New WhatsApp bug via MP4 file triggers snooping concerns

Agencies
November 18, 2019

If someone has sent you an MP4 file on WhatsApp, guard against downloading it as hackers may use a critical vulnerability in the Facebook-owned app to execute snooping attack on both Android and iOS devices.

The specially crafted MP4 file triggers the remote code execution (RCE) and denial of service (DoS) cyber attack.

"The vulnerability is classified as 'Critical' severity that affected an unknown code block of the component MP4 File Handler in WhatsApp," reported gbhackers.com on Saturday.

Facebook has issued an advisory, saying "A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.

"The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE."

The news comes on the heels of an Israeli software Pegasus by cyber intelligence company NSO Group that exploited its video calling system to snoop on 1,400 selected users globally and in India, including human rights activists and journalists.

The issue snowballed into a political one and the Indian government denied either purchasing or planning to purchase the infamous software in question.

"We agree with the government of India's strong statement about the need to safeguard the privacy of all Indian citizens. That is why we've taken this strong action to hold cyber attackers accountable and why WhatsApp is so committed to the protection of all user messages through the product we provide," a WhatsApp spokesperson had said in a statement.

The new vulnerability is found in Android versions prior to 2.19.274; iOS versions prior to 2.19.100; Enterprise Client versions prior to 2.25.3; Business for Android versions prior to 2.19.104; Business for iOS versions prior to 2.19.100; and Windows Phone versions before and including 2.18.368.

Hackers can use the WhatsApp vulnerability to deploy the malware on the user's device to steal sensitive files and also used to surveillance purpose.

"The RCE vulnerability allows hackers to perform the attack remotely without any sort of authentication," claimed the report.

The critical WhatsApp vulnerability can be tracked as CVE-2019-11931.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 7,2020

New Delhi, Jun 7: The Government of India (GoI) must strengthen the laws to protect animals, said People for the Ethical Treatment of Animals (PETA) India CEO Dr Manilal Valliyate on Sunday, following an elephant's death in Kerala and cow injured due to ingestion of explosives in Himachal Pradesh.

"Such incidents are not just restricted to certain regions but are happening all across the country. PETA receives more than 100 similar cases every day. People send in their complaints to us, not just for cows and elephants but for so many other animals as well," he said.

The PETA chief urged the GoI to strengthen the laws established to protect animals.

"As per the current laws set out against animal cruelty, the perpetrator would only be charged Rs 50,000 as a fine. That is equivalent to no punishment at all," added PETA India CEO.

He expressed his anguish against municipal agencies as well, saying that they are not doing "serious" work. He also highlighted how cows are left on the roads to wander, after milking them, to feed on garbage, in several parts of the country.

"These injustices against animals through explosives has been going on for quite a while. But for the first time, it has received such public attention," he said.

After a pregnant elephant was fed cracker-filled pineapple and her eventual death on May 27 in Kerala's Palakkad district, a pregnant cow sustained fatal injuries on May 25 due to accidental ingestion of explosives in Dadh village of Bilaspur district of Himachal Pradesh.

One person has been arrested in the Dadh village for allegedly hurting the cow.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 9,2020

Soon, you may be able to withdraw cash from an ATM without touching any part of the machine. AGS Transact Technologies, a provider of cash and digital payment solutions and automation technology, on Monday said it has successfully developed and tested a touchless ATM solution in light of the COVID-19 pandemic.

The ‘contactless' solution, currently under demo at interested banks, enables a customer to perform all the steps required to withdraw cash from an ATM using the mobile app itself. 

The customer simply has to scan the QR code displayed on the ATM screen and follow the directions on their respective bank's mobile application. 

This includes entering the amount and mPIN required to dispense the cash from the ATM machine. 

According to the company, the QR code feature makes cash withdrawals quicker and more secure, and negates the chances of compromising the ATM Pin or card skimming.

"The new Touchless ATM solution is an extension of the flagship QR Cash solution which ensures safety of the users and will provide a seamless cash withdrawal experience with enhanced security," said Ravi B. Goyal, Chairman and MD, AGS Transact Technologies Ltd.

