1 BILLION Android phones can be infected by text message

For discussions about security.
Post Reply
Message
Author
Bindee

1 BILLION Android phones can be infected by text message

#1 Post by Bindee »

http://www.theregister.co.uk/2015/07/27 ... text_flaw/
Android smartphones can be secretly infected by malware hidden in text messages
No user input is required to exploit this remote-code execution vulnerability – the victim doesn't even have to watch the video, just simply receive it on his or her phone.
pwned ....... :shock:

cthisbear
Posts: 4422
Joined: Sun 29 Jan 2006, 22:07
Location: Sydney Australia

#2 Post by cthisbear »


User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

#3 Post by 8Geee »

Ouch, thats gonna hurt.
Google flavored Android not the most open of devices, G# strikes again.
And the browser is vunerable, too (FF38/39 excepted).
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

Bindee

#4 Post by Bindee »

As it leaves no trace you can bet every government is now exploiting this until it's patched.

User avatar
Ted Dog
Posts: 3965
Joined: Wed 14 Sep 2005, 02:35
Location: Heart of Texas

#5 Post by Ted Dog »

lol guess its time to buy a iPhone :P

this seems like a bit of MUD or same idea that is the current favorite vector of infections font buffer overflow. so far its hit Apple ( OS and iphones ipads ) Microsoft ( all versions since dawn of time it seems ) fast patched out of cycle last week or so. Now Android! Do you wanta bet it also effects Linuxes. :wink: give it a week!

User avatar
Ted Dog
Posts: 3965
Joined: Wed 14 Sep 2005, 02:35
Location: Heart of Texas

#6 Post by Ted Dog »

Bindee wrote:As it leaves no trace you can bet every government is now exploiting this until it's patched.
Or they have already been and now will lose yet another back door. Good thing they probably have a decade head start on these flaws ( if they where put there on purpose to begin with Open source can be worse in some aspects ) :lol:

Bindee

#7 Post by Bindee »

For a bug there does seem to be a lot of coincidences about it that match a purposely built back door. :)

gcmartin

#8 Post by gcmartin »

Anybody else considering the obvious that happens all too often: Coding flaw that someone found to exist.

Patch is on the way to a phone near you.

User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

#9 Post by 8Geee »

Most FUD suggests

A.) take a hammer to the Android-phone
B.) Remove StageFright (lowers security by using a bypass)

I'll just say no to Android/Chrome/Flash in the meantime.
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

User avatar
greengeek
Posts: 5789
Joined: Tue 20 Jul 2010, 09:34
Location: Republic of Novo Zelande

#10 Post by greengeek »

8Geee wrote:B.) Remove StageFright (lowers security by using a bypass)
I'll just say no to Android/Chrome/Flash in the meantime.
Stagefright link here

User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

#11 Post by 8Geee »

Checked the link, lots to do in the meantime!
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

Bindee

#12 Post by Bindee »

http://www.theregister.co.uk/2015/08/06 ... _app_vuln/

Android faces SECOND patching crisis, on the same scale as Stagefright

‘Certifi-gate’ vuln could allow unrestricted device access

User avatar
Ted Dog
Posts: 3965
Joined: Wed 14 Sep 2005, 02:35
Location: Heart of Texas

#13 Post by Ted Dog »

Was talking with a former GOV paid white hat hacker, still a white hat but now remote crashing high end SUVs for a lawyer group. Stuff they did sounded cool but never once talked about going after good Americans only real baddies blackhats.
Of course he was mistrusting of gov being able do all the above but spent most time railing against blutooth.

amigo
Posts: 2629
Joined: Mon 02 Apr 2007, 06:52

#14 Post by amigo »

"Patch is on the way to a phone near you." Unforunately that is true for only a few brands/models.

User avatar
perdido
Posts: 1528
Joined: Mon 09 Dec 2013, 16:29
Location: ¿Altair IV , Just north of Eeyore Junction.?

#15 Post by perdido »

amigo wrote:"Patch is on the way to a phone near you." Unforunately that is true for only a few brands/models.
One simple fix for all android devices is to turn off auto-retrieve MMS messages in text settings. That will still allow receiving the text message, it just makes you tap the download button in the message to get the multimedia attachment.

"Patches? We don't need no stinking patches! I aint gonna show you no stinking patches".Image

User avatar
Ted Dog
Posts: 3965
Joined: Wed 14 Sep 2005, 02:35
Location: Heart of Texas

#16 Post by Ted Dog »

http://www.youtube.com/watch?v=VqomZQMZQCQ


had a co worker rework this line many times, I never knew the source. but its a classic movie and good acting by the guy delivering it. Do not know if he is playing the line with a comic twist or not :lol:

Image

Bindee

#17 Post by Bindee »

Researchers have found a way to steal fingerprints from Android phones packing biometric sensors.........

http://www.theregister.co.uk/2015/08/10 ... _cleartext

Mobile phone security , What security? :D

User avatar
8Geee
Posts: 2181
Joined: Mon 12 May 2008, 11:29
Location: N.E. USA

#18 Post by 8Geee »

Sadly, that rings true, as the various (nefarious) Phone-co's make you contract them as phone OS provider (Re: upgrades/updates to OS!, ATT is notorius) the pain is nearly palpable trying to get these guys in gear.
Linux user #498913 "Some people need to reimagine their thinking."
"Zuckerberg: a large city inhabited by mentally challenged people."

Post Reply