Tommy Mysk and Haj Bakry who are software developers found a critical flaw in the popular video-sharing TikTok app that allows hackers to modify and swap videos on any TikTok account. According to the analysis done by software developers, the TikTok app uses insecure HTTP to transfer its data . Because of this, the TikTok app's images and video transfer are unencrypted (in plain text). TikTok uses CDNs to transfer its data over HTTP. So, if a hacker act as Man-in-the-Middle between the TikTok app and TikTok's CDNs then a hacker can fetch the details of all the videos that a user has watched and downloaded in plain text . By the Man-in-the-Middle attack, it is possible for an attacker to modify the data in transmission and swap out an original video with a fake one . It is also possible that an attacker can spread spam, fake and misleading information in this way. The Developers also demonstrated this flaw by setting up a fake CDN server and their T
It features the latest cybersecurity related post and news.