Thursday, September 28, 2023
  • Home
  • World
  • Business
  • Crypto
  • Games
  • Health
  • Markets
  • Politics
  • Sports
  • Technology
  • Mac os
No Result
View All Result
  • Home
  • World
  • Business
  • Crypto
  • Games
  • Health
  • Markets
  • Politics
  • Sports
  • Technology
  • Mac os
No Result
View All Result
apkconnex
No Result
View All Result

Bugs in transportation app Moovit gave hackers free rides | TechCrunch

apkconnex by apkconnex
August 13, 2023
in Technology
0
Bugs in transportation app Moovit gave hackers free rides | TechCrunch
0
SHARES
100
VIEWS
Share on FacebookShare on Twitter


Hackers may have hijacked the consumer accounts of a well-liked transportation app and used them to get free rides and entry folks’s private data, in keeping with a safety researcher.

Omer Attias, a safety researcher at SafeBreach, stated he discovered three vulnerabilities in the Moovit app, which allowed him to gather new Moovit consumer’s registration data from everywhere in the world — together with mobile phone numbers, e mail addresses, house addresses, and the final 4 digits of bank cards. Worst of all, the bugs may have allowed him to take over different folks’s accounts, and consequently their bank cards, to pay for his personal rides.

This complete chain of exploits may have been carried out with out the goal ever discovering out, other than seeing undesirable costs on their bank card. Attias known as it “the perfect attack.”

“We can fully impersonate accounts, without disconnecting them. It’s crazy, we actually have the ability to perform all the operations on behalf of different accounts, including ordering train tickets,” Attias advised TechCrunch in an interview forward of his speak on the Def Con hacking conference in Las Vegas. “And additionally, we can access all of their personal information.”

To display the influence of the bugs he discovered, Attias created a customized interface that allowed him to take over different folks’s accounts with a few faucets. And whereas Attias stated he examined his exploits solely in Israel, he stated he thinks it may have labored in different cities provided that Moovit operates everywhere in the world.

Moovit is an Israeli startup that was acquired by Intel in 2020 for $900 million. The app permits customers to search out routes and think about public transportation techniques’ maps, in addition to to buy and use tickets. The app and its underlying know-how are broadly used worldwide: Moovit claims to serve 1.7 billion riders in 3,500 cities throughout 112 nations.

While the influence of those vulnerabilities was doubtlessly large, Moovit stated there isn’t any proof that malicious hackers discovered and exploited these bugs. Attias stated that he reported all of the bugs he discovered to the corporate in September 2022, and the corporate subsequently fastened them.

“Moovit was aware of and rectifying the issue when it was reported, and took immediate steps to finish correcting the issue,” Moovit spokesperson Sharon Kaslassi advised TechCrunch. “The vulnerabilities have long since been fixed and no customer action is required. It’s important to note that no bad actors took advantage of these issues to access customer data. Additionally, no credit card information was exposed as Moovit and Moovit-Pango do not keep credit card information on file.”

Kaslassi additionally stated that “ticketing service relevant to these findings is active in Israel only.”

“According to our records, neither Safebreach or anyone else took advantage of any customer data in or outside of Israel,” the spokesperson added.

In response to Moovit’s feedback, Attias stated that he and his colleagues “believe we could have charged any customer not limited to Israeli customers. We haven’t seen any differentiator between Israeli and non Israeli customers in their API requests.”

Read extra from Black Hat:



Tags: AppbugsFreegaveHackersMoovitRidesTechCrunchtransportation
Previous Post

Georgia prosecutor will present witness testimony to grand jury as another Trump indictment appears imminent

Next Post

UK employers increasingly resort to bidding wars to retain staff, says survey

Next Post
UK employers increasingly resort to bidding wars to retain staff, says survey

UK employers increasingly resort to bidding wars to retain staff, says survey

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

apkconnex

Categories

  • Business
  • Crypto
  • Games
  • Health
  • Mac os
  • Markets
  • Politics
  • Sports
  • Technology
  • World
Artifact co-founder Mike Krieger says there’s a ‘flavor’ of Twitter in app’s latest release | TechCrunch

Artifact co-founder Mike Krieger says there’s a ‘flavor’ of Twitter in app’s latest release | TechCrunch

September 28, 2023
What is behind the robust growth projections for Southern Eurozone economies?

What is behind the robust growth projections for Southern Eurozone economies?

September 28, 2023
  • Home
  • Privacy Policy
  • Contact Us
  • About US
  • Disclaimer

© 2022 Apkconnex- All Right are reserved

No Result
View All Result
  • Home
  • World
  • Business
  • Crypto
  • Games
  • Health
  • Markets
  • Politics
  • Sports
  • Technology
  • Mac os

© 2022 Apkconnex- All Right are reserved

  • bitcoinBitcoin(BTC)$27,183.003.95%
  • ethereumEthereum(ETH)$1,662.424.64%
  • tetherTether(USDT)$1.000.15%
  • binancecoinBNB(BNB)$215.722.25%
  • rippleXRP(XRP)$0.511.34%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • staked-etherLido Staked Ether(STETH)$1,660.044.36%
  • cardanoCardano(ADA)$0.2498122.72%
  • dogecoinDogecoin(DOGE)$0.0615652.09%
  • solanaSolana(SOL)$19.704.73%
  • ToncoinToncoin(TON)$2.265.02%
  • tronTRON(TRX)$0.0863441.57%
  • polkadotPolkadot(DOT)$4.082.31%
  • matic-networkPolygon(MATIC)$0.523.91%
  • litecoinLitecoin(LTC)$65.012.62%
  • bitcoin-cashBitcoin Cash(BCH)$240.966.36%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$27,187.003.92%
  • chainlinkChainlink(LINK)$7.874.66%
  • shiba-inuShiba Inu(SHIB)$0.0000071.95%
  • daiDai(DAI)$1.000.28%
  • true-usdTrueUSD(TUSD)$1.000.16%
  • leo-tokenLEO Token(LEO)$3.67-0.74%
  • uniswapUniswap(UNI)$4.455.75%
  • avalanche-2Avalanche(AVAX)$9.345.49%
  • stellarStellar(XLM)$0.1140021.67%
  • moneroMonero(XMR)$146.060.71%
  • okbOKB(OKB)$43.241.21%
  • binance-usdBUSD(BUSD)$1.000.06%
  • ethereum-classicEthereum Classic(ETC)$15.874.11%
  • cosmosCosmos Hub(ATOM)$7.173.67%
  • hedera-hashgraphHedera(HBAR)$0.0498271.60%
  • filecoinFilecoin(FIL)$3.303.75%
  • lido-daoLido DAO(LDO)$1.599.19%
  • makerMaker(MKR)$1,538.396.58%
  • internet-computerInternet Computer(ICP)$3.064.24%
  • crypto-com-chainCronos(CRO)$0.0504101.15%
  • quant-networkQuant(QNT)$90.383.46%
  • AptosAptos(APT)$5.392.45%
  • MantleMantle(MNT)$0.3951492.09%
  • vechainVeChain(VET)$0.0168953.35%
  • ArbitrumArbitrum(ARB)$0.9010.10%
  • optimismOptimism(OP)$1.325.06%
  • nearNEAR Protocol(NEAR)$1.103.71%
  • KaspaKaspa(KAS)$0.0472781.76%
  • aaveAave(AAVE)$66.3210.39%
  • Rocket Pool ETHRocket Pool ETH(RETH)$1,806.234.35%
  • the-graphThe Graph(GRT)$0.0872982.71%
  • algorandAlgorand(ALGO)$0.0978464.14%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$5.190.23%
  • usddUSDD(USDD)$1.000.10%