Android Spying

Open discussion about any topic, as long as you abide by the rules of course!
Post Reply
vileliquid1026
Posts: 1178
Joined: Thu May 03, 2007 4:48 pm

Android Spying

Post by vileliquid1026 »

Has anyone heard about a new Android spyware called 'Stage Freight'? I figured if anyone knew it was you folks.
[i]Be sure your sin will find you out...[/i]
User avatar
Eraser
Posts: 19175
Joined: Fri Dec 01, 2000 8:00 am

Re: Android Spying

Post by Eraser »

fuck'n lol :olo:
Ryoki
Posts: 13460
Joined: Wed Aug 01, 2001 7:00 am

Re: Android Spying

Post by Ryoki »

Never heard of it, but 1 minute of googling tells me it works by receiving a MMS.

Don't think i've ever received one of those seeing as they were practically outdated by the time they were invented, so yeah, not too worried.
[size=85][color=#0080BF]io chiamo pinguini![/color][/size]
User avatar
Eraser
Posts: 19175
Joined: Fri Dec 01, 2000 8:00 am

Re: Android Spying

Post by Eraser »

Ok, lol, I'll spill.

It's actually called "Stagefright" and it's not spyware but the name of an Android library that is used to (among other things) draw previews of media items in the notification area. There is a bug in this library that allows an attacker to send harmful content disguised as an image to a victim. One way of delivering such a payload is through MMS, but that's not the only way (I believe WhatsApp is susceptible to such attacks as well). Once deployed, the payload can, without user interaction, grant the attacker access to certain parts of Android that normally would be off limits.

The bug has been fixed some time ago in Android, but the real problem is that very few handset manufacturers roll out updates to fix such problems. Therefore it's very well possible that your phone is still vulnerable to such attacks.

You can use the Zimperium Stagefright detector to determine if your phone is vulnerable to attacks. If so, it could be wise to disable MMS and disable automatic media downloads in apps such as WhatsApp, Google Hangouts or other applications that can receive media items from strangers.
Ryoki
Posts: 13460
Joined: Wed Aug 01, 2001 7:00 am

Re: Android Spying

Post by Ryoki »

Cheers man. I appear to be vulnerable! :(

Disabled auto media downloads in whatsapp, don't think i have any other stuff that can auto download things from strangers.
[size=85][color=#0080BF]io chiamo pinguini![/color][/size]
User avatar
Eraser
Posts: 19175
Joined: Fri Dec 01, 2000 8:00 am

Re: Android Spying

Post by Eraser »

Note that Stagefright consists of several issues identified as individual CVE's. These CVE's are displayed by Zimperium's testing tool. CVE-2015-6602 and CVE-2015-3876 were added to the detector at a later stage. Stagefright contained a similar bug for both images and audio files. Initially only the bug for images was identified and patched in Android and only at a later time the audio exploit was fixed. So if the aforementioned CVE's are the only ones in red, then your phone did receive the update to fix the problem with images but not with audio files. There's a good chance your phone will receive a fix for the audio problem as well then.
User avatar
PhoeniX
Posts: 4067
Joined: Fri Aug 04, 2000 7:00 am

Re: Android Spying

Post by PhoeniX »

My phone's vulnerable but I'm really not bothered. I think the chances of actually getting hit by this are pretty slim anyway :shrug:.
User avatar
seremtan
Posts: 36013
Joined: Wed Nov 19, 2003 8:00 am

Re: Android Spying

Post by seremtan »

"chances are pretty anyway"

weeell, maybe pretty so :p
User avatar
PhoeniX
Posts: 4067
Joined: Fri Aug 04, 2000 7:00 am

Re: Android Spying

Post by PhoeniX »

Ninja mod edit completed :p.
Post Reply