Category: General|Jan 9, 2020 | Author: Admin

Researchers found critical gaps in TikTok: - Security breaches are becoming epidemic

Share on

Attackers could take over accounts.

Attackers could take over accounts.

TikTok is one of the world's largest social media giants with its 1.5 billion users. But the security of the app has been anything but satisfactory - security company Check Point Research can reveal.

False SMS
The company has discovered that personal information, such as private addresses and e-mail addresses, has been exposed for a long time. Not only one vulnerability has been detected, but several, says Check Point Research.

Through a fake SMS containing a malicious link, the attackers could take over TikTok accounts and manipulate the content, for example by deleting videos, uploading unauthorized videos, and publishing private or "hidden" videos.

- Data usage is extensive and security breaches are becoming epidemic, and our latest research in the area shows that the most popular apps are still at risk. Social media applications are very vulnerable to vulnerability because they represent a good attack surface. Hackers use huge sums of money and effort to penetrate these huge applications. Most users still live under the condition that they are protected through the app they use, says Nils-Ove Gamlem, chief technology officer at Check Point Norway.

Notified TikTok - bug fix launched
Check Point Research's investigations also revealed that TikTok's subdomain, https://ads.tiktok.com, was vulnerable to XXS attacks. This is a type of attack where malicious script is placed on usually reliable websites. According to the researchers, this vulnerability could be used to steal personal information, including email addresses and gender and birth date information.

After the findings were discovered, Check Point Research provided information to TikTok. The company should have initiated internal investigations and a bug fix that sealed the holes was later launched.

- TikTok is committed to protecting user data. Like many organizations, we encourage serious security researchers to report zero-day vulnerabilities to us. Prior to publication, all reported events were patched in the latest version of our app, in agreement with Check Point. We hope this successful solution will stimulate a future collaboration with security researchers, says Luke Deshotel of the TikTok Security Team.

Here's how to attack:

Sponsored Ads:

Comments:


New Windows 11 test hides something Microsoft has not touched in decades

Category: Microsoft|Jan 23, 2022 | Author: Admin

MediaTek shows the world’s first live demos of Wi-Fi 7 technology

Category: IT|Jan 22, 2022 | Author: Admin

iOS 15-hole leaked private Apple ID data to third-party apps

Category: Apple|Jan 21, 2022 | Author: Admin

Had to crisis-postpone new 5G standard in the US to avoid plane chaos

Category: IT|Jan 20, 2022 | Author: Admin

No one found out that the iPhone 13 is missing this until now

Category: Apple|Jan 19, 2022 | Author: Admin

Safari leaks your browser history

Category: General|Jan 18, 2022 | Author: Admin

Chromium Trouble - Can't change default search engine anymore

Category: Google|Jan 17, 2022 | Author: Admin

Here, developers are allowed by Apple to offer alternative payment methods

Category: Apple|Jan 16, 2022 | Author: Admin

Microsoft refuses to correct the error - took matters into its own hands

Category: Microsoft|Jan 15, 2022 | Author: Admin

Now Meta gets the authorities on its neck, again

Category: General|Jan 14, 2022 | Author: Admin

Has invested heavily in podcasts - now Spotify is closing down the studio

Category: General|Jan 13, 2022 | Author: Admin

Claims HomePod mini is on its way to Norway

Category: General|Jan 12, 2022 | Author: Admin

Linux gets the function everyone wants

Category: IT|Jan 11, 2022 | Author: Admin

Flasher RTX 3080 Ti with 3090 BIOS for extra efficient Ethereum mining

Category: General|Jan 10, 2022 | Author: Admin

Dice continues to destroy for himself: removed favorite from Battlefield 2042

Category: General|Jan 9, 2022 | Author: Admin
more