Monday, September 15, 2014

Twitter unleashes bug bounty program

Online social networking service Twitter has launched a bug bounty program in an effort to eliminate the security flaws by giving the opportunity to researchers to formally disclose vulnerabilities and in return get the reward. Twitter has outsourced this program to HackerOne. Although there is no maximum limit for the reward but a minimum reward of $140 is offered for one vulnerability. The security flaws include XSS, CSRF, remote code execution and unauthorized access to tweets and direct messages. Only way a researcher is eligible to monetary reward is to report the bug and will not disclose publicly until the patch is available. <more>

Saturday, September 6, 2014

50 security fixes for Google Chrome

Google Chrome latest version 37.0.2062.94 got 50 security fixes last Tuesday. Security researcher 'lokihardt@asrt' received a huge amount of $30,000 for finding out flaws in Chrome JavaScript engine V8, the Inter-process Communication (IPC), the data synchronization component and extensions. Most of the vulnerabilities allow remote code execution. Besides this other researchers found use-after-free vulnerabilities in DOM, SVG and bindings, spoofing of the extension permission dialog, uninitialized memory read in WebGL and Web Audio. Researchers who worked with the Chrome development also discovered flaws based on internal audits, fuzzing and other types of activities through Address Sanitizer tool. <more>

Facebook to fix auto iPhones calls

Social networking giant Facebook will soon release an update for its messenger app. The patch will fix the issue on iOS that allows attackers to make calls automatically from users' phones by clicking on web link. Andrei Neculaesei a developer from Copenhagen discovered the flaw which can be triggered through the tel URL scheme. According to Apple document, tel URL scheme is used to launch the mobile app on iOS devices and allow dialing of the specified phone number. Applications like Facebook Messenger, Apple's Facetime, Google+ and Gmail usually don't show a pop-up for alerts when users tap a telephone link in a webpage and allow making calls without user consent. <more>