Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/13/2012
02:17 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Apple In-App Store Hacked

Hacker finds way to loot in-app store items and posts a how-to on YouTube.

10 Gorgeous Apps For New iPad
10 Gorgeous Apps For New iPad
(click image for larger view and forslideshow)
A Russian hacker has managed to find a way around the security checks in Apple's in-app purchasing system to make content sold in iOS apps available for free.

The hacker, identifying himself as ZonD80, has posted a YouTube video demonstrating how he was able to create an in-app proxy that authorizes in-app purchases at no cost.

"To buy in-app content," he says in the video,"you must install two certificates and set the IP address of the DNS to a specific IP."

On a Blogger hosted site, he has asked for donations to support the development of his project. The PayPal email address he provides for receipt of funds is a Me.com address, a domain owned by Apple. Presumably this will simplify Apple's effort to identify the hacker, though doing so won't stop the spread of his code: ZonD80 notes on his blog that he has sent the source code and control of the hosting server to someone else.

[ Is Apple environmentally conscious? Read Apple Clean Cloud More Talk Than Walk: Greenpeace. ]

In-app purchasing has become one of the leading sources of revenue for app developers. ABI Research in February predicted that revenue from sale of content in apps will outpace revenue from selling the apps themselves in 2012.

Apple appears to be taking steps to limit the damage. Russian blog i-ekb.ru includes a note, purportedly from ZonD80, indicating that Apple has filed a takedown notice with the service provider of his website.

It's doubtful that Apple will ask Google to remove the hacker's Blogger site--it isn't hosting any code so there might not be any legal foundation to request that Google remove it, unless Apple claims that the domain, in-appstore.com, violates its trademarks.

The hack appears to work on iOS versions 3.0 through 6.0, presently available only in beta form to iOS developers. But not all apps with in-app purchasing are vulnerable. Apple provides a mechanism to validate in-app purchases, in order to allow purchases to be restored on erased or new devices. Developers who have implemented receipt verification, which requires tracking in-app sales using a separate server, can query Apple to confirm the authenticity of purchased items.

Black Hat USA Las Vegas, the premiere conference on information security, features four days of deep technical training followed by two days of presentations from speakers discussing their latest research around a broad range of security topics. At Caesars Palace in Las Vegas, July 21-26. Register today.

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...
CVE-2020-15504
PUBLISHED: 2020-07-10
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other version...
CVE-2020-8190
PUBLISHED: 2020-07-10
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
CVE-2020-8191
PUBLISHED: 2020-07-10
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).