solution to how to find whatsapp user location
Recently the Cyber Forensics Research Group was commissioned to inform the WhatsApp security breach found, which allows for the location of a user when the shares through this application.
The main problem is that to share the location must start a conversation and located on the map, the application using WhatsApp to share location connects to services Google Maps this download thumbnail image that will serve as the icon for conversation chat, but this does not take into account that the channel through which lower the image is not encrypted.
Proof of Concept
We set up a scenario where only our mobile and be connected your computer to the Wi-Fi network.
In our computer use Wireshark to monitor packets traveling through the network.
Open Wireshark with administrator permissions, choose our wireless network card and then choose Start.
Whatsapp and Wireshark
It will start showing all packets transferred in the network, therefore we put the following ip.src == IP_DEL_MOVIL filter, it will show only the packets it sends your mobile device.
In our mobile, we open a conversation and share the location with a contact, we will see in Wireshark as data increases due to the communication established between our mobile and application.
Whatsapp and Wireshark
Stop getting packages and we must seek and find a HTTP GET request to query Google Maps, where the coordinates of the location of the user is displayed.
Whatsapp responded to Cyber Forensics Research Group that the solution to this bug has already been implemented in the beta, but we have not received this update on our devices to solve this problem of security. This proof of concept is only for educational purposes and we are not responsible for the use by the end user.