Mobile apps: An Achilles' heel for web security?
ID: 89b1d919-84e5-5253-81f0-32cfc57a9f9f
STIX ID: report--89b1d919-84e5-5253-81f0-32cfc57a9f9f
Feed Name: Zscaler Security Research Blog
Threat Score
The report demonstrates that JotNot Scanner Pro stores authentication credentials (Evernote, Google Docs, iDisk/WebDAV) in cleartext within its com.mobitech3000.JotNotIPhone.plist inside iTunes backups, meaning an attacker with access to a user's backup can obtain usernames and passwords and potentially access linked services; the author uses this as an example of wider mobile app security failures and urges better developer practices and token-based APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
