Phone manufacturers leaving Android open to attack

By Stewart Mitchell on Dec 2, 2011 11:52 AM
Filed under Security

Android implementation errors could let hackers record phone calls or access user data.

Security researchers have uncovered a flaw in the way Android is implemented on many handsets, making it possible for attackers to to record phone calls, send SMS messages and access user data.

The computer scientists from North Carolina State University tested handsets from several manufacturers, including Samsung, HTC and Motorola and were “surprised to find out these stock phone images do not properly enforce the permission-based security model”, they reported in a paper.

In the absence of an apps vetting process, Android phones rely on a permission-based security model that requires each application to explicitly request permissions before it can be installed.

According to the researchers, they used "interprocedural data flow analysis" techniques to expose possible capability leaks where an untrusted app could gain unauthorised access to sensitive data or privileged actions.

Using a tool dubbed Woodpecker, the researchers found that of the 13 permissions run through the process, 11 of them could be exploited, with one individual phone leaking up to eight permissions.

“These leaked capabilities can be exploited to wipe out the user data, send out SMS messages to premium numbers, record user conversation, or obtain the user’s geo-location data on the affected phones – all without asking for any permission,” the researchers said.

This article originally appeared at pcpro.co.uk

 
Follow us on Facebook and Twitter
 

Copyright © PC Pro, Dennis Publishing

Phone manufacturers leaving Android open to attack
 
 
 
 
 
Top Stories
Major network outage at Anittel
Business customers disconnected most of yesterday.
 
Huawei knocks local revenue out of the park
Still bathing in poor light security-wise.
 
Sophos focus on channel education
Karen Delaney is the new channel director.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  33%
 
No
  52%
 
The same
  15%
TOTAL VOTES: 392

Vote now
CRN Magazine

Issue: 315 | May 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.