TikTok fixes vulnerability that allowed hackers full control over user accounts

SHARE:

TikTok has confirmed that it has fixed a vulnerability that allowed hackers to manipulate content, upload unauthorized videos, make private ...

TikTok has confirmed that it has fixed a vulnerability that allowed hackers to manipulate content, upload unauthorized videos, make private ‘hidden’ videos public, delete videos, and extract confidential information of users via an SMS containing a malicious link. The company says most of the fixes were on the back-end and users are recommended to update their apps to the latest version to be on the safe side.

A Check Point Research report revealed the bug by mentioning it in a blog post. The bug allowed potential hackers to send an SMS message to a mobile number on behalf of TikTok. While the functionality is available on the official TikTok website to let users download the app, hackers could capture HTTP request using a proxy tool and spoof a message that contained harmful links. The link could redirect users to a malicious website, launching Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Sensitive Data Exposure attacks. 

The report also notes that TikTok employed an unconventional JSONP callback, which allows to request data from API servers without CORS and SOP restrictions. As a result, data could be stolen by initiating an AJAX request. Thankfully, Check Point Research informed TikTok about the vulnerability before making the findings public.

Luke Deshotels from TikTok Security Team said, “TikTok is committed to protecting user data. Like many organisations, we encourage responsible security researchers to privately disclose zero-day vulnerabilities to us. Before public disclosure, CheckPoint agreed that all reported issues were patched in the latest version of our app. We hope that this successful resolution will encourage future collaboration with security researchers.”



from Latest Technology News https://ift.tt/2TdNEr8

COMMENTS

Name

7,1,Airtel,1,Andriod,1,Android,4,Android Q,1,apex,1,Apple,7,Apps,1,Asus Rog,1,Black Shark 2,2,Boeing 737 MAX,1,Bsnl,2,camera,2,CPU,3,Donald Trump,1,Earphone,1,Facebook,5,Fan,1,Fitbit,1,foldable Phone,2,Fortnite,1,Galaxy A40,1,Galaxy s10,1,Galaxy s10e,1,Games,10,gaming,1,Google,6,Google Pixel 2,1,Honor 10i,1,Huawe,1,Huawei,6,Huawei GT,1,IBM,1,Instagram,2,Internet,2,ios,2,iPad,2,iphone,2,Israel,1,jiomart,1,Laptop,1,Leica Q2,1,M20,1,mac,1,MacOS,1,Mi 9,1,Mi A2,1,Mi LED TV,1,MicroSoft,3,mobile,1,Moon,2,Mozilla,1,Nasa,2,News,1,Nokia,4,Nokia 62,1,Nvidias,1,OnePlus,4,Oppo,5,P30,3,Pixel,1,Poco F1,1,Pubg,12,Qualcomm,2,Redmi 3,1,Redmi 6 Pro,1,Redmi 7,1,Redmi Note 7,1,reliance,1,Reno,1,samsung,11,Skype,1,SmartPhone,56,Social,5,Spotify,1,Tech,35,Telecom,3,Touchpad,1,Tournament,1,TV,1,Twitter,1,Vivo,2,Watch,2,WhatsApp,1,Xbox,1,Xiaomi,16,y9li,1,
ltr
item
Genius Baba: TikTok fixes vulnerability that allowed hackers full control over user accounts
TikTok fixes vulnerability that allowed hackers full control over user accounts
http://feeds.feedburner.com/~r/digit/latest-news/~4/iSkRyE40lAY
Genius Baba
https://geniusbabaa.blogspot.com/2020/01/tiktok-fixes-vulnerability-that-allowed.html
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/
https://geniusbabaa.blogspot.com/2020/01/tiktok-fixes-vulnerability-that-allowed.html
true
7104319406113350277
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy