Forum Moderators: buckworks & not2easy

Message Too Old, No Replies

LinkedIn ignored SIX WARNINGS about account-hijacking bug

         

tangor

12:53 am on Jun 22, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



LinkedIn accounts can be hijacked through simple man in the middle (MITM) attacks due to a failure to promptly fix a SSL stripping vulnerability .

The flaw described ambitiously as a zero-day vulnerability allowed attackers to gain full control of a user's account after they had logged in via SSL.

Attackers could jump between the user and the service and replace the secure protocol with HTTP allowing access to their account.

User IDs, passwords and all LinkedIn data could then be siphoned off by attackers.

All users outside of Europe and the US who did not tick a box to activate optional HTTPS beyond the login screen were vulnerable to the attack, Zimperium boss Zuk Avraham said in a post.

[theregister.co.uk...]