WhatsApp Hack
198.61.222.60
198.61.222.60
There is definitely a place to out a company that fails to secure things consistently, but asking for credentials in this way absolutely wrecks your credibility to anyone but the most trusting of people that already knows you. No one should input anything into this form, even if it's credible. To do so, is assuming that it is not being stored in any way (unprovable), and that it is following security best practices (on a site that's not even operating on a secure connection). I'm sure you are a standup guy, but I hope we never get complacent with blindly accepting "hack checkers" like the ones that popped up around other notable hacks recently
First impression for most users would be that this is credential harvesting webpage with who knows what running behind it.
Have you played with the node.js clients?
Using my own phone and account BTW.
Worked for my android. Still not working for iOS.
I was using \test\whatsapp.php.
1) Your mac address is available to even passive sniffers without the key to an encrypted network. In some circumstances you don't even need to be connected to a network to grab someone's mac address (iPhones in particular love looking for networks loudly).
2) FTP and AIM passwords can be changed. Yes, a passive sniffer on the same network can still get them, but this is a significantly harder task than getting someone's mac address, and there's no way to change the goal.
3) Brute force attacks become within the realm of possibility. Have someone you know has an iPhone 5 and uses WhatsApp? The first chunk of the mac address is assigned by vendor, so you've already narrowed the search space down drastically by half to needing to guess 6 hex digits.
How about if you're on someone else's network (work, a friend's, an airport, etc...)
I support this though, because WhatsApp has known about this for a couple years now and refuse to do anything about it.
The short version is, anyone can steal your messages if they have your mac address. Anyone on the same network as you, or within wifi range -- even if not connected to a wifi network, but with the radio on -- has your mac address. And you can never change it, so once someone snarfs it once, they get your account for life.
Edit: From the README on the GitHub page:
Password Overview
Android: MD5 hash of reversed IMEI (Credit: WhatsAPI Original Authors)
iOS: MD5 hash of the MAC address repeated twice (Credit: Ezio Amodio)
Windows Phone: MD5 hash of reversed DeviceUniqueId (Credit: Robe Fernández)*Maybe they are grandfathered in? Would they be banned if they pushed an update? Are Apple afraid of kicking out an iMessage competitor?
You just install it, whack in your phone number, and off it goes. Swap to a new phone? Whack in your phone number, and you're back on your account.
This is why WhatsApp has beaten out the competition (along with good marketing in airports, etc) - and there is A LOT of competition. By fixing this 'flaw', WhatsApp will fail. The best they could do is offer an 'advanced security' option for uses who want more secure communication, but the default insecurity will have to stay.
TLDR: Insecurity is the very bedrock of WhatsApp's popularity. It cannot be 'fixed' at this point.
So if I installed WhatsApp to my iPhone 4 under number 917-555-5555, WhatsApp will then text that number with an activation code and when I enter that activation code in the WhatsApp app, it ties that number to my phone with that phone's MAC address/IMEI.
If I then upgraded to the iPhone 5 under the same number, the process repeats itself and now ties that number to the iPhone 5 with it's MAC address/IMEI. I will now lose access to WhatsApp on that number on my iPhone 4.
Instead, just put the code up on github and link to it. The curious but cautious people would be able to verify the hack then
Whatsapp, if you are listening, do the following.. Add an extra column to your database table where user 'credentials' are saved. Lets call it 'password'. Or call it realpassword if you're using password for the md5'ed IMEI/MAC. Now, leave it empty for a moment..
On your next client update, force your users to fill in a password. Don't save it plaintext mmkay, drop a whole pot of salt all over it and save it in the password column. If user has a known password, check if their client sent the correct one.
You can still check IMEI or MAC address too if you want, but only as an extra 'check' to verify user is logging in from their mobile and not some fishy desktop client. Again, the latter isn't secure but is meant as a fallback.