Showing posts with label Google Hangouts. Show all posts
Showing posts with label Google Hangouts. Show all posts

Wednesday, 4 November 2015

Critical Android Leak Fixes In Nexus Devices



During the patch cycle is from November Google poem multiple critical vulnerabilities in the Android version of Nexus devices, allowing an attacker to execute remote code on smartphones and tablets. Just as Microsoft is also Google each month with security updates.

It is in this case for updates to Nexus devices. The updates November fix seven vulnerabilities, two of which are labeled as critical. Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message, or if the user opens an e-mail or website. These are two leaks in the media server and libutils. The remaining five vulnerabilities, including one in the Stage Fright library, have a lesser impact.

According to Google, Android has several security measures that reduce the likelihood that Android leaks can be attacked successfully. For example, there are anti-exploit measures added to newer versions Android. In addition, search the Android Security Team via Verify Apps and SafetyNet to potentially harmful applications. Further send Google Hangouts, and Messenger will not automatically media to processes such as media server.

Updates are over-the-air (OTA) offered and are also available as firmware download. When the updates for the Android handsets from other manufacturers appear is unknown.

Friday, 11 September 2015

Exploit For Stage Fright Serious Flaw In Android Public


Researchers at the end of July, a serious leak revealed in Android have now published the exploit code that vulnerability on a single Android model can be attacked. The vulnerability allows an attacker to send arbitrary code to execute an MMS message, steal information, read e-mails and other tasks.

In the case of older Android devices, it is even possible to completely take over the device. The vulnerability is in Stage Fright, a media library that handles various popular media formats. Because of the severity of the problem decided Zimperium, the company that discovered the vulnerability, not to immediately publish the exploit.

Since the announcement, several manufacturers rolled out updates to protect users from the issue. Google also has new versions of Messenger and Hangouts released to automatic processing of multimedia files to block received via MMS.According Zimperium is therefore now the time has come to publish the exploit code, so that administrators and security professionals to test their systems.

However, the exploit has several limitations. It is not a generic exploit and works only against a single model, namely a Nexus to Android 4.0.4 running. The exploit is not 100% reliable. In addition, the vulnerability is attacked where the exploit makes use of rectified by security in Android 5.0 and newer.