Originally posted by NickFitz
View Post
- Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
- Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
Collapse
You are not logged in or you do not have permission to access this page. This could be due to one of several reasons:
- You are not logged in. If you are already registered, fill in the form below to log in, or follow the "Sign Up" link to register a new account.
- You may not have sufficient privileges to access this page. Are you trying to edit someone else's post, access administrative features or some other privileged system?
- If you are trying to post, the administrator may have disabled your account, or it may be awaiting activation.
Logging in...
Previously on "Major Password vulnerability in multiple Android and iOS apps."
Collapse
-
Yes, as per the original post, the apps are making use of vulnerable web services. The net effect is still that passwords used by or with the apps are vulnerable to brute force attacks without the app owners knowledge.
-
These appear to be vulnerabilities in the HTTP APIs, not in the apps at all. The apps are just client software that uses the relevant HTTP endpoint.
Leave a comment:
-
Had one on my Android tablet. A file manager.
PS That android Appbugs Security Scan logo looks amazingly similar to my android app, also about bugs. With a bit of luck people will get mixed up and install mine by mistake.
https://play.google.com/store/apps/d...com.appbugs.ui
https://play.google.com/store/apps/d....ISee.LandBugsLast edited by xoggoth; 28 July 2015, 08:35.
Leave a comment:
-
Major Password vulnerability in multiple Android and iOS apps.
Time to check your apps. Not specific to Andoid or iOS, just specific to sloppy development.
https://appbugs.co/html/bugs_categor...ord_bruteforce
AppBugs found 53 mobile apps (Android and iOS, approximately 600 million users impacted) have the password brute force issues in their web services and attackers can exploit the holes immediately to steal users passwords.Tags: None
- Home
- News & Features
- First Timers
- IR35 / S660 / BN66
- Employee Benefit Trusts
- Agency Workers Regulations
- MSC Legislation
- Limited Companies
- Dividends
- Umbrella Company
- VAT / Flat Rate VAT
- Job News & Guides
- Money News & Guides
- Guide to Contracts
- Successful Contracting
- Contracting Overseas
- Contractor Calculators
- MVL
- Contractor Expenses
Advertisers
Contractor Services
CUK News
- How to run a contractor limited company — efficiently. Part one: software Yesterday 23:31
- Forget February as an MSC contractor seeking clarity, and maybe forget fairness altogether Yesterday 19:57
- What contractors should take from Honest Payroll Ltd’s failure Jan 21 07:05
- HMRC tax avoidance list ‘proves promoters’ nothing-to-lose mentality’ Jan 20 09:17
- Digital ID won’t be required for Right To Work, but more compulsion looms Jan 19 07:41
- A remote IT contractor's allowable expenses: 10 must-claims in 2026 Jan 16 07:03
- New UK crypto rules now apply. Here’s how mandatory reporting affects contractors Jan 15 07:03
- What the Ray McCann Loan Charge Review means for contractors Jan 14 06:21
- IT contractor demand defied seasonal slump in December 2025 Jan 13 07:10
- Five tax return hacks for contractors as Jan 31st looms Jan 12 07:45

2 more OK
Leave a comment: