New WhatsApp bug via MP4 file triggers snooping concerns

Agencies
November 18, 2019

If someone has sent you an MP4 file on WhatsApp, guard against downloading it as hackers may use a critical vulnerability in the Facebook-owned app to execute snooping attack on both Android and iOS devices.

The specially crafted MP4 file triggers the remote code execution (RCE) and denial of service (DoS) cyber attack.

"The vulnerability is classified as 'Critical' severity that affected an unknown code block of the component MP4 File Handler in WhatsApp," reported gbhackers.com on Saturday.

Facebook has issued an advisory, saying "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

"The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

The news comes on the heels of an Israeli software Pegasus by cyber intelligence company NSO Group that exploited its video calling system to snoop on 1,400 selected users globally and in India, including human rights activists and journalists.

The issue snowballed into a political one and the Indian government denied either purchasing or planning to purchase the infamous software in question.

"We agree with the government of India's strong statement about the need to safeguard the privacy of all Indian citizens. That is why we've taken this strong action to hold cyber attackers accountable and why WhatsApp is so committed to the protection of all user messages through the product we provide," a WhatsApp spokesperson had said in a statement.

The new vulnerability is found in Android versions prior to 2.19.274; iOS versions prior to 2.19.100; Enterprise Client versions prior to 2.25.3; Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368.

Hackers can use the WhatsApp vulnerability to deploy the malware on the user's device to steal sensitive files and also used to surveillance purpose.

"The RCE vulnerability allows hackers to perform the attack remotely without any sort of authentication," claimed the report.

The critical WhatsApp vulnerability can be tracked as CVE-2019-11931.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 24,2020

New Delhi, Jun 24: The Centre has made it mandatory for sellers to enter the 'Country of Origin' while registering all new products on government e-marketplace (GeM).

The e-marketplace is a special purpose vehicle (SPV) under the Ministry of Commerce and Industry which facilitates the entry of small local sellers in public procurement, while implementing 'Make in India' and MSE Purchase Preference Policies of the Centre.

Accordingly, the ministry said the move has been made to promote 'Make in India' and 'Atma Nirbhar Bharat'.

The provision has been enabled via the introduction of new features on GeM.

Besides the registration process, the new feature also reminds sellers who have already uploaded their products, to disclose their products' 'Country of Origin' details.

The ministry further said that failing to disclose the detail will lead to removal of the products from the e-marketplace.

"GeM has taken this significant step to promote 'Make in India' and 'Aatmanirbhar Bharat'," the ministry said in a statement.

"GeM has also enabled a provision for indication of the percentage of local content in products. With this new feature, now, the 'Country of Origin' as well as the local content percentage are visible in the marketplace for all items. More importantly, the 'Make in India' filter has now been enabled on the portal. Buyers can choose to buy only those products that meet the minimum 50 per cent local content criteria."

In case of bids, the ministry said that buyers can now reserve any bid for a "Class I Local suppliers. For those bids below Rs 200 crore, only Class I and Class II Local Suppliers are eligible to bid, with Class I supplier getting purchase preference".

In addition to this, the Department for Promotion of Industry and Internal Trade (DPIIT) has reportedly called for a meeting with all e-commerce companies such as Amazon and Flipkart to display the country of origin on the products sold on their platform, as well as the extent of value added in India.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 31,2020

Cape Canaveral, May 31: SpaceX, the private rocket company of billionaire entrepreneur Elon Musk, launched two Americans into orbit from Florida on Saturday in a landmark mission marking the first spaceflight of NASA astronauts from U.S. soil in nine years.

A SpaceX Falcon 9 rocket lifted off from the Kennedy Space Center at 3:22 p.m. EDT (19:22 GMT), launching Doug Hurley and Bob Behnken on a 19-hour ride aboard the company’s newly designed Crew Dragon capsule bound for the International Space Station.

Just before liftoff, Hurley said, “SpaceX, we’re go for launch. Let’s light this candle,” paraphrasing the famous comment uttered on the launch pad in 1961 by Alan Shepard, the first American flown into space.

Minutes after launch, the first-stage booster rocket of the Falcon 9 separated from the upper second-stage rocket and flew itself back to Earth to descend safely onto a landing platform floating in the Atlantic.

High above the Earth, the Crew Dragon jettisoned moments later from the second-stage rocket, sending the capsule on its way to the space station.

The exhilarating spectacle of the rocket soaring flawlessly into the heavens came as a welcome triumph for a nation gripped by racially-charged civil unrest as well as ongoing fear and economic upheaval from the coronavirus pandemic.

The Falcon 9 took off from the same launch pad used by NASA’s final space shuttle flight, piloted by Hurley, in 2011. Since then, NASA astronauts have had to hitch rides into orbit aboard Russia’s Soyuz spacecraft.

