Connecting to LinkedIn...

W1siziisijiwmtuvmdqvmtuvmdgvntqvmzgvnzi1l01ptlrbu0hfqkxpr19vtljftkrfukvex0lnqudfx3jlc2l6zwrfyw5kx3jlbmrlcmvklmpwzyjdlfsiccisinrodw1iiiwimtkymhgxmjuwiyjdxq

Blog

vCard Vulnerability Exposes WhatsApp Users

8/09/2015 by Sharon Shahzad

W1siziisijiwmtuvmdkvmdgvmtuvndgvmzevnjc3l3doyxrzyxbwicgyks5qcgcixsxbinailcj0ahvtyiisijywmhg0mdbcdtawm2uixv0

A vulnerability discovered in WhatsApp Web, the web-based extension of the WhatsApp mobile application, can be exploited by attackers to trick users into executing arbitrary code on their machines.

Discovered by Check Point security researcher Kasif Dekel, the vulnerability can be exploited by simply sending a vCard contact card containing malicious code to a WhatsApp user. As soon as the seemingly innocent vCard is opened in WhatsApp Web, the malicious code in it can run on the target machine.

This vulnerability allows cybercriminals to compromise the affected computer by distributing all types of malware, including ransomware, bots, and remote access tools (RATs), Check Point’s researcher explains.

The underlying issue lies in the improper filtering of contact cards that are sent using the popular ‘vCard’ format. “By manually intercepting and crafting XMPP requests to the WhatsApp servers, it was possible to control the file extension of the contact card file,” the Check Point researcher explained in a blog post.

An attacker can inject a command in the name attribute of the vCard file, separated by the ‘&’ character. Windows automatically tries to run all lines in the file, including the injection line, when the vCard is opened.

This attack does not require XMPP interception of crafting, due to the fact that anyone can create such a contact with an injected payload, directly on the phone, Check Point notes. As soon as the contact is ready, the attacker only needs to share it through the WhatsApp client to unsuspicious users.

This article has been extracted from http://www.securityweek.com, please click on this link to read the article in full http://www.securityweek.com/vcard-vulnerability-exposes-whatsapp-users

Montash is a multi-award winning global technology recruitment business. Specialising in permanent and contract positions across mid-senior appointments across a wide range of industry sectors and IT functions, including:

ERP Recruitment, BI & Data Recruitment, Information Security Recruitment, Enterprise Architecture & Strategy Recruitment , Energy Technology Recruitment, Demand IT and Business Engagement Recruitment, Digital and E-commerce Recruitment, Leadership Talent, Infrastructure and Service Delivery Recruitment, Project and Programme Delivery Recruitment.

Montash is headquartered in Old Street, London, in the heart of the technology hub. Montash has completed assignments in over 30 countries and has appointed technical professionals from board level to senior and mid-management in permanent and contract roles.

comments powered by Disqus

Social Stream

Latest News

W1siziisijiwmtcvmdcvmtgvmdgvndcvmduvntu5l2jpz3n0b2nrluv4b3rpyy1qyxjhzglzzs1ucmf2zwwtvg91cmktmtc2mju4ndm3lmpwzyjdlfsiccisinrodw1iiiwimzgwedewmcmixv0

Getting Ready to Switch Off

2017-07-17 09:00:00 +0100

According to research by online travel company Expedia, just 53% of workers come back feeling rested after they’ve been on holiday. When you bring work-related stress on holiday with you, you’re never going to be able to truly switch off. So if you've got a summer holiday coming up, what should you do to switch off and unwind? Before you leave... Plan ahead As soon as you know when your last day of work is, make a plan. You don't want to get to that fin...

W1siziisijiwmtcvmdyvmzavmtyvmtgvmjavmtg5l3nodxr0zxjzdg9ja182njkxody3mdkuanbnil0swyjwiiwidgh1bwiilcizodb4mtawiyjdxq

In Her Shoes... SAP Contracting

2017-07-03 09:00:00 +0100

In IT, being a freelancer is very common; due to the nature of project work or other life commitments. SAP is an area in which a quality freelancer can really thrive. We sat down with one of our SAP freelancers, who has 20 years' experience, to find out more about SAP and working under a contract employment model. "After getting a degree in computing, I started my career as a training assistant, but I've always liked to fix things. I used to fix my own ...