November 23, 2024
Apple Announces iOS 6 Will Fix In-App Purchases Hack

Apple Announces iOS 6 Will Fix In-App Purchases Hack

Posted July 20, 2012 at 9:23pm by iClarified
Apple has announced that iOS 6 will fix a vulnerability that allowed a hacker to fraudulently validate in-app purchases.

A vulnerability has been discovered in iOS 5.1 and earlier related to validating in-app purchase receipts by connecting to the App Store server directly from an iOS device. An attacker can alter the DNS table to redirect these requests to a server controlled by the attacker. Using a certificate authority controlled by the attacker and installed on the device by the user, the attacker can issue a SSL certificate that fraudulently identifies the attacker's server as an App Store server. When this fraudulent server is asked to validate an invalid receipt, it responds as if the receipt were valid.

iOS 6 will address this vulnerability. If your app follows the best practices described below then it is not affected by this attack.



Apple also provides steps developers can take to circumvent the vulnerability now.

Read More [via Teresa]


Apple Announces iOS 6 Will Fix In-App Purchases Hack
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (2)
You must login or register to add a comment...
per10
per10 - July 21, 2012 at 2:39am
INSTALLOUS!!!!!!!!!!!!!!!!!!!!!!!!!!
DNA64
DNA64 - July 21, 2012 at 5:02am
TEXT EDIT/NOTEPAD!!! ;P
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Sequoia
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS