Thousands of Apple ID accounts are leaked because an application's server has data leaks
Two of TeenSafe's servers, the monitoring application allows parents to monitor their activity on Android and iOS devices, stored on the Amazon cloud service with security issues.
Specifically, these two servers are not protected by passwords, meaning thousands of accounts of parents and children use TeenSafe risk of information disclosure.
This serious security vulnerability was discovered by security vendor Robert Wiggins. Although one of the servers is only for processing test data, another server contains 10,200 data records including the email address of the parent associated with an account / Apple ID address, device name. , the child's UDID number and password to access the Apple ID are not encrypted.
Importantly, TeenSafe requires users to turn off two-factor authentication for their child's Apple ID account so that parents have the right to monitor the phone without consent. This means hackers can use leaked information to break into accounts and collect data.
Immediately after receiving a warning about the vulnerability, TeenSafe closed one of the servers. Customers were also informed about the risks affected by the company.
See more:
- Detecting an extremely dangerous vulnerability on nearly 16,000 iOS applications
- Windows 10 April Update 2018 Update makes taskbar invisible
- Virtual Assistant Google Assistant will support Vietnamese at the end of the year
You should read it
- Apple released a patch to fix security holes on Mac OS X
- 9 apps that scam and steal users' Facebook accounts
- Apple is the most complete password protection website
- Apple ID accounts are used by Chinese hackers to steal money
- How to delete an Apple ID account
- Differentiate Apple ID and iCloud
- How to add and delete Email accounts on Mac, iPhone and iPad
- Apple promises to upgrade security for iCloud in the next 2 weeks
May be interested
- How to download data from Apple ID to computerapple has allowed users to download personal data of apple id accounts that the company collects.
- Hundreds of thousands of IoT devices are likely to be attacked by vulnerabilities on the serveron christmas day, a vulnerability affecting web servers was embedded with hundreds of thousands of iot devices, namely goahead, a web server created by embedthis software.
- Create VPN Server on Windows 8no need to install any additional applications, you can easily 'turn' your computer into a vpn server if you're using windows 8. in this way, you can share data from the computer. as a simple lan system in the form of remote access. & a
- Username, password, email, phone number ... of more than 160 million Zing ID accounts are for saleon april 24, on a foreign forum called raidforums, a member posted a file that was supposed to be information of vng's 163,666,400 million zing id accounts.
- How to move purchases between 2 Apple accountsif you've purchased apps, subscriptions, music, videos, or other content from one apple account, you can now transfer purchases to another apple account when needed.
- Vietnam reached the top 10 countries with the most leaked Facebook information in the worldaccording to the latest information posted on facebook's blog, there are about 427,446 vietnamese facebook users leaked information. this is just the number that facebook estimates but it is enough for vietnam to rank 9th in the ranking of 10 countries affected by information security.
- Data types in SQL Serverbelow are the data types (data types) in sql server, including character strings, numbers and times / dates.
- Google+ was closed due to a serious security bug that leaked data of more than 500,000 accountsgoogle decided to close the google+ service and as planned, this will take place over the next 10 months, ending in august 2019.
- How to check if your account has leaked data onlinetoday, crooks have many tricks and tricks to steal information from others without the victim's knowledge. here, i will guide you to perform some operations to check if the account has leaked data on the network or not.
- Find out about Managed Group Services Accounts in Windows Server 2012managed service accounts (msa) - managed service account - was introduced in windows server 2008 r2 to automatically manage (or change) the passwords of service accounts.