US EUROPE AFRICA ASIA 中文
World / US and Canada

New ways found to attack Android phones

(Agencies) Updated: 2012-07-26 17:06

LAS VEGAS - Hacking experts on Wednesday demonstrated ways to attack Android smartphones using methods they said work on virtually all such devices in use today, despite recent efforts by search engine giant Google to boost protection.

Experts showed off their prowess at the Black Hat hacking conference in Las Vegas, where some 6,500 corporate and government security technology workers gathered to learn about emerging threats to their networks.

"Google is making progress, but the authors of malicious software are moving forward," said Sean Schulte of Trustwave's SpiderLabs.

Google spokeswoman Gina Scigliano declined to comment on the security concerns or the new research.

Accuvant researcher Charlie Miller demonstrated a method for delivering malicious code to Android phones using a new Android feature known as near field communications.

"I can take over your phone," Miller said.

Near field communications allow users to share photos with friends, make payments or exchange other data by bringing Android phones within a few centimeters of similarly equipped devices such as another phone or a payment terminal.

Miller said he figured out how to create a device the size of a postage stamp that could be stuck in an inconspicuous place such as near a cash register at a restaurant. When an Android user walks by, the phone would get infected, said Miller.

He spent five years as a global network exploit analyst at the US National Security Agency, where his tasks included breaking into foreign computer systems.

"Wild west"

Miller and another hacking expert, Georg Wicherski of CrowdStrike, have also infected an Android phone with a piece of malicious code that Wicherski unveiled in February.

That piece of software exploits a security flaw in the Android browser that was publicly disclosed by Google's Chrome browser development team, according to Wicherski.

Google has fixed the flaw in Chrome, which is frequently updated, so that most users are now protected, he said.

But Wicherski said Android users are still vulnerable because carriers and device manufacturers have not pushed those fixes or patches out to users.

Marc Maiffret, chief technology officer of the security firm BeyondTrust, said: "Google has added some great security features, but nobody has them."

Experts say iPhones and iPads don't face the same problem because Apple has been able to get carriers to push out security updates fairly quickly after they are released.

Two Trustwave researchers told attendees about a technique they discovered for evading Google's "Bouncer" technology for identifying malicious programs in its Google Play Store.

They created a text-message blocking application that uses a legitimate programming tool known as java script bridge. Java script bridge lets developers remotely add new features to a program without using the normal Android update process.

Companies including Facebook and LinkedIn use java script bridge for legitimate purposes, according to Trustwave, but it could also be exploited maliciously.

To prove their point, they loaded malicious code onto one of their phones and remotely gained control of the browser. Once they did that, they could force it to download more code and grant them total control.

"Hopefully Google can solve the problem quickly," said Nicholas Percoco, senior vice president of Trustwave's SpiderLabs. "For now, Android is the Wild West."

Trudeau visits Sina Weibo
May gets little gasp as EU extends deadline for sufficient progress in Brexit talks
Ethiopian FM urges strengthened Ethiopia-China ties
Yemen's ex-president Saleh, relatives killed by Houthis
Most Popular
Hot Topics

...
主站蜘蛛池模板: 欧美成人在线视频| caoporm视频| 欧美freesex黑人又粗又大| 女人与禽牲交少妇| 亚洲无圣光一区二区| 精品国产三级a∨在线观看| 国产在线无码视频一区| jizzjizz之xxxx18| 把水管开水放b里是什么感觉| 亚洲黄色中文字幕| 精品福利一区二区三区 | 久久精品人人槡人妻人人玩AV| 精品免费AV一区二区三区| 国产午夜三级一区二区三| av色综合网站| 成人亚洲欧美激情在线电影| 亚洲免费人成在线视频观看| 污污视频网站免费观看| 免费在线你懂的| 综合图区亚洲欧美另类小说| 国产精品久久久久久久久久免费 | 8av国产精品爽爽ⅴa在线观看| 日本19禁啪啪无遮挡免费| 乱人伦人妻中文字幕| 欧美八十老太另类| 凹凸国产熟女精品视频| 老司机午夜在线视频| 国产主播精品福利19禁vip| 8av国产精品爽爽ⅴa在线观看 | 亚洲伊人久久大香线蕉结合| 好猛好紧好硬使劲好大男男| 中文乱码字幕午夜无线观看| 揉美女胸的黄网站| 久久99精品久久只有精品| 欧美性猛交XXXX乱大交3| 亚洲熟妇AV乱码在线观看| 波多野结衣大战三个黑鬼| 亚洲视频免费在线看| 特级aaa毛片| 人妻少妇被猛烈进入中文字幕| 男女拍拍拍免费视频网站|