About: Gareth Wright
Posts by admin:
1 and 1 iOS Apps sloppy coding allows domain theft and email hijacking »
Apr 14, 2012 | Categories: BlogIn many ways this is much worse than the LinkedIn and Facebook Plist vulnerability exposed last week. Both social apps exposed plain text OAuth Tokens which enable a large amount of personal information to be snaffled from accounts, and in the case of Facebook, access any website or application you’ve authorised via Facebook. What makes [...]
Using iOS Keychain for Data Protection and Migration »
Apr 13, 2012 | Categories: BlogGiven the number of requests I’m currently recieving re using the keychain following my post regarding the use of plain text credientials in plists I’ve decided to reprint an excellent series of articles from Use Your Loaf which helped me get to grips with Keychain access and permissions. Hope this helps out! Remember for maximum [...]
AgileBits 1Password Updated OAuth Tokens Moved to Keychain »
Apr 10, 2012 | Categories: Blog1Password, a cross platform passwords management solution by Agile Bits snatched the crown for the first app developers to publicly test their own iOS app, own up to having, and subsequently fix the plist vulnerability discussed on my April 3rd Post Re Facebook Credential Theft Not only is their blog post oozing with professionalism and [...]
LinkedIn also Vulnerable to Plist Theft »
Apr 7, 2012 | Categories: Blog[UPDATED] LinkedIn update on 26-4-2012 appears to resolve this vulnerability, though no statement or reference to the vulnerability has been made by LinkedIn. Still, they have fixed it, which is a heck of a lot more than Facebook has done! Further testing on popular social apps has revealed that LinkedIn also suffers from the plist [...]
Kolay® The New iPad 3 HD Clear Gel Back Cover Tough TPU Case & Screen Protector for Apple iPad 3 3rd Generation (Works with Smart Cover) »
Apr 4, 2012 | Categories: GadgetsFacebook Plist Mobile Security Hole Allows Identity Theft [Updated] »
Apr 3, 2012 | Categories: BlogI’ve made posts about various iOS games and the fact that developers, rather than encode add to keychain or save values in the binaries, choose to save those values in plain text plists. The majority of traffic to this site is to the pages relating to using these oversights for cheating in iOS games, but [...]
