HomeSecurityHack all Samsung phones with MiTM!

Hack all Samsung phones with MiTM!

Samsung smartphones can be hacked, infected with malicious software, and controlled remotely, via malicious Wi‑Fi hotspots in cafés and hotels, researchers say.

According to NowSecure, millions of the company's devices have a vulnerability that allows remote code execution. The vulnerability naturally stems from a flaw in the software design.Samsung

The solution to avoid it is to use a VPN or simply switch devices.

Essentially, the researchers at NowSecure claim that the touch keyboard app of Samsung Galaxy S6, S5, S4 and S4 Mini updates automatically by downloading a ZIP file from the Internet using an unencrypted HTTP connection.

It does not verify the authenticity of the file, and thus someone who controls your network could intercept the download and send a malicious file to the phone instead of the legitimate one.

The update process runs with system-level access. The extraction of the ZIP file is done without any checks of the files it contains, and with full read and write permissions on the device's file system.

This means that a malicious file could arbitrarily replace device files, replacing the installed software with malicious.

The zip file is downloaded from:

https://skslm.swiftkey.net/samsung/downloads/v1.3-USA/az_AZ.zip

… And if, for example, it contains a file named payload in the path

../../../../../../../../data/payload

when decompressed by the update process, it will create a system file that belongs to the /data directory:

$ su -c "ls -l /data/payload" -rw------- system system 5 2014-08-22 16:07 payload

Something that is not very clever.

The keyboard app cannot be removed, cannot be disabled or replaced by another. It will continue to run and the update process will continue in the background with full system privileges.

“It is unfortunate, for OEMs as well as providers to use pre‑installed third‑party applications on a device,” says researcher Ryan Welton of NowSecure on their blog. “In some cases, these applications run with elevated privileges. This is the case with Samsung's keyboard.”

“This vulnerability applies to Samsung devices, and we have observed it as early as Android 4.2, possibly even on earlier versions, a NowSecure representative said.”.

NowSecure published the proof of concept (PoC) of the vulnerability, and there is currently no patch to fix it.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS