Facebook   Twitter    e-mail newsletter    YouTube    RSS Feed    Android App    iPhone and iPad App     BlackBerry App    


Page 1 of 2 1 2 LastLast
Results 1 to 15 of 19

Thread: Android vulnerability explained

  1. #1

    Default Android vulnerability explained

    Android vulnerability explained

    It isn’t clear whether South African users of Samsung Android devices are vulnerable to a remote wipe exploit

  2. #2

    Default

    Mmmm... Let me take a bite of an Apple while I feel sorry for the other people in the Galaxy.

  3. #3
    Grandmaster lcbxx's Avatar
    Join Date
    Apr 2006
    Location
    Wilgeheuwel
    Posts
    4,000

    Default

    Just test it and then it will be clear...

  4. #4

    Default

    to late this story was on engadget days ago

  5. #5
    Senior Member
    Join Date
    Jan 2004
    Location
    Centurion, South Africa
    Posts
    238

    Default Not really USSD

    Hi,

    Technically, the original article is incorrect to refer to the star/hash-codes as USSD (eg. *#06# to get your IMEI). USSD makes use of a signalling channel between the phone and the network and is initiated by dialing a service code such as *100# (on Vodacom, for example). The exploits do not use USSD, but they do use locally enabled star/hash-codes on the phone.

    As Jan Vermeulen correctly points out, real USSD still requires you to hit the dial button and does not immediately execute when the code is entered.

    I've confirmed that the exploit also does not work on the Motorola DROID3 and a few other Moto devices are also immune. But it's still a nasty hole indeed for unpatched S3's.

    --deckert

  6. #6
    You can't stop The Signal Jan's Avatar
    Join Date
    May 2010
    Location
    The Rabbit Hole
    Posts
    1,850

    Default

    Quote Originally Posted by etphonehome View Post
    to late this story was on engadget days ago
    We've been waiting for comment from Samsung and trying to test on local devices. The Androids in the US and UK are not necessarily the same as SA.
    Quote Originally Posted by TJ99 View Post
    Tech "journalists" are vile sub-human scum, only 1 step above gaming "journalists" these days. Check out the 1st comment for the real story. Of course nothing will ever convince the true believers.

  7. #7

    Default

    Upgrade to JellyBean! FIXED!
    ~*!Needle in my mind!*~
    Samsung GALAXY SIII - Power of the Galaxy in your hands!
    ALIENWARE M11x R3 | Intel i5-2537M | 8GB Ram | DavyGT NVidia 1v Bios Mod

  8. #8
    You can't stop The Signal Jan's Avatar
    Join Date
    May 2010
    Location
    The Rabbit Hole
    Posts
    1,850

    Default

    Quote Originally Posted by Deckert View Post
    As Jan Vermeulen correctly points out, real USSD still requires you to hit the dial button and does not immediately execute when the code is entered.
    What's interesting is that the Samsung wipe code has the form of a USSD code (*2767*3855# - don't type this into your Samsung phone; the XDA guys say it factory _formats_ the device - you'll lose all the data on the device and not just the installed apps and settings) and there are reports of it running anyway.

    Quote Originally Posted by Deckert View Post
    I've confirmed that the exploit also does not work on the Motorola DROID3 and a few other Moto devices are also immune. But it's still a nasty hole indeed for unpatched S3's.
    Thanks for the feedback.

    Various guys have written various tests for this, and I've set up a few pages on my own webserver to run tests, but it seems to me that these tests aren't too reliable unless you're testing the actual factory format code.

    Unfortunately I don't have a non-Nexus Samsung device to test with, but if anyone wants to run the tests anyway I'll publish links to the pages I've written. They basically test for remote execution of the *#*#nnnn#*#* type codes, and then I've also written one that tests for remote execution of a MTN contract USSD code (*162#).
    Quote Originally Posted by TJ99 View Post
    Tech "journalists" are vile sub-human scum, only 1 step above gaming "journalists" these days. Check out the 1st comment for the real story. Of course nothing will ever convince the true believers.

  9. #9

    Default

    It's to do with the TouchWizz launcher.
    I think the only people it will affect is Vodacom branded handsets as they still only have the May 4.0.4 firmware without the brightness slider on the notification shade.

