User's DM won't deleted after logout from Twitter for iOS (com.atebits.xxx.application-state)
Unknown
Vulnerability Details
I would like to add an additional information regarding my previous report about "Unencrypted User's DM and Statuses on twitter.db at Twitter for iOS". I have already tried to logout from my Twitter apps (including from built-in twitter apps for iOS), and then, I already reboot the iDevice too. (tested on iPhone 5 with the same version of Twitter Apps).
In this situation, the twitter.db that located on Cache isn't appear anymore. But, Attacker could still access the User's DM including username and their chat partner from "app.acct.username-some.random.number.detail.10" that could be found on: "Applications > Documents > com.atebits.xxx.application-state".
For support my explanation, I attached the screenshot in this post too.
nb: I'm sorry for opening another ticket. Because, I see that the status is already closed on previous ticket.
Best Regard,
YoKo
Actions
View on HackerOneReport Stats
- Report ID: 23913
- State: Closed
- Substate: resolved
- Upvotes: 3