Security vulnerabilities in ESPN ScoreCenter mobile app
Posted on 18 January 2013.
Bookmark and Share
ESPN ScoreCenter, one of the most popular mobile sports apps on the market, has significant security vulnerabilities that could compromise users’ mobile devices, including the threat of data theft.

First, by displaying basic web content without properly sanitizing user-supplied input, ESPN SportsCenter exposes a cross-site scripting (XSS) flaw. Therefore, active content such as JavaScript can be injected into the app.

Second, ESPN SportsCenter passes authentication credentials in clear text when an account is first created. By sending the password in clear text, ESPN ScoreCenter enables anyone sniffing traffic on the network to easily steal that key piece of information.

“It’s important to remember that many mobile apps are not native applications—they’re essentially web pages displayed in a WebView control, or even just web content mixed in with native controls,” said Michael Sutton, VP, Security Research, Zscaler ThreatLabZ.

“As such, vulnerabilities common to web applications can also occur in mobile apps. Users should be aware that such vulnerabilities in mobile apps often remain hidden, as apps don’t have the same visual indicators to show that data is being sent insecurely,” Sutton added.

The flaws were unearthed using Zscaler Application Profiler (ZAP), the free online tool that makes it easy to assess mobile apps for security risks. ESPN said it is looking into the vulnerabilities in the ScoreCenter app.





Spotlight

Attackers use reflection techniques for larger DDoS attacks

Posted on 17 April 2014.  |  Instead of using a network of zombie computers, newer DDoS toolkits abuse Internet protocols that are available on open or vulnerable servers and devices. This approach can lead to the Internet becoming a ready-to-use botnet for malicious actors.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Apr 18th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //