THE KNOWLEDGE IS THE WORK.
Resources(82)
Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027)
Chariton Karamitas
CENSUS has been investigating for some time now the exploitation potential of Man-in-the-Disk (MitD) vulnerabilities in Android. Recently, CENSUS identified two such vulnerabilities in the popular WhatsApp messenger app for Android. The first of these was possibly independently reported to Facebook and was found to be...
Canary Mail and MailCore2 library missing certificate validation check on IMAP STARTTLS
Rayd Debbas
CENSUS identified that the Canary Mail software in versions 3.20 and 3.21 (and possibly previous versions) is missing a certificate validation check when performing an IMAP connection configured with STARTTLS.
The Known Beacons Attack (34th Chaos Communication Congress)
George Chatzisofroniou
The recent key reinstallation attacks (KRACK) against the WPA2 protocol revealed how an adversary can easily eavesdrop, and in some cases tamper, a Wi-Fi connection secured by the WPA2 protocol. At the same time, Wi-Fi automatic association attacks achieve a similar result (man-in-the-middle position) not by attacking...
Examining the value of SafetyNet Attestation as an Application Integrity Security Control
Anestis Bechtsoudis
Google promotes the SafetyNet Attestation API as a tool to query and assess the integrity status of an Android device. The official documentation, leaves no doubt that the main purpose of the SafetyNet Attestation API is to provide device integrity information to the server counterpart of mobile applications. The...