Online social networking service Twitter has launched a bug bounty program in an effort to eliminate the security flaws by giving the opportunity to researchers to formally disclose vulnerabilities and in return get the reward. Twitter has outsourced this program to HackerOne. Although there is no maximum limit for the reward but a minimum reward of $140 is offered for one vulnerability. The security flaws include XSS, CSRF, remote code execution and unauthorized access to tweets and direct messages. Only way a researcher is eligible to monetary reward is to report the bug and will not disclose publicly until the patch is available. <more>
Monday, September 15, 2014
Saturday, September 6, 2014
50 security fixes for Google Chrome
Google Chrome latest version 37.0.2062.94 got 50 security fixes last Tuesday. Security researcher 'lokihardt@asrt' received a huge amount of $30,000 for finding out flaws
in Chrome JavaScript engine V8, the Inter-process Communication (IPC),
the data synchronization component and extensions. Most of the vulnerabilities
allow remote code execution. Besides this other researchers found
use-after-free vulnerabilities in DOM, SVG and bindings, spoofing of the
extension permission dialog, uninitialized memory read in WebGL and Web
Audio. Researchers who worked with the Chrome development also
discovered flaws based on internal audits, fuzzing and other types of
activities through Address Sanitizer tool. <more>
Facebook to fix auto iPhones calls
Social networking giant Facebook will soon release an update for its messenger app. The patch
will fix the issue on iOS that allows attackers to make calls
automatically from users' phones by clicking on web link. Andrei
Neculaesei a developer from Copenhagen discovered the flaw
which can be triggered through the tel URL scheme. According to Apple
document, tel URL scheme is used to launch the mobile app on iOS devices
and allow dialing of the specified phone number. Applications like
Facebook Messenger, Apple's Facetime, Google+ and Gmail usually don't
show a pop-up for alerts when users tap a telephone link in a webpage
and allow making calls without user consent. <more>
Subscribe to:
Posts (Atom)