Connect with us

Lifestyle

5 Ways Your WhatsApp Messages Can Be Hacked

Published

on

WhatsApp is a popular and easy to use messaging program. It has some security features, like the use of end-to-end encryption to keep messages private. However, hacks targeting WhatsApp could compromise the privacy of your messages and contacts.

Here are five ways that WhatsApp can be hacked.

1. Remote Code Execution via GIF

WhatsApp hack - GIF attack

In October 2019, security researcher Awakened revealed a vulnerability in WhatsApp that let hackers take control of the app using a GIF image. The hack works by taking advantage of the way that WhatsApp processes images when the user opens the Gallery view to send a media file.

When this happens, the app parses the GIF in order to show a preview of the file. GIF files are special because they have multiple encoded frames. This means that code can be hidden within the image.

If a hacker were to send a malicious GIF to a user, they could compromise the user’s entire chat history. The hackers would be able to see who the user had been messaging and what they had been saying. They could also see users’ files, photos, and videos sent through WhatsApp

The vulnerability affected versions of WhatsApp up to 2.19.230 on Android 8.1 and 9. Fortunately, Awakened disclosed the vulnerability responsibly and Facebook, which owns WhatsApp, has been able to patch the issue. To keep yourself safe from this problem, you should update WhatsApp to version 2.19.244 or above.

2. The Pegasus Voice Call Attack

WhatsApp hack - Pegasus attack

Another WhatsApp vulnerability discovered in early 2019 was the Pegasus voice call hack. This scary attack allowed hackers to access a device simply by placing a WhatsApp voice call to their target. Even if the target didn’t answer the call, the attack could still be effective. And the target may not even be aware that malware has been installed on their device.

This worked through a method known as buffer overflow. This is where an attack deliberately puts too much code into a small buffer so that it “overflows” and writes code into a location it shouldn’t be able to access. When the hacker can run code in a location that should be secure, they can take malicious actions.

In the case of this attack, it installed an older and well-known piece of spyware called Pegasus. This allowed hackers to collect data on phone calls, messages, photos, and video. It even let them activate devices’ cameras and microphones to take recordings.

This vulnerability applied to Android, iOS, Windows 10 Mobile, and Tizen devices. It was used by the Israeli firm NSO Group which has been accused of spying on Amnesty International staff and other human rights activists. After news of the hack broke, WhatsApp was updated to protect it from this attack.

If you are running WhatsApp version 2.19.134 or earlier on Android or version 2.19.51 or earlier on iOS, then you need to update your app immediately.

3. Socially Engineered Attacks

Another way that WhatsApp is vulnerable is through socially engineered attacks.These exploit human psychology to steal information or spread misinformation. A security firm called Check Point Research revealed one such attack they named FakesApp. This allowed people to misuse the quote feature in group chat and to alter the text of another person’s reply. Essentially, it allows hackers to plant fake statements that appear to be from other legitimate users.

The researchers were able to do this by decrypting WhatsApp communications. This allowed them to see data sent between the mobile version and the web version of WhatsApp. And from here, they could change values in group chats. Then they could impersonate other people, sending messages which appeared to be from them. They could also change the text of replies.

The researchers point out this could be used in worrying ways to spread scams or fake news. Even though the vulnerability was disclosed in 2018, it had still not been patched by the time the researchers spoke at the Black Hat conference in Las Vegas in 2019, according to ZNet.

4. Media File Jacking

WhatsApp hack - media file jacking

A vulnerability which affects both WhatsApp and Telegram is media file jacking. This attack takes advantage of the way that apps receive media files like photos or videos and write those files to a device’s external storage.

The attack starts by installing a malicious piece of malware hidden inside an apparently harmless app. This malware can then monitor incoming files for Telegram or WhatsApp. When a new file comes in, the malware can swap out the real file for a fake file. The researchers who discovered the issue, Symantec, suggest it could be used to scam people or to spread fake news.

There is a quick fix for this issue. In the WhatsApp app, you should look in Settings and go to Chat Settings. Then find the Save to Gallery option and make sure it is set to Off. This will protect you from this vulnerability. However, a true fix for the issue will require app developers to completely change the way that apps handle media files in the future.

5. Facebook Spying on Whatsapp Chats

WhatsApp hack - Facebook spying

The last topic to consider is more of a security issue than a true vulnerability. It regards whether WhatsApp messages could potentially be read by Facebook or not.

In a blog post, WhatsApp implied that because it uses end-to-end encryption, it is impossible for Facebook to read WhatsApp content: “we’ve rolled out end-to-end encryption. When you and the people you message are using the latest version of WhatsApp, your messages are encrypted by default, which means you’re the only people who can read them. Even as we coordinate more with Facebook in the months ahead, your encrypted messages stay private and no one else can read them. Not WhatsApp, not Facebook, nor anyone else.”

