HomeSecurityVulnerability in TikTok allows hackers to replace viral videos

TikTok vulnerability allows hackers to replace viral videos

video

According to developers Tommy Mysk and Talal Haj Bakry, a vulnerability they discovered in the popular social networking app TikTokcould allow hackers to replace users with fake ones.

The two developers published their findings in a blog post, stating that certain practices of the platform, which are not secure, have created a security gap that can be exploited by malicious actors. 

Like other apps , TikTok uses a CDN (Content Delivery Network) to quickly transfer massive amounts of video and other data over the internet. However, in TikTok's case, the CDN uses a less secure HTTP connection to improve performance.

It is known that whether an intruder, a government, or an ISP, could easily decrypt HTTP traffic. In this way, a malicious actor could gain access to a TikTok user's videos, as well as to the watch history and the videos they download.

The attacker could even replace these videos with fake ones or with videos from all accounts.

To prove their claims, Mysk and Bakry created a proof-of-concept themselves where they uploaded a misinformation video about the coronavirusto the official TikTok account of the World Health Organization (WHO).

The developers tricked the TikTok app, from a device connected to their home WiFi network, into sending requests to a custom server of theirs, designed to mimic TikTok's CDN.

Thus, by taking control of the server that exists between the TikTok app and its CDNs, developers can display and inject whatever they want, simply by changing the DNS registration information on the server, causing the app to be redirected to the fake server each time.

However, that doesn't mean that damage couldn't be done. "If a popular DNS server were compromised to include a malicious video, as we showed earlier, misleading information, fake news, or abusive videos would be served on a large scale, and that's something that could be done," the developers in their post.

The social network has already drawn the attention of the authorities, mainly because it is based in China and there are suspicions that it may collect users' personal data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS