New WhatsApp bug via MP4 file triggers snooping concerns

Agencies
November 18, 2019

If someone has sent you an MP4 file on WhatsApp, guard against downloading it as hackers may use a critical vulnerability in the Facebook-owned app to execute snooping attack on both Android and iOS devices.

The specially crafted MP4 file triggers the remote code execution (RCE) and denial of service (DoS) cyber attack.

"The vulnerability is classified as 'Critical' severity that affected an unknown code block of the component MP4 File Handler in WhatsApp," reported gbhackers.com on Saturday.

Facebook has issued an advisory, saying "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

"The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

The news comes on the heels of an Israeli software Pegasus by cyber intelligence company NSO Group that exploited its video calling system to snoop on 1,400 selected users globally and in India, including human rights activists and journalists.

The issue snowballed into a political one and the Indian government denied either purchasing or planning to purchase the infamous software in question.

"We agree with the government of India's strong statement about the need to safeguard the privacy of all Indian citizens. That is why we've taken this strong action to hold cyber attackers accountable and why WhatsApp is so committed to the protection of all user messages through the product we provide," a WhatsApp spokesperson had said in a statement.

The new vulnerability is found in Android versions prior to 2.19.274; iOS versions prior to 2.19.100; Enterprise Client versions prior to 2.25.3; Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368.

Hackers can use the WhatsApp vulnerability to deploy the malware on the user's device to steal sensitive files and also used to surveillance purpose.

"The RCE vulnerability allows hackers to perform the attack remotely without any sort of authentication," claimed the report.

The critical WhatsApp vulnerability can be tracked as CVE-2019-11931.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 13,2020

Bengaluru, Mar 13: In the wake of fresh cases of Covid-19 reported in Karnataka, Infosys Foundation chairperson Sudha Murty has urged the Karnataka government to take steps to shut malls and theatres, saying the coronavirus multiplies in air-conditioned areas.

In a letter to the government, she said preventive measures should be taken to control the spread of coronovirus before it gets worse.

Murty, who also leads the State government-constituted Karnataka Tourism Task Force, said she has discussed the current situation with Chairman and Executive Director of Narayana Health, Devi Prasad Shetty.

She suggested closure of all schools and colleges with immediate effect, malls, theatres and “all air-conditioned areas where the virus multiplies”, and allow only essential services like pharmacy, grocery and petrol bunks.

“It is not scientifically proven that the virus dies in high temperature,” she said pointing to spread of the virus -- despite heat -- in peak summer in Australia and Singapore, which have “summer all 12 months”.

“I request you to vacate one government hospital with at least 500 - 700 beds for this purpose (to deal with coronavirus cases), which requires oxygen lines and pipes,” she said.

“Infosys Foundation, the philanthropic and CSR arm of software major Infosys, would do the civil work and Devi Shetty has agreed to share resources like medical equipment,” she added.

“We would like to work with the government proactively so that we can prevent this as early as possible,” Sudha Murty said.

The total number of confirmed coronavirus positive cases in Karnataka is five, including the 76-year old man from Kalaburagi who died on Tuesday night.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
February 27,2020

Feb 27: With the window to submit comments on India's proposed personal data protection law closing on Tuesday, a period of anxious wait for final version of the Bill started for social media firms.

This comes even as global Internet companies have called on the government for improved transparency related to intermediary Guidelines (Amendment) Rules and allay fears about the prospect of increased surveillance and prompting a fragmentation of the Internet in India that would harm users.

As per the proposed amendments, an intermediary having over 50 lakh users in the country will have to be incorporated in India with a permanent registered office and address.

When required by lawful order, the intermediary shall, within 72 hours of communication, provide such information or assistance as asked for by any government agency or assistance concerning security of the state or cybersecurity.

This means that the government could pull down information provided by platforms such as Wikipedia, potentially hampering its functioning in India.

In the open letter to IT Minister Ravi Shankar Prasad, leading browser and software development platform like Mozilla, Microsoft-owned GitHub and Cloudflare earlier called for improved transparency by allowing the public an opportunity to see a final version of these amendments prior to their enactment.

According to a Business Insider report, Indian users may lose access to Wikipedia if the new intermediary rules for internet and social media companies are approved.

Since the rules would require the website to take down content deemed illegal by the government, it would require Wikipedia to show different content for different countries.

Anusha Alikhan, senior communications director for Wikimedia told Business Insider that the platform is built though languages and not geographies. Therefore, removing content from one country, while it is still visible to other country users may not work for the company’s model.

India is one of Wikipedia’s largest markets. Over 771 million Indian users accessed the site in just November 2019.

