Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Android Bug Would Have Allowed Phone Infections From A Computer Click

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
Judi Lynn Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-07-11 03:29 PM
Original message
Android Bug Would Have Allowed Phone Infections From A Computer Click
Source: Forbes

Android Bug Would Have Allowed Phone Infections From A Computer Click
Mar. 7 2011 - 1:05 pm

It’s no surprise that the line between phone security and computer security is blurring. But few Android users would have guessed that for most of the last month, a single click on their PC could have infected their phone with whatever program a cybercriminal chose.

Late last month, Google patched a so-called “cross-site scripting” flaw in its Android Web Market that would have allowed a malicious hacker to trick users into installing malware on their phones with just a spoofed link on the Web or in their email, according to security researcher Jon Oberheide. By wrapping code into a carefully-crafted link to the Market sent to a user or planted on a website, an exploit based on that bug could have hijacked the Market’s ability to silently install programs to a user’s phone via a Web interface, so long as he or she is logged into a Google account.

In a blog post, Oberheide applauds Google for fixing the bug in late February, as well as paying him a $1,337 fee for reporting the bug as part of the company’s bug bounty program. But he notes that “since the Android web market was launched earlier this year, it was possible to remotely install arbitrary applications with arbitrary permissions onto a victim’s phone simply by tricking them into clicking a malicious link (either on their desktop OR phone). The exploit universally across all Android devices, versions, and architectures.”

Oberheide also points out that despite the fix, Google still allows installations of Android apps from the Web interface without warnings on the phone. That’s a dangerous privilege, given how easily the login credentials to a user’s Google account can be stolen.

Read more: http://blogs.forbes.com/andygreenberg/2011/03/07/android-bug-would-have-allowed-phone-infections-from-a-computer-click/
Printer Friendly | Permalink |  | Top
musiclawyer Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-07-11 03:35 PM
Response to Original message
1. There is already a thread on GD
Not as bad a flamewar there as I expected.
Printer Friendly | Permalink |  | Top
 
Electric Monk Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-07-11 05:03 PM
Response to Original message
2. They paid him a leet fee for reporting the bug? lol
Printer Friendly | Permalink |  | Top
 
Tunkamerica Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Mar-07-11 11:50 PM
Response to Reply #2
3. It's been the standard payout for a while. I read it on their blog several months ago.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 24th 2024, 08:34 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC