Showing posts with label Hack Android. Show all posts
Showing posts with label Hack Android. Show all posts

Friday, 7 August 2015

Free App Checks Android Devices On Stage Fright Leak



Owners of an Android device that want to know whether they are vulnerable to severe Stage Fright leak can now download a free app that controls the device. Additionally, Samsung has an app ( .apk ) that empower users MMS messages can disable it on their device.

The Stage Fright-vulnerability was discovered by security Zimperium and Trend Micro. By only sending a MMS message an attacker could execute code on vulnerable machines. But the leak is attacking via apps websites. In reality, not about one vulnerability, but consists Stage Fright of ten different vulnerabilities, as has Zimperium let you know.

Google and several manufacturers have already announced that they will be releasing updates for Stage Fright serious flaw, which are expected to be rolled out by the end of this month. Through the free " Stage Fright detector App "by Zimperium now users can check whether they are still vulnerable. In addition, the security company also took the following video online in which the vulnerability is demonstrated.

Thursday, 6 August 2015

Google: Update Stage Fright Leak Available On Time


Owners of an Android device will receive a security update for a very serious leak in time, so has Google at the Black Hat conference in Las Vegas announced. It is the Stage Fright vulnerability can perform, allowing a remote attacker code on smartphones.

All that this requires is sending an MMS message, although the vulnerability via websites and apps is to attack. The problem was discovered by security Zimperium and Trend Micro. Both parties warned Google that then came up with an update.Rolling out the patch among telecom operators and manufacturers was difficult. Because of all the attention, and for the extent of the problem were various manufacturers in motion and made ​​known to come up with patches. As announced Samsung itself entirely new policy for the rollout of Android security updates. Each month users will soon receive updates.

In the case of Google, the Internet giant will today send updates to owners of a Nexus Nexus 5 and 6, according to Android Police, and Business Insider . According to Adrian Ludwig from the Android Security Team most Android users will receive the update later this month. Yet he is optimisch that users will be protected by existing security measures such as ASLR.This technology makes it harder to vulnerabilities like Stage Fright use and is present on 90% of Android devices. In addition, Ludwig expects the patches are rolled out on time, even before attackers through Stage Fright users can attack, reports The Verge .

Wednesday, 5 August 2015

Researchers Steal Remotely Fingerprint Android User


Researchers will today at the Blackhat conference in Las Vegas to show how they can steal the fingerprints of Android users on a large scale and at a distance. The attack is of course only possible on devices that include a fingerprint scanner.

The number of devices that this option offers is expected to grow strongly in the coming years, which in 2019 half of all smartphones has a fingerprint scanner. Researchers from security firm FireEye developed four ways to steal the fingerprint of a user. One attack is striking in particular, since that makes it possible to collect at a distance and on a large scale fingerprints. The attack is mounted on a HTC One Max and Samsung Galaxy S5. The problems which make possible the attack are present in the various Android "fingerprint frameworks".

"In this attack the fingerprint data of the victim fall directly into the hands of an attacker. For the rest of the life of the victim, the attacker can use this information to do wrong things," said researcher Zhang Yulong opposite ZDNet . How the attacks are precise in their work will be announced later today. The article will be updated. After being informed of a number of vendors now released patches.

Thursday, 16 April 2015

Leak In Popular AirDroid App Let Assume Attacker Device


A vulnerability in the popular AirDroid Android app made it possible for attackers to take over vulnerable devices once the user opened a link. AirDroid is a free app for managing an Android smartphone or tablet from Windows, Mac, or the Web.


It also supports GPS tracking, sending text messages, change and manage files from other apps. AirDroid has been downloaded more than 20 million times. The app was found to contain a serious authentication leak allowing a remote attacker could take over someone's phone or tablet. The only thing needed to do this was an attacker sending a malicious link that was opened by a user, for example via a chat application on Windows or Mac. "The attack can be performed silently, meaning that works even when the app is not running. Only the installation on a device is sufficient," says researcher Matt Bryant Bishop Fox .

In case of a successful attack is possible for the attacker to take pictures, follow the GPS location of the victim and contacts from the address book to attack difficult. Everything AirDroid has access to is accessible to an attacker. The vulnerability was reported to the developers of AirDroid who have solved the problem in the most recent version of the app. This fix was published in February , but the vulnerability is only now disclosed. The video below demonstrates the attack.

Thursday, 19 March 2015

9 Year Old Demonstrates Attack On Android Smartphone


A 9 year old boy last week during a security conference demonstrated how Android smartphones can be attacked by a malicious app. Reuben Paul gave during the B-Sides conference in Texas not only a demonstration, he also provided the keynote .

The boy showed how he through a malicious app, which looked like a game, was given access to the smartphone. Then he could turn on the camera and steal the address book, call history and messages. "Also, I located where they were," said Paul opposite My Fox Chicago . "If a child can do it, it's a piece of cake for a normal hacker." Through the demonstration Paul wanted to warn the public to be careful when downloading apps.

Thursday, 19 February 2015

Disabled Device Malware: "Android Malware Disables Smartphones Called Off"


Researchers at anti-virus company AVG discovered malware for Android that allows users to believe that the device is turned off, while this is not the case. The "disabled" device malware can then make calls, take pictures and perform other tasks.

Recording A Call
How the malware from spreading and where it was found just let AVG not know. However, the virus fighter says that the malware after installation will require root privileges. Then, different processes and injected hijacked objects. When users want to disable their smartphone hereinafter there appears a hoax which offers the possibility to turn off also the device.

Transmitting A Private Message
Users who see the unit off now get the real closing animation and the screen is black. However, the phone is still on. This is possible because a function that the phone actually turns off because the infection can never be invoked. Users who also want to be sure that get off their device AVG advised to remove the battery.