HistoryJul 28, 2012 - 12:00 a.m.

meetOne Insecure Transport / Information Disclosure

meetOne, currently in Germany in the Top 50 social apps of the iTunes  
Store, has multiple vulnerabilities and has been found guilty of stealing  
Apple iPhone address books and abusing the e-mail addresses there for spam.  
Apple Inc. is ignoring the data theft and it seems even supressing  
information about it. meetOne also has lost its complete user database to  
the public, including CLEARTEXT passwords, and refuses to properly inform  
its members.  
meetOne is a subsidiary of ProSiebenSat.1, one of Germanys largest media  
corporations and running some of its largest TV stations, where meetOne is  
actively promoted. We've ran into serious problems getting information  
about the following data thefts and breaches published, probably because  
most German media outlets do not want to tackle a direct competitor like  
If you run the network traffic of the "meetOneToGo" iPhone application  
immediately after starting it and logging in through ngrep, you will notice  
multiple curious things:  
* Passwords are sent in clear text over HTTP (possibly identifying  
information has been cleared and replaced by ___ in the examples)  
HTTP/1.1 200 OK  
Cache-Control: no-store, no-cache, must-revalidate, post-check=0,  
Content-Type: application/json  
Date: ___  
Expires: Thu, 19 Nov 1981 __:__:__ GMT  
P3P: CP="HONK"  
Pragma: no-cache  
Server: nginx/1.0.12  
Set-Cookie: sid=________________________________; path=/; domain=.  
X-Powered-By: PHP/5.3.10-1~dotdeb.1  
Content-Length: ___  
Connection: keep-alive  
A couple of API calls later, it will upload your iPhone adress book without  
asking the user first. Please note, that the API name does not even  
disguise, that the feature is used for "inviting" (=spamming) those users  
(session id and irrelvant information removed from the example, to shorten  
it). In our experience, spam mails are sent 1-2 weeks later after the  
information has been stolen. Users are sent an e-mail where they're told  
they received a message on the site (even though they are not even  
registered yet at that moment) and have to register, to read the message  
(which is then a pretty lame "Welcome to meetOne").  
POST /api/phoneapi.php HTTP/1.1  
User-Agent: meetOne/2.2 CFNetwork/548.1.4 Darwin/11.0.0  
Content-Type: multipart/form-data; boundary=0xKhTmLbOuNdArY  
Content-Disposition: form-data; name="format"  
Content-Disposition: form-data; name="service"  
Content-Disposition: form-data; name="action"  
Content-Disposition: form-data; name="name[]"  
Name of first person in address book  
Content-Disposition: form-data; name="name[]".  
Name of second person in address book and so on.  
Content-Disposition: form-data; name="email[]"  
e-mail address of first person in address book  
Content-Disposition: form-data; name="email[]"  
e-mail address of second person in address book and so on  
Apple Inc. has been informed about this breach of German data protection  
laws and their own appstore rules on the 19th of July. Unfortunately, they  
do not pull the app from app store and allow the stealing of address books  
to continue.  
On the 22th of July, we were informed by Apple that "leider konnten wir  
anhand der sehr guten Rezessionen dieses Apps keine AuffΓ€lligkeiten  
feststellen.", which means (including a pretty lame misspelling by Apple's  
support), that Apple could not see further reports of this behaviour in the  
user reviews of the app and therefore WILL NOT ACT. This is especially  
ridiculous, as we know of at least one case, where a user review, which  
warned users about the data theft, was deleted by Apple from the store. So,  
it seems Apple is basing its decisions partly on the same user reviews  
which it censors itself. After we threatened, that we will publish our  
findings on the 23th of July, we were promised the case will be sent to the  
review team in the USA for further examination. Since then, we have not  
heard anything from Apple and further inquiries are simply ignored and stay  
To add insult to the injury, the site even leaks all stolen e-mail  
addresses to the public:  
The page contains an input type="hidden" field with the e-mail adress of  
the "invited" person. If you count the invID parameter up or down, you can  
access about 8 million e-mail-adresses which were obtained by stealing  
iPhone address books. We found our own address book entries there, which  
the app earlier stole.  
Now, on the most serious data breach. The app sends an API calll:  
Unfortunately, it was possible to call the same API WITHOUT session id, and  
with ANY (numerical) memberID and it happily returned all the users'  
information. As an experiment, we queried the data of member id "3" - a  
JSON dataset is returned, containg the clear text password as well as all  
kinds of information, like the sexual preferences of the user, in some  
cases even phone numbers or postal addresses.  
We've shortened the example considerably and removed identifying  
information by replacing critical places with ____. The account seems to  
belong to the owner of the site, by the way.  
12:00:00","changeDate":"2012-07-17 21:07:59","lastLoginDate":"2012-07-__  
+ habe Lust auf Flirt und komme aus Berlin. Schreib mir doch einfach eine  
kurze Nachricht, wenn Du mehr \u00fcber mich wissen willst. Ich w\u00fcrde  
After being informed by heise online  
site closed at least this data leakage and reset the passwords of all  
its members. Unfortunately, they chose NOT TO INFORM their members of the  
data leakage (it seems it has been open for months, nobody knows, who  
retreived the data, as even the site owners admit), instead they disguised  
the password reset as a "regular routine", so users of the site, which  
happened to use the same password somewhere else, still consider their  
passwords safe.  
Due to the lackluster media interest and Apples non-reaction, we've seen no  
other choice than full disclosure in this case.  