crimes","a":86},{"b":"d","i":"973547","t":"CNN Student News - October 30, 2014","a":87},{"b":"d","i":"973521","t":"What's Slippier Than Gas Prices? Slippery Politicians. Here's Why","a":88},{"b":"e","i":"533675","t":"Apple CEO Tim Cook Comes Out: \u201cI\u2019m Proud to Be Gay\u201d","a":89},{"b":"e","i":"533677","t":"Help! The Law Finally Allows Me to Marry My Boyfriend\u2014but He Doesn\u2019t Want To.","a":90},{"b":"d","i":"973495","t":"Hobgood Facial Plastic Surgery to Volunteer at TRI-2-UNIFY Triathlon","a":91},{"b":"e","i":"533665","t":"Reminders of a Bygone Internet","a":92},{"b":"d","i":"973482","t":"SP Plus Corporation Announces Payment Transaction Processing Joint Venture","a":93},{"b":"d","i":"973484","t":"Project will apply cognitive computing to uncover new patient treatment options","a":94},{"b":"d","i":"973485","t":"Food's Latest Scandal: What's Wrong With Your Shrimp","a":95},{"b":"e","i":"533660","t":"It’s Ivanka Trump’s Birthday! She turns 33 | InStyle","a":96},{"b":"d","i":"973466","t":"READ IN: Lowered Expectations Edition","a":97},{"b":"c","i":"1893954","t":"Megyn Kelly Runs Interference For Ferguson Police Department","a":98},{"b":"d","i":"973420","t":"ScienceBased Health Welcomes Ike K. Ahmed, MD, FRSC and Lisa C. Olmos, MD, MBA to Scientific Advisory Board","a":99},{"b":"d","i":"973432","t":"14th Annual Stand Up for Kids Awards Honour Local Child Advocates","a":100}]


      Sweden recognises Palestinian state, draws Israeli anger - Yahoo News UK