However, according to developer Gregorio Zanon, this is not strictly true. The fact WhatsApp uses end-to-end encryption does not mean all messages are private. On an operating system like iOS 8 and above, apps can access files in a “shared container.”

Both the Facebook and WhatsApp apps use the same shared container on devices. And while chats are encrypted when they are sent, they are not necessarily encrypted on the originating device. This means the Facebook app could potentially copy information from the WhatsApp app.

To be clear, there is no evidence that Facebook has used shared containers to view private WhatsApp messages. But the potential ability is there for them to do so. Even with end-to-end encryption, your messages may not be private from Facebook’s all-seeing eye.

Stay Aware of Security Issues in WhatsApp

These are examples of the way that WhatsApp can be hacked. While some of these issues have been patched since their disclosure, others have not.

 

 

Facebook Comments

Lifestyle

Virgil Abloh Criticized For Donating A Trifling $50 To #BlackLivesMatter Protesters’ Bail Fund

Published

on

Virgil Abloh, the founder and CEO of the premium brand ‘Off-White’ and artistic director of menswear line at Louis Vuitton, had a very interesting way of expressing his support to the Black Lives Matter movement and social media users are not here for it.

Since protests ignited by George Floyd’s death broke, many protesters who support the Black Lives Matter movement have been arrested for ‘looting’ and ‘violence’. Several celebrities have offered to pay for the legal expenses and release of the protesters who have been taken into custody.

While celebrities like Chrissy Teigen have already pledged $200,000 to help out the imprisoned protesters, Abloh revealed through his Instagram story that he had donated “$50” to protesters in need of bail money.
“The Miami community ~ I’m crazy inspired. For kids in the streets that need a bail funds [sic] for George Floyd protests,” he wrote in the Story.

In the backdrop of protests, Abloh took to his Instagram to rant about ‘streetwear culture’ and slammed the protesters for ransacking Sean Wotherspoon’s store.

In Los Angeles, the RSVP Gallery, which sells his ‘Off-White’ brand, was looted.

Reacting to the news, he said that the ones who have looted the merchandise should be ashamed of their actions.
“If it heals your pain, you can have it,” he wrote.

Twitter erupted with anger over Abloh’s modest contribution — some even briefly changed his Wikipedia page to read Virgil “Cheap Ass” Abloh and Virgil “50$” Abloh.

Facebook Comments
Continue Reading

Lifestyle

Alleged Rapist Confesses How He Rapes Lady

Published

on

A Nigerian man identified as Ogimex Aka Obonblingz has confessed how he used to rape ladies narrating what happened and made him stop.

The young man revealed he was young at that time and one day, what he went through after trying to rape some two ladies made him rescind his decision about raping people.

He said this while reacting to the death of Uwa Vera Omozuwa, the first-year UNIBEN student.

The lady was murdered after she was raped by unknown assailants and this young man in his reaction indicated that he used to rape women who refuse to have sex with him when he was much younger.

Read what made him stop in the screenshot below.

Facebook Comments
Continue Reading

Lifestyle

You Can’t Be On Social Media If You Don’t Have Tolerance : Dela Seada Of Miss Malaika Fame | WATCH

Published

on

Social media influencer, Dela Seade of Miss Malaika fame, appeared on Leah Brown’s Queen In the Making workshop, where she addressed matters around the impact of social media in beauty pageantry shows.

According to Mz Dela, one of the key things anyone needs to have to be on social media is tolerance. During the online workshop targeted at young girls with interest in becoming beauty pageants, she explained there are keyboard warriors who’ll deflate your confidence with trolling comments and if you don’t have the strength for it, you’ll give up.

She says it’s like spiritual warfare to deal with trolls and her tactics were to ignore them.

Watch below.

View this post on Instagram

Dela Seada Speaks On QiM Workshop About Online Brand, Growth And More Social media influencer, Dela Seade of Miss Malaika fame, appeared on @Leah_ABrown’s Queen In the Making workshop, where she addressed matters around the impact of social media in beauty pageantry shows. According to @MzDela, one of the key things anyone need to have to be on social media is tolerance. During the online workshop targeted at young girls with interest in becoming beauty pageants, she explained there are keyboard warriors who’ll deflate your confidence with trolling comments and if you don’t have the strength for it, you’ll give up. She says it’s like a spiritual warfare to deal with trolls and her tactics was to ignore them. [Press Play] for more of what she has to say about branding on social media and strategies to grow your presence. Hit our Instastory to continue watching this episode of the QiM workshop. _______________________________________________________ #FameBugs #Ghana #Beauty #Pageants #Queen #MissMalaika #MzDela #LeahBrown #GhanaNews #Malaika2020 #MissGhana2020 #Hair #Makeup #MissUniverseGhana2020 #BeautyQueen #Accra #GhanaTwitter #Instagram #Malaika2019 #Influencer #Ghanaian #Celebrities #Gossip #Enews #FameBugs

A post shared by FameBugs (@famebugs) on

Facebook Comments
Continue Reading

Trending