A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) Bilawal Bhutto blasts Pakistan govt: Why are terrorists who attack other nations free?, Global : Today Indya

Latest News

WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE
Friday, February 7, 2020 IST
WhatsApp Bug Allows Malicious Code-Injection, One-Click RCE

A high-severity vulnerability could allow cybercriminals to push malware or remotely execute code, using seemingly innocuous messages.

 
 

Security researchers have identified a JavaScript vulnerability in the WhatsApp desktop platform that could allow cybercriminals to spread malware, phishing or ransomware campaigns through notification messages that appear completely normal to unsuspecting users. And, further investigation shows this could be parlayed into remote code-execution.
 
The desktop platform has more than 1.5 billion monthly active users. The high-severity bug (rated 8.2 on the CVSS severity scale) could impact those that also use WhatsApp for iPhone, if they don’t update their desktop and mobile apps, and if they don’t use newer versions of the Chrome browser.
 
“A vulnerability [CVE-2019-1842] in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting (XSS) and local file reading,” according to the National Vulnerability Database. “Exploiting the vulnerability requires the victim to click a link preview from a specially crafted text message.”
 
More specifically, “The flaws leave users vulnerable to attacks by allowing both the text content and links in website previews to be tampered with to display false content and modified links that point to malicious destinations,” PerimeterX founder and CTO Ido Safruti wrote in a blog post, on Tuesday.
 
Bad actors can inject harmful code or links into “seemingly innocuous exchanges,” according to Safruti, causing unsuspecting users to click on malicious links that appear to them like messages from a friend.
 
“These message modifications would be completely invisible to the untrained eye,” he wrote. “Such attacks would be possible by simply modifying the JavaScript code of a single message prior to delivery to its recipient.”
 
However, the end game is remote code-execution — a potential outcome in some browsers, according to the researchers.
 
Bug Details
 
PerimenterX cybersecurity researcher and JavaScript expert Gal Weizman first discovered vulnerabilities leading to this latest bug in WhatsApp in 2017. He broke down the journey to discovering the latest flaw and its potential for leading to RCE in a separate post. He also said he has been working with Facebook, which owns and oversees WhatsApp, to fix the issues.
 
In his breakdown, Weizman showed how he  started by tampering with the JavaScript for the rich preview banners of messages—the ones that include extra information regarding a link that is in the body of the message.
 
 
Through the WhatsApp desktop platform, Weizman was able to find the code where messages are formed, tamper with it and then let the app continue in its natural message-sending flow. This bypassed filters and sent the modified message through the app as usual, appearing relatively normal in the user interface. Weizman also found that website previews, displayed when users share web links, can also be tampered with before being shown.
 
In this way, it’s possible to inject links that redirect a user to malicious web pages or that initiate malware downloads. Further, the researcher discovered that he could also make those links look like authentic domain links — i.e., as if they really come from Facebook or other legitimate website.

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
'Worse than prison': A rare look inside China's detention camps to 'brainwash' Muslims

ALMATY: Hour upon hour, day upon day, Omir Bekali and other detainees in far western China's new indoctrination camps had to disavow the...

Recently posted . 225K views . 1 min read
 

 Article
What The Shape Of Your Belly Button Says About Your Health

If you have payed attention to the belly buttons of people on the beach or the members of your family, you have probably noticed that they have different shapes and...

Recently posted . 10K views . 2 min read
 

 Article
New ‘Langya’ virus hits China as 35 people found infected: How deadly is it?

The Langya henipavirus has a place with a similar group of infections, including Nipah, which is known to kill up to 3/4 of people in extreme cases.

Recently posted . 6K views . 1 min read
 

 Article
Queen Elizabeth Dies At 96: The New Royal Line Of Succession

Queen's death: The eldest of her four children, Charles, Prince of Wales, who at 73 was the oldest heir apparent in British history, became king immediately...

Recently posted . 6K views . 1 min read
 

 
 

More in Electronics & Gadgets

 Article
Zomato data hacked: 17 million emails, passwords stolen but ‘payment details safe’

Online food aggregator Zomato said on Thursday its website was hacked, and 17 million client email locations and passwords were stolen from its database. In any cas...

Recently posted. 1K views . 14 min read
 

 Article
Fossils Show World-Wide Catastrophe On The Day Dinosaurs Died

Ancient fish died within the first minutes or hours after the asteroid hit, according to a paper published Friday in Proceedings of the National Academy of Scienc...

Recently posted. 1K views . 1 min read
 

 Article
The decline of Afghanistan's Hindu and Sikh communities

"I am an Afghan first... But if our life is under threat, if our families are faced with risks, we have to leave."

Recently posted. 1K views . 0 min read
 

 Article
France Records All-Time Hottest Temperature At 45 Degrees Celsius: Weather Service

The record was set in the village of Villevieille in the southern department of Gard, which registered a high of 45.1 degrees Celsius.

Recently posted. 860 views . 0 min read
 

 Article
When Google didn’t know the answer: From fake news to Aadhaar helpline

Gaffes, missteps and outright blunders in the journey from search engine to one of the world’s most valuable conglomerates.

Recently posted. 1K views . 0 min read
 

 
 
 

   Prashnavali

  Thought of the Day

"A person should not be too honest. Straight trees are cut first and Honest people are screwed first."
Chanakya

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top