HomeSecurityADB Exploit Leaves Thousands of Android Devices Exposed

ADB Exploit Leaves Thousands of Android Devices Exposed

AndroidA new network worm has appeared on Android devices, which exploits the feature – a feature that is enabled by default by phone manufacturers.

The worm was revealed in a blog postby security researcher Kevin Beaumont, who wrote that ADB is completely unprotected and thousands of Android devices connected to the internet are currently exposed due to this vulnerability.

How does the exploit work?

Hardware manufacturers release their products with Android Debug Bridge enabled by default, and the service connects via TCP port 5555, through which someone can connect to a device over the Internet.

“However, to be enabled – theoretically – someone would need to physically connect, with a device that uses USB and first enable the Debug Bridge”, says Kevin.

Given that ADB is a troubleshooting utility, it allows the user to access several sensitive tools, including a Unix shell. Exploiting this feature, a cryptocurrency miner worm named ADB.Miner worm spread to various devices in February. The worm can find new devices to infect, using port 5555.

The risks at stake

According to Kevin, there are thousands of Android devices that remain exposed. Anyone who connects to a device running ADB can execute commands remotely.

“This is particularly concerning, as it allows anyone – without a password – to gain root access remotely to these devices and then install hidden software and execute malicious actions.

ADB.Miner is still active

The ADB.Miner worm that first appeared in February from Qihoo 360 Netlab remains active and scanning activity on port 5555 has not stopped yet. Millions of scans were recorded just in the last month.

The solution

Kevin advises Android device owners to immediately disable the ADB interface. “This problem has nothing to do with the Android Debug Bridge itself”, Kevin said. “ADB was not designed to be exploited in this way”.

Add also that sellers should not have products with Debug Bridge enabled over the network, as this leads to the creation of a Root Bridge – a situation where anyone can exploit the devices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS