> By providing any WhatsApp registered telephone number
and the text for the status update, it is possible to change a user's
status. This action does not require any prior authentication or
authorization
> (on registration) The vendor has implemented bruteforce
protection by locking a number after 10 tries. This step makes a
successful attack on a specific number unlikely but an attacker
bruteforcing X00 numbers can still guess X number(s) on average.
> As published in the past several times already the XMPP traffic from
WhatsApp is not encrypted.
And they are planning to charge money for it?
edit: perhaps even worse is their response to the security vulnerability seen in the timeline - they knew about the bug since 09-14
Comments
Some more information about this can be found here: http://packetstormsecurity.org/files/108010/SA-20111219-1.tx...
Wow it seems there is no security at all:
> By providing any WhatsApp registered telephone number and the text for the status update, it is possible to change a user's status. This action does not require any prior authentication or authorization
> (on registration) The vendor has implemented bruteforce protection by locking a number after 10 tries. This step makes a successful attack on a specific number unlikely but an attacker bruteforcing X00 numbers can still guess X number(s) on average.
> As published in the past several times already the XMPP traffic from WhatsApp is not encrypted.
And they are planning to charge money for it?
edit: perhaps even worse is their response to the security vulnerability seen in the timeline - they knew about the bug since 09-14