Skip to main content

Hundreds of GPS Location Tracking Services Leaving User Data Open to Hackers


gps-location-tracking-device


Security researchers have unearthed multiple vulnerabilities in hundreds of GPS services that could enable attackers to expose a whole host of sensitive data on millions of online location tracking devices managed by vulnerable GPS services.

The series of vulnerabilities discovered by two security researchers, Vangelis Stykas and Michael Gruhn, who dubbed the bugs as 'Trackmageddon' in a report, detailing the key security issues they have encountered in many GPS tracking services.

Trackmageddon affects several GPS services that harvest geolocation data of users from a range of smart GPS-enabled devices, including children trackers, car trackers, pet trackers among others, in an effort to enable their owners to keep track of where they are.

According to the researchers, the vulnerabilities include easy-to-guess passwords (such as 123456), exposed folders, insecure API endpoints, and insecure direct object reference (IDOR) issues.

By exploiting these flaws, an unauthorized third party or hacker can get access to personally identifiable information collected by all location tracking devices, including GPS coordinates, phone numbers, device model and type information, IMEI numbers, and custom assigned names.

gps-location-tracking




What's more? 
On some online services, an unauthorized third party can also access photos and audio recordings uploaded by location tracking devices.

The duo said they have been trying to reach out to potentially affected vendors behind the affected tracking services for warning them of the severity of these vulnerabilities.

According to the researchers, one of the largest global vendors for GPS tracking devices, ThinkRace, may have been the original developer of the flawed location tracking online service software and seller of licenses to the software.
Although four of the affected ThinkRace domains have now been fixed, the remaining domains still using the same flawed services continue to be vulnerable. Since many services could still be using old versions of ThinkRace, users are urged to stay up-to-date.
"We tried to give the vendors enough time to fix (also respond for that matter) while we weighted this against the current immediate risk of the users," the researchers wrote in their report. 
"We understand that only a vendor fix can remove user’s location history (and any other stored user data for that matter) from the still affected services but we (and I personally because my data is also on one of those sites) judge the risk of these vulnerabilities being exploited against live location tracking devices much higher than the risk of historic data being exposed."
In many cases, vendors attempted to patch the vulnerabilities, but the issues ended up re-appearing. Around 79 domains still remain vulnerable, and researchers said they did not know if these services would be fixed.
"There have been several online services that stopped being vulnerable to our automated proof of concept code, but because we never received a notification by a vendor that they fixed them, it could be that the services come back online again as vulnerable," the duo said.
You can find the entire list of affected domains on the Trackmageddon report.

Stykas and Gruhn also recommended some suggestions for users to avoid these vulnerabilities, which includes removing as much data from the affected devices as possible, changing the password for the tracking services and keeping a strong one, or just stopping to use the affected devices until the issues are fixed.

Comments

Popular posts from this blog

#Facebook Video vs #YouTube Video find better one.

Live streams are now, mainstream. Live video has grown faster than most mediums, because it establishes a real-time connection and facilitates a conversation between the streamer and the audience. Nowadays, most social media platforms and video platforms allow you to stream live video. But, between the 2 major platforms, YouTube and Facebook, which one is actually the best for you to live stream to? On this blog post, we’ll talk about YouTube live vs. Facebook live. Here, you’ll find a side-by-side comparison between Facebook and YouTube, to help you decide where to focus your live streaming efforts as a brand or individual. Regardless of the platform, you prefer, keep in mind that they are the 2 biggest platforms out there. If you want to build an online audience, it’s wise to have an online presence on both. You can share different content on each of them, but for live streaming events and intricate live videos, you can and should go live on both platforms at the same time. This way,...

Thousands of Government Websites Hacked to Mine Cryptocurrencies

There was a time when hackers simply defaced websites to get attention, then they started hijacking them to spread banking trojan and ransomware, and now the trend has shifted towards injecting scripts into sites to mine cryptocurrencies. iPhone-X Styled ASUS Zenfone 5, Brings Along More Zenfone 5 Lite Renders Thousands of government websites around the world have been found infected with a specific script that secretly forces visitors' computers to mine cryptocurrency for attackers. Have you ever faced difficulty in transferring cash to a friend or relative The cryptocurrency mining script injection found on over 4,000 websites, including those belonging to UK's National Health Service (NHS), the Student Loan Company, and data protection watchdog Information Commissioner's Office (ICO), Queensland legislation, as well as the US government's court system. World’s tallest hotel Users who visited the hacked websites immediately had their computers...

CCI imposes Rs 135.86 crore penalty on Google for search bias

CCI noted in its order that undue intervention in product design can affect legitimate product improvements, given that design is an important dimension of competition. 4G smartphones at Rs 500, on a monthly plan of Rs 60 NEW DELHI|MUMBAI: The Competition Commission of India (CCI) has imposed a ?136-crore fine on Google for "search bias" and abusing its "dominant position". The Indian competition regulator's ruling comes after similar setbacks in the European Union and Russia for the world's most popular search engine. An introduction to Progressive Web Apps In a 190-page order, the Competition Commission of India (CCI) said Google abused its dominant position on three counts that largely relate to search, while no foul play was seen in case of advertising. CCI imposed a penalty amounting to 5% of the average revenue generated from India over the three years to FY15, an amount of ?135.85 crore, which has to be deposited within 60 days. A ma...