    Vodacom leading the pack once again!

  10. #10
    You can't stop The Signal Jan's Avatar
    Join Date
    May 2010
    Location
    The Rabbit Hole
    Posts
    1,850

    Default

    Quote Originally Posted by alternate View Post
    It's to do with the TouchWizz launcher.
    I think the only people it will affect is Vodacom branded handsets as they still only have the May 4.0.4 firmware without the brightness slider on the notification shade.

    Vodacom leading the pack once again!
    Not everyone is convinced that it's to do with the TouchWiz launcher, which is why I did this article. Based on the Android patch linked to in the article, it looks like the vulnerability was only fixed in the stock dialler in July.

    However, other device manufacturers don't seem to support the factory format code I posted above (not going to post it again for fear of someone trying it out and blaming me).

    So the vulnerability in the diallers is there, but there's no secret code for a script kiddie to use to wipe your phone with unless you're on a Samsung.
    Quote Originally Posted by TJ99 View Post
    Tech "journalists" are vile sub-human scum, only 1 step above gaming "journalists" these days. Check out the 1st comment for the real story. Of course nothing will ever convince the true believers.

  11. #11
    MyBB Legend mercurial's Avatar
    Join Date
    Jun 2007
    Location
    /\/¯¯¯¯¯\/\
    Posts
    24,711
    We're all running on caveman software...
    I did not have NULL relations with that variable.
    My latest threads

  12. #12
    You can't stop The Signal Jan's Avatar
    Join Date
    May 2010
    Location
    The Rabbit Hole
    Posts
    1,850

    Default

    Also mentioned in the article, and The Verge reported they could still remote wipe an AT&T SGS3. One assumes that SA's less carrier-customised devices would already have received the update, but Samsung haven't responded to my queries and I don't have an SGS3 to test with.

    I have the exploit code hosted on my webserver, so if anyone wants to volunteer their Samsung device, I'm willing to volunteer a link. By PM, to protect the less savvy, of course.

    Samsung also doesn't mention any other Galaxy device, a number of which were reported as vulnerable in the original demonstration: http://www.youtube.com/watch?v=Q2-0B04HPhs
    Quote Originally Posted by TJ99 View Post
    Tech "journalists" are vile sub-human scum, only 1 step above gaming "journalists" these days. Check out the 1st comment for the real story. Of course nothing will ever convince the true believers.

  13. #13

    Default

    "Samsung haven't responded" Typical, but not as bad as LG.

    I don't understand, is my Galaxy S II (running ICS 4.0.3) and my Galaxy Tab P1000 (2.3.?) affected?

  14. #14

    Default

    At least google maps is working..

  15. #15
    You can't stop The Signal Jan's Avatar
    Join Date
    May 2010
    Location
    The Rabbit Hole
    Posts
    1,850

    Default

    Quote Originally Posted by Boris Becker View Post
    I don't understand, is my Galaxy S II (running ICS 4.0.3) and my Galaxy Tab P1000 (2.3.?) affected?
    Probably, and most likely respectively. Would you like to submit your devices for testing?

    I have non-destructive tests we can run as a first-order check if you want...
    Quote Originally Posted by TJ99 View Post
    Tech "journalists" are vile sub-human scum, only 1 step above gaming "journalists" these days. Check out the 1st comment for the real story. Of course nothing will ever convince the true believers.

Page 1 of 2 1 2 LastLast

Similar Threads

  1. HTC Android security vulnerability revealed
    By jes in forum Broadband and IT News
    Replies: 11
    Last Post: 02-12-2011, 03:51 PM
  2. Replies: 4
    Last Post: 03-10-2011, 02:39 PM
  3. Replies: 1
    Last Post: 07-07-2011, 02:31 PM
  4. New IE vulnerability
    By rpm in forum Broadband and IT News
    Replies: 22
    Last Post: 05-02-2010, 03:59 PM
  5. New DNS Vulnerability
    By Drake2007 in forum Software
    Replies: 0
    Last Post: 08-08-2009, 08:37 PM

Tags for this Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •