ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    iOS Masque Attack

    IT Discussion
    apple security swisscheese ios
    6
    15
    3.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • nadnerBN
      nadnerB
      last edited by nadnerB

      Well, this sucks for iOS users. There's another way of exploiting the hole that WireLurker is using but this time, no PC is required.

      Have a read of this: http://www.tomshardware.com/news/ios-masque-attack-wirelurker-enhanced,28052.html#xtor=RSS-998

      The important bits:

      • "Masque Attack" works much like WireLurker in that it takes advantage of Apple’s enterprise provisioning to bypass other security checks on iOS.
      • Unlike WireLurker, though, Masque Attack doesn’t even need to infect the user's PC
      • FireEye reported the malware to Apple months ago (July 26, to be exact), Apple doesn’t seem to have fixed the loophole yet

      I haven't watched it but one of articles I found [au.pcmag.com] when fact checking has a demo of the attack in action: https://www.youtube.com/watch?v=3VEQ-bJUhPw

      1 Reply Last reply Reply Quote 1
      • nadnerBN
        nadnerB
        last edited by

        Here's the post from the FireEye blog: http://www.fireeye.com/blog/technical/cyber-exploits/2014/11/masque-attack-all-your-ios-apps-belong-to-us.html

        1 Reply Last reply Reply Quote 0
        • thanksajdotcomT
          thanksajdotcom
          last edited by

          That is pretty major.

          1 Reply Last reply Reply Quote 0
          • ?
            A Former User
            last edited by

            is there any protection for this?

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              So is Gmail as an app the only target? I have Gmail on the iOS email client.

              Reid CooperR 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                Basically it looks like this requires a really stupid user both to click a link that is a phishing attack as well as not notice that Gmail is being replaced as well as have the Gmail app installed already. Is that all true? Seems like a very scary attack but for a very limited audience.

                1 Reply Last reply Reply Quote 0
                • Reid CooperR
                  Reid Cooper @scottalanmiller
                  last edited by

                  @scottalanmiller said:

                  So is Gmail as an app the only target? I have Gmail on the iOS email client.

                  From the article it looks like it can steal data from nearly any third party app, but not the Apple apps. So normal users would have no risk to email, messaging or web browsing. It would be things like Facebook that would be at risk.

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    But it needs the same bundle identifier? Does that mean that they have to make a guess as to what you have installed in order to action the attack? Like they guess that you have Facebook Messenger installed, so they use its bundle identifier? Then, if you do actually have it, it replaces it and if you don't, if fails and you are safe?

                    1 Reply Last reply Reply Quote 0
                    • Reid CooperR
                      Reid Cooper
                      last edited by

                      I think so, that is how I read it.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        Not too much risk for businesses then, really focused on end user data.

                        Reid CooperR nadnerBN 2 Replies Last reply Reply Quote 0
                        • Reid CooperR
                          Reid Cooper @scottalanmiller
                          last edited by

                          @scottalanmiller said:

                          Not too much risk for businesses then, really focused on end user data.

                          Seems that way.

                          1 Reply Last reply Reply Quote 0
                          • nadnerBN
                            nadnerB @scottalanmiller
                            last edited by

                            @scottalanmiller said:

                            Not too much risk for businesses then, really focused on end user data.

                            Isn't that 90% of apples clientele?
                            Seriously though, I don't actually know but I figure that a good portion of Apples users would fall for it mainly because of the "Macs are immune to this crap" type of mentality.

                            thanksajdotcomT JaredBuschJ 2 Replies Last reply Reply Quote 1
                            • thanksajdotcomT
                              thanksajdotcom @nadnerB
                              last edited by

                              @nadnerB said:

                              @scottalanmiller said:

                              Not too much risk for businesses then, really focused on end user data.

                              Isn't that 90% of apples clientele?
                              Seriously though, I don't actually know but I figure that a good portion of Apples users would fall for it mainly because of the "Macs are immune to this crap" type of mentality.

                              I can see that...

                              1 Reply Last reply Reply Quote 0
                              • JaredBuschJ
                                JaredBusch @nadnerB
                                last edited by

                                @nadnerB said:

                                Isn't that 90% of apples clientele?
                                Seriously though, I don't actually know but I figure that a good portion of Apples users would fall for it mainly because of the "Macs are immune to this crap" type of mentality.

                                No. They will fall for it because they clicked on a get this app free link.

                                General end users have no clue that one system is more secure than another. That only comes in to play in the more technical circles.

                                nadnerBN 1 Reply Last reply Reply Quote 2
                                • nadnerBN
                                  nadnerB @JaredBusch
                                  last edited by

                                  @JaredBusch said:

                                  No. They will fall for it because they clicked on a get this app free link.

                                  General end users have no clue that one system is more secure than another. That only comes in to play in the more technical circles.

                                  Very true.

                                  1 Reply Last reply Reply Quote 0
                                  • 1 / 1
                                  • First post
                                    Last post