Breaking News

TerraMaster Launches F2-425 2-Bay NAS Announcing ASUS NUC 15 Performance ASUS and Noctua announce ASUS GeForce RTX 5080 Noctua Edition graphics card G.SKILL DDR5 R-DIMM Achieves DDR5-8400 CL38 256GB (8x32GB) Overclock with AMD Ryzen Threadripper PRO 9985WX Processor TEAMGROUP Unveils NV5000 M.2 PCIe 4.0 SSD

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Uncovered 'Master key' Makes Android Phones Makes Vulnerable

Uncovered 'Master key' Makes Android Phones Makes Vulnerable

Smartphones Jul 4,2013 0

Security research firm BlueBox has discovered a vulnerability that could allow cyber-thieves to turn any legitimate Android application into a Trojan, completely unnoticed by the phone user. The vulnerability in Android?s security model allows a hacker to turn any legitimate application into a malicious Trojan. The vulnerability has been around at least since the release of Android 1.6 and could affect any Android phone released in the last 4 years - or nearly 900 million devices. According to BlueBox, depending on the type of application, a hacker can exploit the vulnerability for anything from data theft to creation of a mobile botnet.

Installation of a Trojan application from the device manufacturer can grant the application full access to Android system and all applications (and their data) currently installed. The application then not only has the ability to read arbitrary application data on the device (email, SMS messages, documents, etc.), retrieve all stored account & service passwords, it can essentially take over the normal functioning of the phone and control any function thereof (make arbitrary phone calls, send arbitrary SMS messages, turn on the camera, and record calls). Finally, and most unsettling, is the potential for a hacker to take advantage of the always-on, always-connected, and always-moving (therefore hard-to-detect) nature of these "zombie" mobile devices to create a botnet.

The vulnerability involves discrepancies in how Android applications are cryptographically verified & installed, allowing for APK code modification without breaking the cryptographic signature.

All Android applications contain cryptographic signatures, which Android uses to determine if the app is legitimate and to verify that the app hasn't been tampered with or modified. This vulnerability makes it possible to change an application's code without affecting the cryptographic signature of the application - essentially allowing a malicious author to trick Android into believing the app is unchanged even if it has been.

While the risk to the individual and the enterprise is great, this risk is compounded when you consider applications developed by the device manufacturers (e.g. HTC, Samsung, Motorola, LG) or third-parties that work in cooperation with the device manufacturer (e.g. Cisco with AnyConnect VPN) - that are granted special elevated privileges within Android - specifically System UID access.

Google had no comment to make on BlueBox's discovery.

Tags: android
Previous Post
Samsung Introduces The WB110 Camera with 26x Optical Zoom
Next Post
Huawei, London college To Cooperate On Big Data Technologies

Related Posts

  • What’s new in Android 15, plus more updates

  • Connecting all things Android at MWC Barcelona

  • New features for businesses in Android 13

  • Lucky number Android 13: The latest features and updates

  • What’s beta than Android 13?

  • HLDS UD Station DVDRW (Preview)

  • Android Gets a New Keyboard for Typing Braille

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

Latest News

TerraMaster Launches F2-425 2-Bay NAS
Enterprise & IT

TerraMaster Launches F2-425 2-Bay NAS

Announcing ASUS NUC 15 Performance
Enterprise & IT

Announcing ASUS NUC 15 Performance

ASUS and Noctua announce ASUS GeForce RTX 5080 Noctua Edition graphics card
GPUs

ASUS and Noctua announce ASUS GeForce RTX 5080 Noctua Edition graphics card

G.SKILL DDR5 R-DIMM Achieves DDR5-8400 CL38 256GB (8x32GB) Overclock with AMD Ryzen Threadripper PRO 9985WX Processor
PC components

G.SKILL DDR5 R-DIMM Achieves DDR5-8400 CL38 256GB (8x32GB) Overclock with AMD Ryzen Threadripper PRO 9985WX Processor

TEAMGROUP Unveils NV5000 M.2 PCIe 4.0 SSD
Enterprise & IT

TEAMGROUP Unveils NV5000 M.2 PCIe 4.0 SSD

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed