New WhatsApp bug via MP4 file triggers snooping concerns

Agencies
November 18, 2019

If someone has sent you an MP4 file on WhatsApp, guard against downloading it as hackers may use a critical vulnerability in the Facebook-owned app to execute snooping attack on both Android and iOS devices.

The specially crafted MP4 file triggers the remote code execution (RCE) and denial of service (DoS) cyber attack.

"The vulnerability is classified as 'Critical' severity that affected an unknown code block of the component MP4 File Handler in WhatsApp," reported gbhackers.com on Saturday.

Facebook has issued an advisory, saying "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

"The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

The news comes on the heels of an Israeli software Pegasus by cyber intelligence company NSO Group that exploited its video calling system to snoop on 1,400 selected users globally and in India, including human rights activists and journalists.

The issue snowballed into a political one and the Indian government denied either purchasing or planning to purchase the infamous software in question.

"We agree with the government of India's strong statement about the need to safeguard the privacy of all Indian citizens. That is why we've taken this strong action to hold cyber attackers accountable and why WhatsApp is so committed to the protection of all user messages through the product we provide," a WhatsApp spokesperson had said in a statement.

The new vulnerability is found in Android versions prior to 2.19.274; iOS versions prior to 2.19.100; Enterprise Client versions prior to 2.25.3; Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368.

Hackers can use the WhatsApp vulnerability to deploy the malware on the user's device to steal sensitive files and also used to surveillance purpose.

"The RCE vulnerability allows hackers to perform the attack remotely without any sort of authentication," claimed the report.

The critical WhatsApp vulnerability can be tracked as CVE-2019-11931.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 30,2020

The GST Council is unlikely to make major changes in the indirect tax structure at its next meeting slated mid June.

A top government source said that the Centre is not in favour of increasing tax rates on any goods or service as it could further impact consumption and demand that is already suppressed due the COVID-19 pandemic and lockdown.

It was widely expected that the GST Council could consider raising tax rates and cess on certain non-essential items to boost revenue for states and the Centre. Several states have reportedly taken an over 80-90 per cent hit in GST collections in April, the official data for which has not yet been released by the Centre.

"The need of the hour is to boost consumption and improve demand. By categorising items into essential and non-essential and then raising taxes on non-essential is not what Centre favours. But, the issue on rates and relief will be decided by the GST Council that is meeting next month," the finance ministry official source quoted above said.

The GST Council is chaired by the Union finance minister and thus the views of the Centre play out strongly in the council meetings.

However, the Council will also have to balance the expectations of the states whose revenues have nosedived after the coronavirus outbreak and wide scale disruption to businesses while they have still not been paid GST compensation since the December-January period.

To the question of wider scale job losses in the period of lockdown as businesses get widely impacted, the official said that the Finance Ministry has asked the labour ministry to collect data on job losses during Covid-19 and is constantly engaging with the ministry to oversee job losses and salary cuts.

On restrictions put on Chinese investment in India, the official clarified that no decision had yet been taken to restrict China through the Foreign Portfolio Investment (FPI) route.

Asked about monetising government debt, the official said that the issue would be looked at when we reach a stage. It has not come to that stage yet.

In the government's over Rs 20 lakh crore economic package, the official defended its structure while suggesting that comparisons with the economic packages of other countries should not be drawn as India's needs were different from others.

"We have gone in more reforms that is needed to give strength to the economy. This is required more in our country," the official source said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
April 17,2020

New Delhi, Apr 17: The Indian Railways turned 167 years old on Thursday and for the first time ever, its trains did not carry any passengers on its birthday and instead stood idle in the yards waiting for the nationwide lockdown to end.

On this day 167 years ago, the wheels of the first passenger train in the country from Mumbai to Thane started rolling.

In 1974, Indians experienced life without trains for the first time. In May 1974 during the strike of the railways that lasted for around three weeks, drivers, station masters, guards, track staff and many others went on 'chakka jam' demanding fixed working hours for train drivers and an across-the-board pay hike.

"I can recall those times vividly. I remember that our leader George Fernandes had almost secured a deal with the then railway minister, but it fell through when it was taken to the then Prime Minister Indira Gandhi," All India Railwaymens Federation General Secretary Shiv Gopal Mishra, who was an apprentice in the railways at that time, told PTI.

"Fernandes was arrested in Lucknow. The workers went through a lot at that time. But those were days that angry workers had refused to give in and took great risks to get their demands met," he said.

However, just like this time, four decades ago too freight trains carrying essential supplies were run and the unions agreed to let some passenger trains run on the trunk routes like the Kalka Mail from Howrah to Delhi.

"Never ever in its history, there has been such a long interruption of services. Not during the World Wars, not during the 1974 railway strike, or any other national calamity or natural disaster," a railway spokesperson said.

The first Indian Railways passenger train was flagged off on April 16, 1853, from Mumbai to nearby Thane.

On Thursday, the Railway Ministry wished the railways a happy birthday on Twitter - "Today, 167 years ago with the zeal of 'never to stop' the wheels of the first passenger train from Mumbai to Thane started rolling. For the first time, passenger services are stopped for your safety. Stay indoors & make the nation victorious," it said.

Railway has suspended all passenger services since March 25 till May 3 due to the coronavirus outbreak. Around 15,523 trains run by the railways have been affected including 9,000 passenger trains and 3,000 mail express services which are run daily. It caters to over 20 million passengers every day.

According to the Union health ministry, the death toll due to coronavirus rose to 414 and the number of cases to 12,380 in the country on Thursday.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 19,2020

New Delhi, Jul 19: Three of the 10 most valued companies added a total of Rs 98,622.89 crore to their market valuation last week, led by stellar gains in IT major Infosys.

Seven companies from the coveted list witnessed a decline in their market valuation last week, but their cumulative loss of Rs 37,701.1 crore was less than the total gain made by three firms -- Reliance Industries Limited, Hindustan Unilever Limited and Infosys.

The market capitalisation of Infosys zoomed Rs 52,046.87 crore to Rs 3,85,027.58 crore. Shares of Infosys had rallied over 9 per cent on Thursday after the company posted a stronger-than-expected 12.4 per cent rise in the first quarter consolidated net profit.

Hindustan Unilever Limited added Rs 25,751.07 crore in its market valuation which stood at Rs 5,48,232.26 crore at close on Friday. Reliance Industries' m-cap jumped Rs 20,824.95 crore to Rs 12,11,682.08 crore.

In contrast, HDFC's valuation plunged Rs 13,920.21 crore to Rs 3,13,269.70 crore and that of Tata Consultancy Services (TCS) declined Rs 7,617.34 crore to Rs 8,26,031.21 crore.

The valuation of ICICI Bank tumbled Rs 4,205.71 crore to Rs 2,29,156.24 crore and that of Kotak Mahindra Bank by Rs 4,175.28 crore to Rs 2,62,864.37 crore.

Bharti Airtel's m-cap dipped Rs 4,009.83 crore to Rs 3,09,521.05 crore and HDFC Bank's by Rs 3,403.97 crore to Rs 6,03,463.97 crore.

The valuation of ITC declined by Rs 368.76 crore to Rs 2,38,469.29 crore.

In the ranking of top-10 firms, RIL was at the number one rank followed by TCS, HDFC Bank, HUL, Infosys, HDFC, Bharti Airtel, Kotak Mahindra Bank, ITC and ICICI Bank.

During the last week, the 30-share BSE index advanced 425.81 points or 1.16 per cent.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.