Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

iOS 9 is under threat! Once again XcodeGhost is attacking on apple!

In China, a malware called XcodeGhost was found, which was infecting a lot of applications on Apple’s App Store. Very popular applications were also under its control such as WeChat. All these things happened during the September of this year. Apple reacted quickly to fix this problem but XcodeGhost is still alive and it has been found running on iOS 9 devices once again in many enterprise environments.

FireEye (a security vendor) said that according to their research from last four weeks 210 enterprise networks are using XcodeGhost infected applications. Some of these enterprises are in US. More than 25,000 attempts have been generating by these apps to connect to the malware’s own commands and control servers.

FireEye researchers has demonstrate some scenarios, they said when attackers may not be controlling the servers then it is possible to hijack the traffic to provide applications to iOS using devices outside the App Store, forcefully promotion of any application in the App Store by automatically directing iOS users to a download page, launch of pop-up windows which is phishing in actual, force browsers to open URLs. According to FireEye, XcodeGhost is running on the iPhones which are using iOS version 6 to 9. Some users were aware about it and they update their iOS versions but a number of users are still using outdates iOS. Due to this XcodeGhost is infecting devices once again.

 According to FireEye, “Some of enterprises are doing too much effort to block the XcodeGhost DNS query within the network of their enterprise to cut off the communication between employee’s iPhones and the attacker’s CnC servers. By doing this they could be protect themselves from being hijacked. But they need to know that, until these employees will not update their devices and apps, they will be vulnerable to the XcodeGhost outside their enterprise.”

In US enterprises, there are so many devices which are infected with XcodeGhost. All this happen within a very short time period. “This malware is a big threat for organizations”, FireEye said. A new variant of XcodeGhost dubbed XcodeGhost S, is very dangerous for ATS (Application Transport Security) feature. This feature is Apple’s latest weapon against malware.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.