Secure Messengers and Man in the Contacts Attack
Offered By: OWASP Foundation via YouTube
Course Description
Overview
Explore the Man in the Contacts (MitC) attack and its implementation in this conference talk from OWASP AppSec EU 2018. Learn about the vulnerabilities in smartphone contact management that allow malicious applications to manipulate contact data for impersonation and communication interception. Discover how the speakers built and deployed a functional MitC implementation within a game published on Google's Play Store, demonstrating its potential as a spear phishing weapon. Gain insights into the responses from popular messaging apps, see a live demonstration, and understand possible mitigations for this security threat in mobile ecosystems.
Syllabus
Secure Messengers and Man in The Contacts - Laureline David & Jeremy Matos
Taught by
OWASP Foundation
Related Courses
People Information Gathering with the Social Engineering Toolkit (SET)Pluralsight Application of the MITRE ATT&CK Framework
Cybrary Linux Red Team Exploitation Techniques - Red Team Series
Linode via YouTube Windows Red Team Exploitation Techniques | Red Team Series 3-13
Linode via Independent Early Detection through Deception
YouTube