Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

Apple Mail Privacy Issue

Apple Mail Privacy Issue

A serious flaw in Apple Mail has been revealed by a German Website, which can expose the private data of the Mail users. The flaw is taken as serious as it can expose users' private data to spammers, phishers, cyber criminals and online tracking companies.

The vulnerability appears when a user uses Spotlight search feature. The feature happens to index your received emails if you use Apple Mail. So, when you use the Spotlight Search on a Mac, it will show you previews to your emails and this means it is automatically loading external images linked to the email.

Apple Mail Privacy Issue

If users open external files, their private data may unknowingly be shared with the email senders. Tracking pixels included in the emails by some senders may lead to sending of information back to the senders to tell them their email has been opened. Email marketers are the main users of this feature since it is their way of gathering data.

On first revelation of this Apple OS X Yosemite Spotlight feature vulnerability, IDG News Service tested this flaw by

sending emails with the tracking pixels to Apple Mail addresses. They managed to receive a preview of the unopened emails using Spotlight and they could see:

  • The receiver's IP address
  • The receiver's current OS version
  • Details about the receiver's browser
  • The receiver's Quick Look version

Apple Mail Privacy Issue

Apple Mail Privacy Issue

Apple Mail Privacy Issue: OS X Yosemite Again Vulnerable

Temporary Fix

While users have to wait for an official Patch to be delivered from Apple, there is a temporary fix for this problem:

  • Go to your system preferences
  • Click on Spotlight to access its settings
  • Uncheck the Mail & Messages option for Spotlight

By doing this, none of your emails will be loaded in the Spotlight search results anymore. These steps also ensure that no external content is loaded either.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.