“It’s incredible, the power, the technology,” said U.S. President Donald Trump, who was at Kennedy Space Center at Cape Canaveral in Florida for the launch. “That was a beautiful sight to see.”

The mission’s first launch attempt on Wednesday was called off with less than 17 minutes remaining on the countdown clock. Weather again threatened Saturday’s launch, but cleared in time to proceed with the mission.

SPACEFLIGHT MILESTONES

NASA chief Jim Bridenstine has said resuming launches of American astronauts on American-made rockets from U.S. soil is the space agency’s top priority.

“I’m breathing a sigh of relief, but I will also tell you I’m not gonna celebrate until Bob and Doug are home safely.” Bridenstine said.

For Musk, the launch represents another milestone for the reusable rockets his company pioneered to make spaceflight less costly and more frequent. And it marks the first time commercially developed space vehicles - owned and operated by a private entity rather than NASA - have carried Americans into orbit.

The last time NASA launched astronauts into space aboard a brand new vehicle was 40 years ago at the start of the space shuttle program.

Musk, the South African-born high-tech entrepreneur who made his fortune in Silicon Valley, is also chief executive of electric carmaker and battery manufacturer Tesla Inc. He founded Hawthorne, California-based SpaceX, formally known as Space Exploration Technologies, in 2002.

Hurley, 53, and Behnken, 49, NASA employees under contract to fly with SpaceX, are expected to remain at the space station for several weeks, assisting a short-handed crew aboard the orbital laboratory.

Boeing Co, producing its own launch system in competition with SpaceX, is expected to fly its CST-100 Starliner vehicle with astronauts aboard for the first time next year. NASA has awarded nearly $8 billion combined to SpaceX and Boeing for development of their rival rockets.

Trump also hailed the launch as a major advance toward the goal of eventually sending humans to Mars.

He was joined at the viewing by Musk, as well as Vice President Mike Pence, Commerce Secretary Wilbur Ross, Education Secretary Betsy DeVos, Florida congressman Matt Gaetz and Senator Rick Scott.

Earlier on Saturday, the crew bid goodbye to their families. Prior to climbing into a specially designed Tesla automobile for the ride to the launch site, Behnken told his young son, “Be good for mom. Make her life easy.”

During the drive, Behnken and Hurley passed former astronaut Garrett Reisman who held a sign saying, “Take me with you.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 18,2020

New Delhi, Jun 18: Vodafone Idea on Thursday told the Supreme Court that it has incurred Rs 1 lakh crore losses as it insisted it is not in a position to furnish bank guarantees.

A bench comprising Justices Arun Mishra, S. Abdul Nazeer, and M.R. Shah, taking up the adjusted gross revenue (AGR) matter through video conferencing, directed the telecom companies to submit their financial documents and books for the last 10 years.

Asking Vodafone if it was a foreign company, the bench said that how can the company say it would not furnish any bank guarantee.

"What if you fly away overnight in future without paying anything?" it asked.

Senior advocate Mukul Rohatgi, representing Vodafone Idea, denied his client is a completely foreign firm and cited before the bench its tie-ups and investments.

Vodafone owes over Rs 58,000 crore as AGR dues and so far, has paid close to Rs 7,000 crore.

Rohatgi contended before the court that the telecom company is in a tough situation, and cannot furnish any fresh bank guarantee, as profits have eluded the company in past many quarters. He submitted before the bench that Rs 15,000 crore bank guarantees are lying with the government, and his client's losses are over Rs 1 lakh crore.

"I cannot offer any more surety," he informed the bench.

Justice Mishra noted that this is public money and these dues should be recovered. "Do not tell us that you will pay if you were to make profits... the money must come," he noted.

Justice Shah observed that the telecom industry is the only industry which earned during the Covid-19 pandemic. "After all, this money will be used for public welfare", he said.

Rohatgi argued that his client would have to fold up if orders were issued to clear dues tomorrow. "11,000 employees will have to go without notice, as we cannot pay them," he added.

Senior advocate Abhishek Manu Singhvi, appearing for Bharti Airtel, contended before the court that out of Rs 21,000 crore AGR dues, the company has already deposited a sum of Rs 18,000 crore.

He argued that his client has given a bank guarantee, in excess of demand, to DoT, and supported the proposal for phased repayment of remaining AGR dues. He insisted that the company needs to sit down with the government and calculate the dues. Airtel owes Rs 25,976 crore after paying Rs 18,000 crore, as per the government.

Senior advocate Arvind Datar, representing Tata Telecom, informed the bench that his client has paid Rs 6,504 crore in AGR dues so far, and furnishing a bank guarantee may adversely impact investments in the sector.

The total AGR dues are close to Rs 1.5 lakh crore.

The top court will now take up the matter in the third week of July.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.