Skip to main content

Google Wallet Has Been Hacked – Two Vulnerabilities Discovered

The magic has been paused – Google Wallet which is an innovative way of payment technology from Google has been hacked today. Not with one vulnerability, but two.

The first hack is able to use brute-force attacks to reveal the Google Wallet PIN which keeps the application secure. The second hack allow access to Wallet app in your Android device and will add the ability to add the prepaid balance that is tied to the device.

 

Hacked Android 

To those who are hearing Google Wallet for the first time, it lets you digitize your credit cards and the ability to pay things using near-field communication (NFC) technology. It means, you can just touch your phone to an NFC device and the item you are buying is automatically charged to your account. Currently, only Google has implemented this technology with Google Wallet in its Android powered Nexus S 4G available on Sprint.

The first vulnerability which was discovered by Zvelo, reveals Google Wallet PIN in Android devices which are rooted. Wallet Cracker is a simple app developed by this team.

 

“The lynch-pin, however, was that within the PIN information section was a long integer “salt” and a SHA256 hex encoded string “hash”. Knowing that the PIN can only be a 4-digit numeric value, it dawned on us that a brute-force attack would only require calculating, at most, 10,000 SHA256 hashes. This is trivial even on a platform as limited as a smartphone. Proving this hypothesis took little time.”

 

Watch the video below for more details -

 

 

The second vulnerability which was discovered later today works on non-rooted devices as well and requires no special hacking skills. TheSmartPhoneChamp uploaded a video demo that shows this hack. This is quite simple than earlier one. Someone who found your stolen device can easily access your digital money (funds) by just clearing the Google Wallet app data. Once the new PIN has been entered, the intruder can add your Google Prepaid Card that is tied to the device and access available money.

Second hack demo -

 

 

Google has reportedly working on these two security flaws.

Comments

Popular posts from this blog

Microsoft Officially Confirmed New Windows Logo

Microsoft changed its Windows Logo, an inspired design from its new Metro interface. A day after Apple unveiled its next operating system Mountain Lion, Microsoft announced in an official blog confirmation that it has redesigned the Windows Logo. This new logo is truly inspired from its well known mobile operating system Windows Phone.         The new design is the biggest change from its classic 90s logo. In an official post , Microsoft’s Principal Director of User Experience for Windows confirmed that the new logo carries Metro principle of being ‘Authentically Digital’. “ It’s a window… not a flag …., “your name is Windows. Why are you a flag?” In some ways you can trace the evolution of the Windows logo in parallel with the advancements of the technology used to create logos. From the simple two color version in Windows 1.0 to the intricate and detailed renderings in Windows Vista and Windows 7, each change makes sense in the context i...

Breaking: Microsoft India Store Has Been Hacked. Passwords In Plain Text Format Exposed [Update]

Well, this is huge! Microsoft’s India online store website has been hacked and all user information which was stored in plain text format without any encryption has also been exposed. It looks like the hacker team got remote access to the whole web server. The main reasons behind this hack are still unknown but from the homepage replaced information, its been predicted that a non well known hacker organization EvilShadow is behind all this invasion.     Microsoft pulled out the store page right now and might be working on this to get back the site. The unacceptable thing in all this story is that the software giant stored all the user information including passwords in the database in plain text without any encryption for such online shopping site. Update (as of 11:45 PM Central Time, 2/12/12) – The Microsoft Store India is still currently unavailable to users. To patch up things, Microsoft is asking customers to change their passwords immediately. Full email me...

Windows Phone 7.5 Tango Officially Renamed As ‘Refresh’

The next version of Microsoft’s Windows Phone operating system after Mango 7.1 is officially renamed as ‘Windows Phone 7.5 Refresh’ – according to the head of Windows Phone division for Microsoft Italy.     According to Italian version of the post , 7.5 Refresh update will mostly be an update to the minimum specs of the devices it’ll be able to run (minimum RAM requirements is dropped from 512 MB to 256 MB). Other updates which may include in this release are better media messaging, location awareness icon, export and manage contacts to SIM card. The next major update after ‘Refresh’ is called Windows Phone Apollo (probably Windows Phone 8) could certainly be an exciting release from Microsoft. This Apollo update may have BitLocker kind of support on mobile devices, multi-core support. [ via ] [ Image ]