Go Back   iPod touch, iPhone, and iPad forum - Multi-Touch Fans > iPhone OS / iOS Ecosystem > iTunes App Store Games & Apps

What are you waiting for? Join the hundreds of thousands of other iPod touch and iPhone users in our community. Talk about the latest apps and accessories, or post your question on the forums! All visitors must register before they can post and answer questions and participate in our lively community, so register for free today!
Reply
 
Thread Tools Search this Thread
  #1  
Old 07-10-2009
SkylarEC's Avatar
Super Moderator Emeritus
Join Date: Sep 2007
 
None
Default Cancel your tapulous accounts now.

There is an utility called UDID changer, which is useless, but whatever. UDID can be used to change the UDID on someone's phones to your UDID.

Tapulous' complete authorization system is based on UDID. This means that if someone has your UDID and UDID changer, then they have access to your tapulous account. Tapulous stores your passwords on their server, and the only way to get to it is with the correct UDID, your UDID.

A malicious user changes their UDID to your UDID, accesses your Twinkle account and now have access to your Twitter and Facebook, and whatever else they store.


For the sake of safety, cancel your Tapulous accounts as soon as possible, or change your twitter and facebook passwords until this vulnerability is fixed.


All it takes for someone to get your UDID is for you to give it to them, whether or not you know you are. Well, how is this possible?
  • The malicious user may just ask you, and you may give it to them.
  • The malicious user may give you screenshots for a fantastic application they are making and offer you a beta. Of course, they need your UDID for you to beta test.
  • The malicious user may be someone you know that actually has access to your device.
  • Installer applications, such as Installer and Cydia send requests to the server with the UDID in the request. The maicious user may set up a repo to collect UDIDs.
  • Etc. There are so many ways, it's ridiculous.

Basically, you are not safe if you have a iPhone or iPod touch and a Tapulous account, you are at risk.


UPDATE Tapulous are aware of the exploit, and are now working on a fix.
__________________

Last edited by SkylarEC; 07-10-2009 at 04:24 PM..
  #2  
Old 07-10-2009
Banned
Join Date: Jul 2009
 
2G iPod touch 32GB
3.0 jailbroken
*goes to cancel account*
Woah thats not ok. Thanks for the heads up.
  #3  
Old 07-10-2009
mitchell209's Avatar
Multi-Touch Maven
Join Date: Jan 2009
 
iPad 16GB
3.2 jailbroken
Oh, that doesn't sound good.

I don't know my Tapulous account, though.
I don't even have a Facebook, so it's all good for me, though.

Let's hope they can fix this soon.
Sponsored Links
  #4  
Old 07-10-2009
BadKarma's Avatar
Multi-Touch Addict
Join Date: Jul 2008
 
iPod touch 8GB
3.0 jailbroken
Very true, but I wonder how you are going to get the "dim-witted" to heed this warning.
  #5  
Old 07-10-2009
mitchell209's Avatar
Multi-Touch Maven
Join Date: Jan 2009
 
iPad 16GB
3.2 jailbroken
Quote:
Originally Posted by The Joker View Post
Very true, but I wonder how you are going to get the "dim-witted" to heed this warning.
We're not. We'll just laugh at them for not heeding the warning.
  #6  
Old 07-10-2009
SkylarEC's Avatar
Super Moderator Emeritus
Join Date: Sep 2007
 
None
The dim witted failing to heed the warning are those that will make Tapulous take notice and fix their system.
  #7  
Old 07-10-2009
APVangeliLMS's Avatar
Multi-Touch Lover
Join Date: Jan 2009
 
iPhone 3G (Black) 8GB
4.0.1
What?

I would think they should get right on to fixing that like now!

Twinkle is the only twitter app I like to use though... darn.
  #8  
Old 07-10-2009
SkylarEC's Avatar
Super Moderator Emeritus
Join Date: Sep 2007
 
None
Quote:
Originally Posted by APVangeliLMS View Post
What?

I would think they should get right on to fixing that like now!
They won't fix it if they don't know about it. Spread the word.
  #9  
Old 07-10-2009
APVangeliLMS's Avatar
Multi-Touch Lover
Join Date: Jan 2009
 
iPhone 3G (Black) 8GB
4.0.1
Quote:
Originally Posted by SkylarEC View Post
They won't fix it if they don't know about it. Spread the word.
I shall tell them through their twitter and twinkle accounts!
  #10  
Old 07-10-2009
Multi-Touch Amateur
Join Date: Feb 2009
 
alright. How do u cancel it?
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT -7. The time now is 02:34 PM.

Recent blog posts: Recent threads:

Powered by vBulletin®
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2007 - 2010 Vigorous Media LLC - All Rights Reserved.


no new posts
Page generated in 0.05645 seconds with 9 queries