New WhatsApp bug via MP4 file triggers snooping concerns

Agencies
November 18, 2019

If someone has sent you an MP4 file on WhatsApp, guard against downloading it as hackers may use a critical vulnerability in the Facebook-owned app to execute snooping attack on both Android and iOS devices.

The specially crafted MP4 file triggers the remote code execution (RCE) and denial of service (DoS) cyber attack.

"The vulnerability is classified as 'Critical' severity that affected an unknown code block of the component MP4 File Handler in WhatsApp," reported gbhackers.com on Saturday.

Facebook has issued an advisory, saying "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

"The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

The news comes on the heels of an Israeli software Pegasus by cyber intelligence company NSO Group that exploited its video calling system to snoop on 1,400 selected users globally and in India, including human rights activists and journalists.

The issue snowballed into a political one and the Indian government denied either purchasing or planning to purchase the infamous software in question.

"We agree with the government of India's strong statement about the need to safeguard the privacy of all Indian citizens. That is why we've taken this strong action to hold cyber attackers accountable and why WhatsApp is so committed to the protection of all user messages through the product we provide," a WhatsApp spokesperson had said in a statement.

The new vulnerability is found in Android versions prior to 2.19.274; iOS versions prior to 2.19.100; Enterprise Client versions prior to 2.25.3; Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368.

Hackers can use the WhatsApp vulnerability to deploy the malware on the user's device to steal sensitive files and also used to surveillance purpose.

"The RCE vulnerability allows hackers to perform the attack remotely without any sort of authentication," claimed the report.

The critical WhatsApp vulnerability can be tracked as CVE-2019-11931.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 25,2020

In a study conducted in 117 countries, researchers have found that the world is experiencing the most dramatic reduction in the seismic noise (the hum of vibrations in the planet's crust) in recorded history due to global COVID-19 lockdowns.

Measured by instruments called seismometers, seismic noise is caused by vibrations within the Earth, which travel like waves and the waves can be triggered by earthquakes, volcanoes, and bombs - but also by daily human activity like travel and industry.

This quiet period was likely caused by the total global effect of social distancing measures, closure of services and industry, and drops in tourism and travel, the study published in the journal Science, reported.

The new research, led by the Royal Observatory of Belgium and five other institutions around the world including Imperial College London (ICL), showed that the dampening of 'seismic noise' caused by humans was more pronounced in more densely populated areas.

"Our study uniquely highlights just how much human activities impact the solid Earth, and could let us see more clearly than ever what differentiates human and natural noise," said study co-author Stephen Hicks from ICL in the UK.

For the findings, the research team looked at seismic data from a global network of 268 seismic stations in 117 countries and found significant noise reductions compared to before any lockdown at 185 of those stations.

Researchers tracked the 'wave' of quietening between March and May as worldwide lockdown measures took hold.

The largest drops in vibrations were seen in the most densely populated areas, like Singapore and New York City, but drops were also seen in remote areas like Germany's the Black Forest and Rundu in Namibia.

Citizen-owned seismometers, which tend to measure more localised noise, noted large drops around universities and schools around Cornwall, UK and Boston, US - a drop in noise 20 per cent larger than seen during school holidays.

The findings showed that countries like Barbados, where lockdown coincided with the tourist season, saw a 50 per cent decrease in noise.

"The changes have also given us the opportunity to listen in to the Earth's natural vibrations without the distortions of human input," the study authors wrote.

Earlier in April, a study published in the journal Nature, reported at least a 30 per cent reduction in that amount of ambient human noise since lockdown began in Belgium.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 31,2020

Cape Canaveral, May 31: SpaceX, the private rocket company of billionaire entrepreneur Elon Musk, launched two Americans into orbit from Florida on Saturday in a landmark mission marking the first spaceflight of NASA astronauts from U.S. soil in nine years.

A SpaceX Falcon 9 rocket lifted off from the Kennedy Space Center at 3:22 p.m. EDT (19:22 GMT), launching Doug Hurley and Bob Behnken on a 19-hour ride aboard the company’s newly designed Crew Dragon capsule bound for the International Space Station.

Just before liftoff, Hurley said, “SpaceX, we’re go for launch. Let’s light this candle,” paraphrasing the famous comment uttered on the launch pad in 1961 by Alan Shepard, the first American flown into space.

Minutes after launch, the first-stage booster rocket of the Falcon 9 separated from the upper second-stage rocket and flew itself back to Earth to descend safely onto a landing platform floating in the Atlantic.

High above the Earth, the Crew Dragon jettisoned moments later from the second-stage rocket, sending the capsule on its way to the space station.

The exhilarating spectacle of the rocket soaring flawlessly into the heavens came as a welcome triumph for a nation gripped by racially-charged civil unrest as well as ongoing fear and economic upheaval from the coronavirus pandemic.

The Falcon 9 took off from the same launch pad used by NASA’s final space shuttle flight, piloted by Hurley, in 2011. Since then, NASA astronauts have had to hitch rides into orbit aboard Russia’s Soyuz spacecraft.

“It’s incredible, the power, the technology,” said U.S. President Donald Trump, who was at Kennedy Space Center at Cape Canaveral in Florida for the launch. “That was a beautiful sight to see.”

The mission’s first launch attempt on Wednesday was called off with less than 17 minutes remaining on the countdown clock. Weather again threatened Saturday’s launch, but cleared in time to proceed with the mission.

SPACEFLIGHT MILESTONES

NASA chief Jim Bridenstine has said resuming launches of American astronauts on American-made rockets from U.S. soil is the space agency’s top priority.

“I’m breathing a sigh of relief, but I will also tell you I’m not gonna celebrate until Bob and Doug are home safely.” Bridenstine said.

For Musk, the launch represents another milestone for the reusable rockets his company pioneered to make spaceflight less costly and more frequent. And it marks the first time commercially developed space vehicles - owned and operated by a private entity rather than NASA - have carried Americans into orbit.

The last time NASA launched astronauts into space aboard a brand new vehicle was 40 years ago at the start of the space shuttle program.

Musk, the South African-born high-tech entrepreneur who made his fortune in Silicon Valley, is also chief executive of electric carmaker and battery manufacturer Tesla Inc. He founded Hawthorne, California-based SpaceX, formally known as Space Exploration Technologies, in 2002.

Hurley, 53, and Behnken, 49, NASA employees under contract to fly with SpaceX, are expected to remain at the space station for several weeks, assisting a short-handed crew aboard the orbital laboratory.

Boeing Co, producing its own launch system in competition with SpaceX, is expected to fly its CST-100 Starliner vehicle with astronauts aboard for the first time next year. NASA has awarded nearly $8 billion combined to SpaceX and Boeing for development of their rival rockets.

Trump also hailed the launch as a major advance toward the goal of eventually sending humans to Mars.

He was joined at the viewing by Musk, as well as Vice President Mike Pence, Commerce Secretary Wilbur Ross, Education Secretary Betsy DeVos, Florida congressman Matt Gaetz and Senator Rick Scott.

Earlier on Saturday, the crew bid goodbye to their families. Prior to climbing into a specially designed Tesla automobile for the ride to the launch site, Behnken told his young son, “Be good for mom. Make her life easy.”

During the drive, Behnken and Hurley passed former astronaut Garrett Reisman who held a sign saying, “Take me with you.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 14,2020

Social media platform WhatsApp assured the Supreme Court on Wednesday that it will not roll out its payment services without complying with all payment regulations and norms in the country.

A bench headed by Chief Justice S.A. Bobde and comprising Justices Indu Malhotra and Hrishikesh Roy took up the matter through video conferencing. Senior advocate Kapil Sibal, representing the social media platform, said "WhatsApp Inc makes a statement on behalf of his client that they will not go ahead with the payments' scheme without complying with all the regulations in force."

The statement was made during the hearing of a petition seeking a ban on payment through WhatsApp, as it does not conform to the data localization norms. The top court took the assurance made by WhatsApp on record.

WhatsApp made the statement during the hearing of a plea seeking a ban on its payment service, for not being in line with data localization norms.

In 2018, WhatsApp was granted a beta licence to launch its payment service, but a dedicated and separate app is yet to be launched. A petition was moved in the apex court that WhatsApp's existing model for its payments service should be declared inconsistent with the Unified Payment Interface (UPI) Scheme, as a separate dedicated app has not been offered by the company.

The petitioner NGO, Good Governance Chambers, argued that the National Payments Corporation of India (NPCI) and the Reserve Bank of India (RBI) must change its model on the lines of the UPI payment scheme, and its operations may be suspended until these conditions are met.

The apex court today asked the Centre, Facebook and WhatsApp to file their replies within three weeks and it will take up the matter thereafter. The court noted that the government may process the applications filed by WhatsApp in accordance with the law and there is no stay on the same. Facebook was represented by senior advocate Arvind Datar.

The petitioner argued that lapses have been found in relation to WhatsApp's claims of having a secure and safe technological interface for securing sensitive user data.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.