Attacks/Breaches
7/6/2010
01:38 PM
50%
50%

Apple App Store Suffers Hack Attack

Company insists user data has not been compromised, but is nonetheless advising customers to watch for suspicious transactions.

Apple said Tuesday that it removed a seller from its online applications store after discovering that he gamed the store's sales ranking system to make it appear as though his e-books accounted for 42 of the site's top 50 electronics books.

Apple said the hack was carried about by a developer named Thuat Nguyen.

"His apps were removed from the App Store for violating the developer Program License Agreement, including fraudulent purchase patterns," Apple said in a statement.

The company did not provide details about how Nguyen managed to rig its sales data. Some observers are speculating that he merely manipulated sales figures, while others believe Nguyen may have actually gained access to App Store user accounts to make unauthorized purchases.

Nguyen listed his Web site as "mycompany", an Internet address that reportedly leads to a domain name parking page.

Apple insisted App Store or iTunes users' information is not at risk as a result of the incident. "Developers do not receive any iTunes confidential customer data when an app is downloaded," the company said.

Still, Apple cautioned its customers to be vigilant for suspicious transactions.

"If your credit card or iTunes password is stolen and used on iTunes we recommend that you contact your financial institution and inquire about cancelling the card and issuing a chargeback for any unauthorized transactions," Apple said.

"We also recommend that you change your iTunes account password immediately," Apple added. Investors shrugged off news about the breach. Apple shares were up .69%, to $248.65, in midday trading Tuesday.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2808
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a rel...

CVE-2014-9713
Published: 2015-04-01
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

CVE-2015-0259
Published: 2015-04-01
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

CVE-2015-0800
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2...

CVE-2015-0801
Published: 2015-04-01
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.