HomeSpacer
TV
Spacer
MOVIES
Spacer
MUSIC
Spacer
FASHION
Spacer
GEEKS
Spacer
BOOKS
Spacer
ART
Spacer
COMEDY
Spacer
DANCE
Spacer
CLASSICAL
Spacer
OPERA
Spacer
TRAVEL
Spacer
FITNESS
Spacer
THEATER
 
 LOG IN | REGISTER NOW!

GEEKS TODAY
TOP TOPICS
TOP MOBILE APPS
ABOUT US

Zscaler Uncovers Security Vulnerabilities in ESPN ScoreCenter Mobile App


Related: Mobile Security

Zscaler Uncovers Security Vulnerabilities in ESPN ScoreCenter Mobile App

Zscaler, the leading provider of Security Cloud services for the mobile, social, everywhere enterprise, today revealed that ESPN ScoreCenter, one of the most popular mobile sports apps on the market, has significant security vulnerabilities that could compromise users' mobile devices, including the threat of data theft. The flaws were unearthed using Zscaler Application Profiler (ZAP), the free online tool that makes it easy to assess mobile apps for security risks. ESPN said it is looking into the vulnerabilities in the ScoreCenter app. For more detailed background on this specific mobile app security threat, including a video on how to use ZAP, visit this blog post.

The security vulnerabilities with the ESPN ScoreCenter app highlight a growing security problem as mobile apps proliferate and basic security measures are overlooked in the development process.

"It's important to remember that many mobile apps are not native applications-they're essentially web pages displayed in a WebView control, or even just web content mixed in with native controls," said Michael Sutton, VP, Security Research, Zscaler ThreatLabZ. "As such, vulnerabilities common to web applications can also occur in mobile apps. Users should be aware that such vulnerabilities in mobile apps often remain hidden, as apps don't have the same visual indicators to show that data is being sent insecurely."

First, by displaying basic web content without properly sanitizing user-supplied input, ESPN SportsCenter exposes a cross-site scripting (XSS) flaw. Therefore, active content such as JavaScript can be injected into the app. Second, ESPN SportsCenter passes authentication credentials in clear text when an account is first created. By sending the password in clear text, ESPN ScoreCenter enables anyone sniffing traffic on the network to easily steal that key piece of information.

The flaws were Discovered using ZAP, Zscaler's Application Profiler. ZAP is an easy to use, free online tool where users can search the name of any iOS or Android app, and receive an instant assessment of its security and privacy risks, along with an overall risk score. Users can also use ZAP to scan traffic from an app installed on their device to see whether their own data is being exposed. No security expertise is needed to use ZAP. As more users submit mobile apps for analysis, Zscaler's ThreatLabZ team adds the results to the ZAP database, in effect crowdsourcing the security profiles of thousands of mobile apps.

Leave Comments

Related Links
BlackBerry 10 Smartphones Approved for Use On U.S. Department of Defense NetworksBlackBerry 10 Smartphones Approved for Use On U.S. Department of Defense Networks
May 02, 2013
Security Update: Mobile Malware Up 163% in 2012, 2013 to Be WorseSecurity Update: Mobile Malware Up 163% in 2012, 2013 to Be Worse
April 15, 2013
AVG Technologies Brings Family Safety to Windows Phone 8 DevicesAVG Technologies Brings Family Safety to Windows Phone 8 Devices
April 11, 2013
Survey: Users Now Carrying An Average of 3.1 Devices...Too Many?Survey: Users Now Carrying An Average of 3.1 Devices...Too Many?
March 14, 2013
Websense and F5 Networks Announce Joint Development of High-Performance Security SolutionsWebsense and F5 Networks Announce Joint Development of High-Performance Security Solutions
February 25, 2013

Past Articles by This Author:
  • BlackBerry to Launch BBM Messenger for iOS and Android this Summer
  • Apple vs. Samsung Update: Apple Adds Galaxy S4 to Massive Lawsuit
  • Condoleezza Rice, Walter Isaacson, Jim Collins to Headline ExactTarget Connections Sept. 17-19
  • ChannelAdvisor and Google Host Webinar to Share Tips for Success with Enhanced Campaigns
  • Leaf Unveils Second Generation of its Built-for-Business Tablet
  • BlackBerry Unveils Version 10.1 Now Available for Download for Enterprise Users
  • BlackBerry Announces Q5 a 'Youthful and Fun Smartphone'
  • BlackBerry to Webcast Keynote and Alicia Keys Performance from Orlando
  • McAfee and Intel Deliver New Model for Consumer Security - LiveSafe
  • Leaf Unveils New POS Android Tablet

    More Articles by This Author...

  • Get News & Specials!

    FLIPBOARD
    APPLE
    SAMSUNG
    GOOGLE
    TUMBLR
    BELKIN
    VERIZON
    PANASONIC
    NETFLIX
    T-MOBILE

    CBS HBO GAMING ACCESSORIES DISNEY SMASH CLOUD MOBILE ABC IPHONE

    Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars TUMBLR Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars
    Apple and Sony iRadio Negotiations Stymied by Song-Skipping APPLE Apple and Sony iRadio Negotiations Stymied by Song-Skipping
    Spike TV to Air Live Reveal of New Xbox Today SPIKE TV Spike TV to Air Live Reveal of New Xbox Today
    Adobe Creative Cloud FAIL; Suspends File Sync Service ADOBE Adobe Creative Cloud FAIL; Suspends File Sync Service
    New Bitcoin Service Available - MailACoin NEWS New Bitcoin Service Available - MailACoin
    HP and SAP Advance SAP HANA Through Joint Innovation ENTERPRISE HP and SAP Advance SAP HANA Through Joint Innovation
    Amazon Offers Exclusive Madden NFL 25 Package with FREE NFL Sunday Ticket MADDEN NFL 25 Amazon Offers Exclusive Madden NFL 25 Package with FREE NFL Sunday Ticket

    BWW TV World Logo
      
    BWW Movies World Logo
      
    BWW Fashion World Logo
      
    BWW Music World Logo
    BroadwayWorld.com Logo
      
    BWW Opera World Logo
      
    BWW Dance World Logo
      
    BWW Comedy World Logo
      

    All Materials Copyright 2013 Wisdom Digital Media | Privacy Policy | RSS/XMLFeeds