| By Business Wire | Article Rating: |
|
| January 18, 2013 12:31 PM EST | Reads: |
758 |
Please replace the release with the following corrected version due to multiple revisions.
The corrected release reads:
ZSCALER UNCOVERS SECURITY VULNERABILITIES IN ESPN SCORECENTER MOBILE APP
Security Risks Present in ESPN ScoreCenter Highlight More Widespread Security Problems With Mobile Apps
Zscaler®, the leading provider of Security Cloud services for the mobile, social, everywhere enterprise, today revealed that ESPN ScoreCenter, one of the most popular mobile sports apps on the market, has significant security vulnerabilities that could compromise users’ mobile devices, including the threat of data theft. See this blog post for more background information: http://research.zscaler.com/2013/01/mobile-app-wall-of-shame-espn.html. The flaws were unearthed using Zscaler Application Profiler (ZAP), the free online tool that makes it easy to assess mobile apps for security risks. ESPN said it is looking into the vulnerabilities in the ScoreCenter app.
The security vulnerabilities with the ESPN ScoreCenter app highlight a growing security problem as mobile apps proliferate and basic security measures are overlooked in the development process.
“It’s important to remember that many mobile apps are not native applications—they’re essentially web pages displayed in a WebView control, or even just web content mixed in with native controls,” said Michael Sutton, VP, Security Research, Zscaler ThreatLabZ. “As such, vulnerabilities common to web applications can also occur in mobile apps. Users should be aware that such vulnerabilities in mobile apps often remain hidden, as apps don’t have the same visual indicators to show that data is being sent insecurely.”
First, by displaying basic web content without properly sanitizing user-supplied input, ESPN ScoreCenter exposes a cross-site scripting (XSS) flaw. Therefore, active content such as JavaScript can be injected into the app. Second, ESPN ScoreCenter passes authentication credentials in clear text when an account is first created. By sending the password in clear text, ESPN ScoreCenter enables anyone sniffing traffic on the network to easily steal that key piece of information.
The flaws were discovered using ZAP, Zscaler’s Application Profiler. ZAP is an easy to use, free online tool where users can search the name of any iOS or Android app, and receive an instant assessment of its security and privacy risks, along with an overall risk score. Users can also use ZAP to scan traffic from an app installed on their device to see whether their own data is being exposed. No security expertise is needed to use ZAP. As more users submit mobile apps for analysis, Zscaler’s ThreatLabZ team adds the results to the ZAP database, in effect crowdsourcing the security profiles of thousands of mobile apps.
About Zscaler
Zscaler is transforming enterprise security with the world’s largest security cloud built from the ground up to safely enable users doing business beyond the corporate network. Zscaler’s security cloud processes over 8 billion transactions a day with near-zero latency to instantly secure over 10 million users in 180 countries, with no hardware or software required. More than 3,500 global enterprises are using Zscaler today to simplify their IT operations, consolidate point security products, and securely enable their business for mobility, cloud and social media. For more information, visit us at www.zscaler.com.
Zscaler® and the Zscaler Logo are trademarks of Zscaler, Inc.
All other trademarks are the property of their respective firms.
Published January 18, 2013 Reads 758
Copyright © 2013 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Business Wire
Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Windows Azure IaaS Reaches General Availability
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Enterasys Spotlights SDN's Impact on Traditional Networking in Upcoming Webinar
- NASA's Twitter Account Wins Back-To-Back Shorty Awards
- Big Data Isn’t About the Database, It’s About the Application
- BEA Updates WebLogic SOA Portal for Web 2.0 Era
- Basho Announces Open Source Riak CS and General Availability of Riak CS Enterprise v1.3
- Cloud Expo New York | Danger Ahead: Why File Sync Is NOT Endpoint Backup
- Charli XCX Sets US Headline Tour; High Profile Dates Celebrate Upcoming Debut Album Featuring the Hit Single, "You're The One" and the YouTube Smash, "You (Ha Ha Ha)"; UK Angel-Pop Sensation Takes Texas by Storm With Series of Spectacular SXSW Showcases;
- Symphony EYC Appoints New Account Manager to Drive Global Opportunities
- Cloud People: A Who's Who of Cloud Computing
- Cloud Expo New York Speaker Profile: Dave Linthicum – Cloud Technology Partners
- Cloud Expo New York Speaker Profile: Jill T. Singer – NRO
- Examining the True Cost of Big Data
- Cloud Expo New York: How to Use Google Apps Script
- Windows Azure IaaS Reaches General Availability
- Upcoming Domino's Pizza Investor Events
- New Relic Q1 2013 Blazes Past Growth Targets and Reaches 40,000 Active Customer Accounts
- Enterasys Spotlights SDN's Impact on Traditional Networking in Upcoming Webinar
- Rackspace Hosting Named “Platinum Plus Sponsor” of Cloud Expo New York
- NASA's Twitter Account Wins Back-To-Back Shorty Awards
- Scripps Networks Interactive’s Popular Lifestyle Shows from HGTV, DIY Network, Food Network, Cooking Channel and Travel Channel Coming to Prime Instant Video and Amazon Instant Video
- The Top 150 Players in Cloud Computing
- Who Are The All-Time Heroes of i-Technology?
- Where Are RIA Technologies Headed in 2008?
- Success, Arrogance, Rise and Fall
- AJAX World RIA Conference & Expo Kicks Off in New York City
- Personal Branding Checklist
- The Top 250 Players in the Cloud Computing Ecosystem
- i-Technology Viewpoint: Attack of the Blogs
- Exclusive Q&A with Jeff Haynie, Co-Founder & CEO, Appcelerator
- Web 2.0 News and Wrapping Up "Real-World AJAX" Seminar
- Passing Parameters to Flex That Works
- i-Technology Viewpoint: It's Time to Take the Quotation Marks Off "Web 2.0"






















