• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

76 Popular Apps Vulnerable to Data Interception, Warns iOS Security Researcher

February 7, 2017 by Wayne Wilson 3 Comments

At least 76 popular iOS apps found to have risks for data interception. At the time of the findings, more than 18,000,000 apps downloaded from Apple’s App Store. Popular apps such as Snapchap and various banking apps are among the known vulnerable apps. The vulnerable apps failed to make use of the Transport Layer Security Protocol. Without this security, applications are susceptible to data interception by hackers. The developers of the application must make fix.  Apple is unable to address at OS level because changes there can open up additional holes in security. The current work around is not to use applications effected by this flaw on public Wi-Fi but rather use data service provided by cellular company.

https://www.macrumors.com/2017/02/07/popular-ios-apps-vulnerable-interception/

Filed Under: Week 03 Tagged With:

Reader Interactions

Comments

  1. Loi Van Tran says

    February 7, 2017 at 4:31 pm

    Hi Wayne,

    Thanks for posting this interesting read. I got a little curious and tracked down the list of 76 apps that was mentioned in the article which is provided in the link below. Most of the low priorities app, I’ve never even heard of and unfortunately the Medium/High risk were not disclosed. It also provided a list of past occurrences and I was surprised to see CISCO WebEx on there. I will definitely wait to see the Medium/high risks ones to see if it’s an app that I use.

    Log in to Reply
    • Loi Van Tran says

      February 7, 2017 at 4:40 pm

      https://medium.com/@chronic_9612/76-popular-apps-confirmed-vulnerable-to-silent-interception-of-tls-protected-data-2c9a2409dd1#.sg5vve94f

      Log in to Reply
  2. Jason A Lindsley says

    February 8, 2017 at 7:10 pm

    Thanks for tracking this down Loi Van. That is pretty ironic that the app I use for this class was at one time vulnerable! I am not very familiar with the low and medium priority apps. Hopefully, the developers fix these apps or the rest are released soon!

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in