Free Newsletter
Register for our Free Newsletters
Newsletter
Zones
Access Control
LeftNav
Alarms
LeftNav
Biometrics
LeftNav
Detection
LeftNav
Deutsche Zone (German Zone)
LeftNav
Education, Training and Professional Services
LeftNav
Government Programmes
LeftNav
Guarding, Equipment and Enforcement
LeftNav
Industrial Computing Security
LeftNav
IT Security
LeftNav
Physical Security
LeftNav
Surveillance
LeftNav
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
 
News

Free online tool reduces mobile app vulnerability

Zscaler : 21 January, 2013  (New Product)
ZScaler comments on mobile sports app vulnerability and the availability of a free tool to reduce associated risks
Free online tool reduces mobile app vulnerability

According to ZScaler, ESPN ScoreCenter, one of the most popular mobile sports apps on the market, has significant security vulnerabilities that could compromise users’ mobile devices, including the threat of data theft. The flaws were unearthed using Zscaler Application Profiler (ZAP), the free online tool that makes it easy to assess mobile apps for security risks. ESPN said it is looking into the vulnerabilities in the ScoreCenter app.

The security vulnerabilities with the ESPN ScoreCenter app highlight a growing security problem as mobile apps proliferate and basic security measures are overlooked in the development process.

“It’s important to remember that many mobile apps are not native applications—they’re essentially web pages displayed in a WebView control, or even just web content mixed in with native controls,” said Michael Sutton, VP, Security Research, Zscaler ThreatLabZ. “As such, vulnerabilities common to web applications can also occur in mobile apps. Users should be aware that such vulnerabilities in mobile apps often remain hidden, as apps don’t have the same visual indicators to show that data is being sent insecurely.”

First, by displaying basic web content without properly sanitizing user-supplied input, ESPN ScoreCenter exposes a cross-site scripting (XSS) flaw. Therefore, active content such as JavaScript can be injected into the app. Second, ESPN ScoreCenter passes authentication credentials in clear text when an account is first created. By sending the password in clear text, ESPN ScoreCenter enables anyone sniffing traffic on the network to easily steal that key piece of information.

The flaws were discovered using ZAP, Zscaler’s Application Profiler. ZAP is an easy to use, free online tool where users can search the name of any iOS or Android app, and receive an instant assessment of its security and privacy risks, along with an overall risk score. Users can also use ZAP to scan traffic from an app installed on their device to see whether their own data is being exposed. No security expertise is needed to use ZAP. As more users submit mobile apps for analysis, Zscaler’s ThreatLabZ team adds the results to the ZAP database, in effect crowdsourcing the security profiles of thousands of mobile apps.

Bookmark and Share
 
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
 
   © 2012 ProSecurityZone.com
Netgains Logo