Also read: Explained: What is the Personal Data Protection Bill and why you should care

The Personal Data Protection Bill, 2019, which was introduced in Lok Sabha in the winter session last year, was referred to a Joint Parliamentary Committee (JPC) of both the Houses.

The government last month decided to seek views and suggestions on the Bill from individuals and associations and bodies concerned and the last date for submitting the comments was on Tuesday.

Prasad, while introducing the Personal Data Protection Bill, 2019, in the Lok Sabha on December 11, announced that the draft Bill empowers the government to ask companies including Facebook, Google and others for anonymised personal data and non-personal data.

There was a buzz when the Bill's latest version was introduced in the Lok Sabha, especially the provision seeking to allow the use of personal and non-personal data of users in some cases, especially when national security is involved.

Several legal experts red-flagged the issue and said the provision will give the government unaccounted access to personal data of users in the country.

In their submission to the JPC, several organisations also flagged that the power to collect non-personal and anonymised data by the government without notice and consent should not form part of the Bill because of issues regarding effective anonymisation and potential abuse.

"Clauses 35 and 36 of the Bill provide unbridled access to personal data to the Central Government by giving it powers to exempt its agencies from the application of the Bill on the basis of various broad worded grounds," SFLC.in, a New Delhi-based not-for-profit legal services organisation, commented.

The Software Alliance, also known as BSA, a trade group which includes tech giants such as Microsoft, IBM and Adobe, among others said that the current version of the privacy bill pose substantial challenges, including the sweeping new powers for the government to acquire non-personal data, restrictions on data transfers, and local storage requirements.

"We urge the Joint Parliamentary Committee, as it considers revisions to the Bill, to eliminate provisions concerning non-personal data from the Personal Data Protection Bill and to remove the data localisation requirements and restrictions on international data flows," said Venkatesh Krishnamoorthy, Country Manager-India, BSA.

The Personal Data Protection (PDP) Bill, 2019 draws its origins from the Justice B.N. Srikrishna Committee on data privacy, which produced a draft of legislation that was made public in 2018 ("the Srikrishna Bill").

The mandatory requirement for storing a mirror copy of all personal data in India as per Section 40 of the Srikrishna Bill has been done away with in the PDP Bill, 2019, meaning that companies like Facebook and Twitter would be able to store data of Indian users abroad if they so wish.

But the bill prohibits processing of sensitive personal data and critical personal data outside India.

What is more, what constitutes critical data has not been clearly defined.

As per the proposals, social media companies will have to modify their application as they are required to have a system in place by which a user can verify themselves.

So legal experts believe that some system to upload identification documents should be there and something like the Twitter blue tick mark should be there to identify verified accounts.

"The 2019 Bill introduces a new category of data fiduciaries called social media intermediaries ('SMIs'). SMIs are a subcategory of significant data fiduciaries ('SDFs') and will be notified by the Central government after due consultation with the DPA, or the Data Protection Authority. Clause 26(4) of the Bill defines SMIs as intermediaries who primarily or solely enable online interaction between two or more users," SFLC.in said.

"On a plain reading of the definition, online platforms like Facebook, Twitter, YouTube, TikTok, ShareChat and WhatsApp are likely to be notified as SMIs under the Bill," it added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 19,2020

Cybersecurity researchers on Monday warned of a Trojan malware campaign which is targeting India's co-operative banks using COVID-19 as a bait.

Seqrite, the enterprise arm of IT security firm Quick Heal Technologies, detected the new wave of Adwind Java Remote Access Trojan (RAT) campaign.

Researchers at Seqrite warned that if attackers are successful, they can take over the victim's device to steal sensitive data like SWIFT logins and customer details and move laterally to launch large scale cyberattacks and financial frauds.

According to the researchers, the Java RAT campaign starts with a spear-phishing email which claims to have originated from either the Reserve Bank of India or a nationalised bank.

The content of the email refers to COVID-19 guidelines or a financial transaction, with detailed information in an attachment, which is a zip file containing a JAR based malware.

Upon further investigation, researchers at Seqrite found that the JAR based malware is a Remote Access Trojan that can run on any machine which has Java runtime enabled and hence it can impact a variety of endpoints, irrespective of their base operating system.

Once the RAT is installed, the attacker can take over the victim's device, send commands from a remote machine, and spread laterally in the network.

In addition, this malware can also log keystrokes, capture screenshots, download additional payloads, and extract sensitive user information, Seqrite said, adding that such attack campaigns can effectively jeopardise the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds.

To prevent such attacks, users need to exercise ample caution and avoid opening attachments and clicking on web links in unsolicited emails.

Banks should also keep their operating systems updated and have a full-fledged security solution installed on all the devices, Seqrite advised.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.