Presentation is loading. Please wait.

Presentation is loading. Please wait.

Researcher Finds Google Android Data Stealing Vulnerability 報告者:劉旭哲.

Similar presentations


Presentation on theme: "Researcher Finds Google Android Data Stealing Vulnerability 報告者:劉旭哲."— Presentation transcript:

1 Researcher Finds Google Android Data Stealing Vulnerability 報告者:劉旭哲

2 A researcher revealed a way to exploit a vulnerability affecting Google Android users that can be used to steal data The flaw impacts Android 2.3 The same nature as a vulnerability uncovered last year on Android 2.2. 目前已在 Nexus S 證實可以竊取資訊

3 Requires some knowledge of JavaScript and Android. Mainly in the Android browser – there is a nonbrowser component in Android The attack works by requiring the user to visit a malicious link.

4 STEPs 1.The Android browser doesn’t prompt the user when downloading a file – for example "payload.html“ – It automatically downloads to /sdcard/download/payload.html 2.Using JavaScript get this payload to automatically open – causing the browser to render the local file. 3.When opening an HTML file within this local context, – Browser will run JavaScript without prompting the user. – JavaScript is able to read the contents of files.

5 惡意網站惡意網站 惡意網站惡意網站 1. User 點擊惡意連結 2. 下載 payload.html 3. 瀏覽器執行 JS ,打開 payload.html 4. Payload.html 抓取特定文件

6 One limiting factor : – Know the name and path of the file. – However, data with consistent names on the SD card, and pictures stored with a consistent naming convention – An attacker could also read and upload any file "stored on the phone's /sdcard" The attack is not a root exploit and still runs in the Android sandbox. – Attackers cannot grab all the files on the system.

7 However, there are other ways to exploit the same flaw. The ultimate fix will require changing some essential components in the Android framework itself.

8 Other interesting news: – FBI issues warrants over pro-WikiLeaks attacks – Facebook blames bug for Zuckerberg page hack – Facebook Puts HTTPS Security Guard on Full-Time Duty.

9 Reference http://www.eweek.com/c/a/Security/Researcher- Finds-Google-Android-Data-Stealing-Vulnerability- 571999/ http://www.eweek.com/c/a/Security/Researcher- Finds-Google-Android-Data-Stealing-Vulnerability- 571999/ http://www.csc.ncsu.edu/faculty/jiang/nexuss.html http://thomascannon.net/blog/2010/11/android-data- stealing-vulnerability/ http://thomascannon.net/blog/2010/11/android-data- stealing-vulnerability/ http://news.cnet.com/8301-27080_3-20029630- 245.html?part=rss&tag=feed&subj=News-Security http://news.cnet.com/8301-27080_3-20029630- 245.html?part=rss&tag=feed&subj=News-Security http://news.cnet.com/8301-1009_3-20029885- 83.html?part=rss&tag=feed&subj=News-Security http://news.cnet.com/8301-1009_3-20029885- 83.html?part=rss&tag=feed&subj=News-Security http://www.technewsworld.com/story/71737.html


Download ppt "Researcher Finds Google Android Data Stealing Vulnerability 報告者:劉旭哲."

Similar presentations


Ads by Google