Showing posts with label Security Zimperium. Show all posts
Showing posts with label Security Zimperium. Show all posts

Friday, 2 October 2015

StageFright 2.0: Android Phones Vulnerable To New Stage Fright Leak


Millions of devices with Android are vulnerable because of a new vulnerability in the Stage Fright-media library and a security update from Google is not yet available. Reported security Zimperium. Stage Fright is a library that handles a variety of media formats.

A problem in the handling of MP3 or MP4 files ensures that an attacker could execute arbitrary code in the worst case to the unit. In late July, investigators were already several vulnerabilities in the Stage Fright library known. These include leak made ​​it possible to attack Android devices via MMS messages. The two now discovered vulnerabilities as "Stage Fright 2.0 identified". The first vulnerability is present in every Android device since version 1.0 was launched in 2008.

The researchers discovered a second leak making them the first leak on devices with Android 5.0 and newer can attack if a specially crafted MP3 or MP4 file is processed. Older phones may be at risk if the vulnerable component is invoked via third party apps or placed by the operator on the phone.

The primary attack vector for the first Stage Fright-leakage was via MMS, but this is in new versions of the Google Hangouts, and Messenger apps no longer possible. The researchers therefore see the browser as the main attack vector. An attacker could entice a user for example to a website or may execute the exploit via a man-in-the-middle. Google was informed on August 15 about the problems, but a patch is not yet available.

Friday, 11 September 2015

Exploit For Stage Fright Serious Flaw In Android Public


Researchers at the end of July, a serious leak revealed in Android have now published the exploit code that vulnerability on a single Android model can be attacked. The vulnerability allows an attacker to send arbitrary code to execute an MMS message, steal information, read e-mails and other tasks.

In the case of older Android devices, it is even possible to completely take over the device. The vulnerability is in Stage Fright, a media library that handles various popular media formats. Because of the severity of the problem decided Zimperium, the company that discovered the vulnerability, not to immediately publish the exploit.

Since the announcement, several manufacturers rolled out updates to protect users from the issue. Google also has new versions of Messenger and Hangouts released to automatic processing of multimedia files to block received via MMS.According Zimperium is therefore now the time has come to publish the exploit code, so that administrators and security professionals to test their systems.

However, the exploit has several limitations. It is not a generic exploit and works only against a single model, namely a Nexus to Android 4.0.4 running. The exploit is not 100% reliable. In addition, the vulnerability is attacked where the exploit makes use of rectified by security in Android 5.0 and newer.

Friday, 7 August 2015

Free App Checks Android Devices On Stage Fright Leak



Owners of an Android device that want to know whether they are vulnerable to severe Stage Fright leak can now download a free app that controls the device. Additionally, Samsung has an app ( .apk ) that empower users MMS messages can disable it on their device.

The Stage Fright-vulnerability was discovered by security Zimperium and Trend Micro. By only sending a MMS message an attacker could execute code on vulnerable machines. But the leak is attacking via apps websites. In reality, not about one vulnerability, but consists Stage Fright of ten different vulnerabilities, as has Zimperium let you know.

Google and several manufacturers have already announced that they will be releasing updates for Stage Fright serious flaw, which are expected to be rolled out by the end of this month. Through the free " Stage Fright detector App "by Zimperium now users can check whether they are still vulnerable. In addition, the security company also took the following video online in which the vulnerability is demonstrated.

Thursday, 6 August 2015

Google: Update Stage Fright Leak Available On Time


Owners of an Android device will receive a security update for a very serious leak in time, so has Google at the Black Hat conference in Las Vegas announced. It is the Stage Fright vulnerability can perform, allowing a remote attacker code on smartphones.

All that this requires is sending an MMS message, although the vulnerability via websites and apps is to attack. The problem was discovered by security Zimperium and Trend Micro. Both parties warned Google that then came up with an update.Rolling out the patch among telecom operators and manufacturers was difficult. Because of all the attention, and for the extent of the problem were various manufacturers in motion and made ​​known to come up with patches. As announced Samsung itself entirely new policy for the rollout of Android security updates. Each month users will soon receive updates.

In the case of Google, the Internet giant will today send updates to owners of a Nexus Nexus 5 and 6, according to Android Police, and Business Insider . According to Adrian Ludwig from the Android Security Team most Android users will receive the update later this month. Yet he is optimisch that users will be protected by existing security measures such as ASLR.This technology makes it harder to vulnerabilities like Stage Fright use and is present on 90% of Android devices. In addition, Ludwig expects the patches are rolled out on time, even before attackers through Stage Fright users can attack, reports The Verge .

Tuesday, 4 August 2015

Attack On Very Serious Android Leak Nearly Public



On a Chinese forum has published information about how a very serious flaw in Android can be used to attack millions of Android phones via only a single MMS message, although the vulnerability also through apps and websites exploit. Reported security Zimperium.

Zimperium discovered the vulnerability, which called Stage Fright got. Later it turned out that anti-virus company Trend Micro same vulnerability was independently discovered . According Zimperium the problem affects 950 million Android devices. It is estimated that in 50% of the sensitive devices the attack without any user interaction to perform. In other cases, opening an MMS sufficient.

Right

The attack an attacker could execute arbitrary code with system privileges or media on the device. Thus, an attacker could take complete control of the camera and microphone, for example, to monitor users. On some handsets running the vulnerable software that is attacked via the MMS message with system privileges. In this case, an attacker elevated privileges and can do almost anything on the device that the user can. Zimperium argues that this is, however, "some" equipment. An attacker could execute arbitrary code on a device, even if the media rights, then may however try to increase his rights.

Originally publish at the Black Hat security conference in Las Vegas this week an exploit. Several organizations asked Zimperium to wait this. Something the company has agreed with it. The security updates for Android, however, are open source. Therefore, many researchers now work on an exploit to attack the vulnerability, reports the company. "We therefore believe that it is only a matter of time before we see attacks in the wild, assuming they do not already take place", said security researcher Zuk Avraham of Zimperium last Saturday knowing. This morning the company warned via Twitter that an exploit is now almost public.

Updates

The problem is that many Android users to update their phone company or the manufacturer of the device are dependent, instead of Google. Therefore it can take a long time updates ultimately be offered if the device is still supported. Several older Android models that are vulnerable and are no longer supported miss an important security measure. As a result, the impact on these devices is much greater.

It would total to about 60 million sets. According to Avraham, an attacker will create a network worm to send MMS messages.Together would the aircraft, after being infected, can send six billion MMS messages per day. Something that could have consequences for the network of telecom providers.

Actions

Users who want to protect themselves getting Zimperium the advice to keep the device up to date. In case the device is no longer supported, users on an operating system such as CyanogenMod switch that supports older devices longer. Another measure that can be taken is to disable automatic retrieval of MMS messages.

Saturday, 1 August 2015

Seriously Android Leak Also To Attack On Apps And Websites


This week it was announced that there was a very serious leak is present in Android which allows an attacker installed on millions of Android phones malware by only sending a single MMS message. Stage Fright, such as the vulnerability is known, however, is also to attack in other ways, according to the Japanese anti-virus company Trend Micro .

Security Zimperium Stage Fright made known this week. Trend Micro says that it has also found the same vulnerability independently of Zimperium and on May 19 of this year has been reported to Google. This implies that at least two parties have discovered a critical vulnerability of this magnitude and this then Google decided to report.

Attack Vectors

Trend Micro, however, that there are more ways to use Stage Fright. In addition to sending an MMS message, an attacker can use an app to attack the vulnerability, and the use of a website. The vulnerability is caused by the way the Android media server handles MP4 files. This allows an attacker to cause a heap overflow and then execute arbitrary code such as installing malware.



In addition to sending a malicious MP4 file from an MMS message, it is also possible to embed such a file in a Web site or by allowing an app to open, and thereby infect an Android phone with malware. Google has already rolled out an update, but many Android users for patches depend on their telecom provider or manufacturer of the device if the device is still supported.According to Trend Micro, the problem in Android version 4.0.1 to 5.1.1, which represents 94% of all Android devices.

Monday, 27 July 2015

Millions Of Android Phones Vulnerable By New Leak



Researchers have discovered a serious vulnerability in Android which makes it possible to gain access to devices simply by sending an MMS message. Then an attacker can steal information, read emails, activate the microphone and perform other tasks. The vulnerability is in Stage Fright, a media library that handles various popular media formats.

Security Zimperium discovered vulnerability in the Android part, that the self worst Android leak calls so far. An attacker only needs namely to send an MMS message to execute code on the device. It is thereby even possible to remove the message before the user gets to see it. Only the acknowledgement is all that is visible. The researchers warn that the vulnerability is very serious, because there is no interaction from the victim is required.

Estimates suggest that 950 million Android devices running risk. The problem is particularly acute among Android versions Jelly Bean, which is about 11% of all Android devices. Zimperium warned Google that has already rolled out patches for Android. In many cases, telecoms providers and manufacturers are, however, responsible for distributing updates to their users and the security company also fears that it may take a long time before everyone is protected.

Two manufacturers, however, are a positive exception. Meanwhile the Black Phone Silent Circle is patched and Mozilla Firefox is protected from the issue. At the upcoming Black Hat conference in Las Vegas will have more details about the vulnerability are announced.