With minimum investment, the banks can enable this solution for their ATM networks by upgrading the existing software.

AGSTTL has so far installed, maintained and managed a network of over 72,000 ATMs across the country and also provides customised solutions to leading banks. 

The company earlier introduced UPI-QR based Cash withdrawal solution in partnership with Bank of India. 

This is how the solution works.

Open the Bank mobile application on your smartphone and select QR Cash Withdrawal. Enter the amount you wish to withdraw on the mobile app and scan the QR code on the ATM screen.

Next, confirm the amount by clicking on ‘proceed' in the app and enter the mPin to authenticate the transaction. Now collect the cash and receipt and you are done.

"The seamless, cardless and touchless withdrawal method is designed to provide easy transaction flow, without the need to touch the ATM screen or enter the pin," said Mahesh Patel, President and Group Chief Technology Officer, AGS Transact Technologies.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 22,2020

New delhi, Jun 22: As consumer sentiment runs high amid growing chorus for boycotting Chinese goods in the country, the fluid market situation offers new opportunities for various smartphone makers, especially the non-Chinese ones like Samsung, Apple, Nokia, Asus and others, to realign their strategies and regain the lost market share in the face of fierce Chinese competition.

The challenge here would be not to look "opportunistic" and leverage the current explosive situation on just riding on the anti-Chinese sentiment but to offer real challenges in the form of top-end devices with solid internals at affordable price points, feel industry experts.

"The current market conditions in India are fluid and open up new opportunities for smartphone original equipment manufacturers (OEMs) to focus and leverage," Prabhu Ram, Head-Industry Intelligence Group, CyberMedia Research (CMR), told IANS.

In the first quarter (January-March) this year, Samsung's shipments were driven by its upgraded A and M series (A51, A20s, A30s, and M30s).

According to Counterpoint Research, Samsung managed to hold third position in Q1 2020 due to launches across several price tiers, especially in the affordable premium segment (S10 Lite, Note 10 Lite).

The South Korean smartphone maker last week announced a Rs 4,000 price drop on its popular Galaxy Note10 Lite smartphone that will now cost Rs 37,999 (6GB variant).

Earlier this month, Samsung launched two new smartphones, Galaxy M11 and Galaxy M01, with powerful batteries under Rs 15,000 in India.

Galaxy M11 comes in two variants. The 3GB+32GB will be priced at Rs 10,999 while the higher 4GB+64GB variant will be available for Rs 12,999.

Samsung has also launched an affordable Galaxy A21s smartphone with quad-camera system and 5,000mAh battery at a starting price of Rs 16,499.

Also read: Boycott China? OnePlus 8 Pro sold out within minutes of going on sale

On the other hand, Apple grew a strong 78 per cent YoY driven by strong shipments of iPhone 11 and multiple discounts on platforms like Flipkart and Amazon in Q1, according to Counterpoint.

Apple has also brought its cheapest yet powerful new iPhone SE that costs Rs 38,900 (64GB) in India with a special offer from HDFC Bank. The new iPhone SE is powered by the Apple-designed A13 Bionic, the fastest chip in a smartphone and features the best single-camera system ever in an iPhone.

According to Tarun Pathak, Associate Director, Counterpoint Research, consumer sentiments are running high and a section of users will look for alternatives, benefitting global and Indian brands.

"However, we do not think non-Chinese brands will run aggressive campaigns based on the situation as it might look like being opportunistic," Pathak told media.

It may actually let brands of Chinese origin try to run aggressive campaigns on their presence and scale.

"Some of these Chinese brands have been active in scaling up local value addition, creating jobs and investing in research and development," Pathak noted.

On Saturday, market leader Xiaomi said that it is "more Indian" than any other smartphone brand.

The company's India head Manu Kumar Jain said that the company's mobile phone R&D centre and product team is in India, it employs 50,000 people in the country, the entire leadership team is Indian and that the company pays its taxes in India.

Earlier, Realme India CEO Madhav Sheth who is also very active on social media said that Realme is an Indian startup.

In his latest episode of Ask Madhav' series on YouTube, Sheth said: "I can proudly say Realme is an Indian startup, which is now a global MNC (multinational corporation)".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.