HomeSecurityAirDroid app: the flaw that gave hackers complete control

AirDroid app: the flaw that gave hackers complete control

AirDroid

AirDroid, a popular management tool for Android, has fixed a serious authentication flaw in its web interface that could give a hacker complete control of a mobile phone.

The issue was fixed in an update released last month, according to Matt Bryant, a consultant at security firm Bishop Fox, who discovered the flaw. Versions 3.0.4 and earlier of the tool are affected.

AirDroid allows users to manage their phone from a Windows or Mac tablet or through a web interface. To do this, it requires a lot of permissions, such as the ability to send text messages, activate the camera, and more.

Bishop Fox found that it could compromise a device running AirDroid by simply sending the user a malicious link via SMS, Bryant wrote.

Vulnerable versions of AirDroid use JavaScript Object Notation with padding, or JSONP, to request data from a server on a different domain. Web browsers typically prohibit this as a security precaution, known as the same-origin policy.

“Because JSONP is an insecure data exchange method, it is possible to overshadow the full functionality of the AirDroid app,” Bryant wrote. “In this way, other users’ Android devices can be hijacked.”

A successful attack means a hacker would have full control over an Android device and would be able to view the phone's contacts, track the device using GPS, and transfer photos.

Bryant said Bishop Fox has reviewed the AirDroid patch "and found it more than adequate.".

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS