{"id":6999,"date":"2012-04-05T20:48:24","date_gmt":"2012-04-06T04:48:24","guid":{"rendered":"http:\/\/www.perivision.net\/wordpress\/?p=6999"},"modified":"2012-04-06T12:15:09","modified_gmt":"2012-04-06T20:15:09","slug":"facebook-claims-is-current-vulnerability-is-because-of-jailbreak-oh-really","status":"publish","type":"post","link":"https:\/\/www.perivision.net\/wordpress\/2012\/04\/facebook-claims-is-current-vulnerability-is-because-of-jailbreak-oh-really\/","title":{"rendered":"Facebook claims its current vulnerability is because of jailbreak. Oh really?"},"content":{"rendered":"<p><a href=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-5643\" title=\"facebook locked\" src=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked.jpg\" alt=\"\" width=\"225\" height=\"225\" srcset=\"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked.jpg 225w, https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked-150x150.jpg 150w, https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked-36x36.jpg 36w, https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked-115x115.jpg 115w\" sizes=\"auto, (max-width: 225px) 100vw, 225px\" \/><\/a>The news has been moving around the interwebs on how <a href=\"http:\/\/garethwright.com\/blog\/facebook-mobile-security-hole-allows-identity-theft\">Gareth Wright<\/a> found a security issue with Facebook on the iphone. Seems the key information needed to request and hold a token to Facebook is stored unencrypted in a plist file. Facebook claims that this is not a security risk since its stored in a directory that is not suppose to be accessible by any other application.<\/p>\n<p>Facebook responded:<\/p>\n<blockquote><p>Facebook&#8217;s iOS and Android applications are only intended for use with the manufacture provided operating system, and access tokens are only vulnerable if they have modified their mobile OS (i.e. jailbroken iOS or modded Android) or have granted a malicious actor access to the physical device&#8230;.<\/p><\/blockquote>\n<p>Gareth responded on <a href=\"http:\/\/news.cnet.com\/8301-1009_3-57410237-83\/facebook-says-id-theft-threat-only-on-jailbroken-phones\/?part=rss&amp;subj=news&amp;tag=title\">CNET<\/a>:<\/p>\n<blockquote><p>Wright called Facebook&#8217;s statement &#8220;rubbish,&#8221; adding that the vulnerability is present on both jailbroken and non-jailbroken phones.<\/p><\/blockquote>\n<p>Although I have not tested this myself, given the number of times he was able to successfully access Facebook plists, I think I&#8217;m inclined to believe him.\u00a0 Although I&#8217;m not one for connecting my iphone to ports I do not now, I will be even more careful.\u00a0 However, what do you guys think?<\/p>\n<p>The following is some of the means and devices Gareth created to access the plist.<\/p>\n<p><a href=\"http:\/\/garethwright.com\/wp-content\/uploads\/Multiple-accounts-drawsome1.png\"><img loading=\"lazy\" decoding=\"async\" title=\"Multiple accounts drawsome\" src=\"http:\/\/garethwright.com\/wp-content\/uploads\/Multiple-accounts-drawsome1-150x150.png\" alt=\"\" width=\"150\" height=\"150\" \/><\/a> After contacting Facebook and waiting for a reply took the liberty of\u00a0 knocking together a few proof of concepts.<\/p>\n<p>1) A hidden application which runs on shared PC\u2019s Any device plugged in to charge has the Plist copied<\/p>\n<p>2) A recompile of an open source iphone explorer like program with the added code<\/p>\n<p>3) A saved game editing tool with the added code<\/p>\n<p>4) A credit card sized hardware solution that takes all of two seconds to copy the plist should you have physical access to an iDevice<\/p>\n<p>5)\u00a0 A modified speaker dock<\/p>\n<p>Over the course of a week over 1000 vulnerable plists were located and counted, though I hasten to add at no point was any data copied.<\/p>\n<p>&nbsp;<\/p>\n<div class=\"SPOSTARBUST-Related-Posts\"><H3>Related Posts<\/H3><ul class=\"entry-meta\"><li class=\"SPOSTARBUST-Related-Post\"><a title=\"Ray-Ban Facebook Glasses: Good, Bad, and not quite the AR\" href=\"https:\/\/www.perivision.net\/wordpress\/2021\/09\/ray-ban-facebook-glasses-good-bad-and-not-quite-the-ar\/\" rel=\"bookmark\">Ray-Ban Facebook Glasses: Good, Bad, and not quite the AR<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"Bought a Black Friday cheap tablet?  Better step up security on that thing\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/11\/bought-a-black-friday-cheap-tablet-better-step-up-security-on-that-thing\/\" rel=\"bookmark\">Bought a Black Friday cheap tablet?  Better step up security on that thing<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"WHY would facebook buy Oculus.. Unless&#8230; Second life a la Facebook?\" href=\"https:\/\/www.perivision.net\/wordpress\/2014\/03\/why-would-facebook-buy-oculus-unless-second-life-a-la-facebook\/\" rel=\"bookmark\">WHY would facebook buy Oculus.. Unless&#8230; Second life a la Facebook?<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"New iOS7 UI as a jailbreaker.  Apple shows some Metro love\" href=\"https:\/\/www.perivision.net\/wordpress\/2013\/06\/new-ios7-ui-jailbreak-apple-shows-some-metro-love\/\" rel=\"bookmark\">New iOS7 UI as a jailbreaker.  Apple shows some Metro love<\/a><\/li>\n<li class=\"SPOSTARBUST-Related-Post\"><a title=\"Wow.  iOS 6.1.3 just came out and login bypass hack\" href=\"https:\/\/www.perivision.net\/wordpress\/2013\/03\/ios-6-1-3-login-bypass-hack\/\" rel=\"bookmark\">Wow.  iOS 6.1.3 just came out and login bypass hack<\/a><\/li>\n<\/ul><\/div>","protected":false},"excerpt":{"rendered":"<p>The news has been moving around the interwebs on how Gareth Wright found a security issue with Facebook on the iphone. Seems the key information needed to request and hold a token to Facebook is stored unencrypted in a plist file. Facebook claims that this is not a security risk since its stored in a&hellip; <a class=\"read-more\" href=\"https:\/\/www.perivision.net\/wordpress\/2012\/04\/facebook-claims-is-current-vulnerability-is-because-of-jailbreak-oh-really\/\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":5643,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,755,3,4],"tags":[463,1632,46],"class_list":["post-6999","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fail","category-ios","category-iphone","category-jailbreak","tag-facebook","tag-plist","tag-security"],"jetpack_featured_media_url":"https:\/\/www.perivision.net\/wordpress\/wp-content\/uploads\/2011\/07\/facebook-locked.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pjzQD-1OT","_links":{"self":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/6999","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/comments?post=6999"}],"version-history":[{"count":3,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/6999\/revisions"}],"predecessor-version":[{"id":7008,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/posts\/6999\/revisions\/7008"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/media\/5643"}],"wp:attachment":[{"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/media?parent=6999"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/categories?post=6999"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.perivision.net\/wordpress\/wp-json\/wp\/v2\/tags?post=6999"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}