HomeSecurityZimperium releases an active exploit for Stagefright

Zimperium releases active exploit for Stagefright

Zimperium releases its active Stagefright exploit code, which demonstrates that the Stagefright vulnerability can allow Remote Code Execution without user interaction.

Zimperium releases active exploit for Stagefright
Zimperium said it is releasing the code so that administrators and penetration testers can validate the effectiveness of the Android community response, and that it has already postponed the release of the exploit twice at the behest of carriers and device manufacturers. Its focus now, it said, is “to wake up the ecosystem and force them to realize that updates need to be distributed more promptly.”
Specifically, Stagefright allows a hacker to gain complete control over an Android device simply by sending a specific type of file to the recipient, who doesn’t have to open it to open the door for attackers.
Hackers can send an MMS to gain access to phones, or devices can be infected using malicious video files that play automatically when a web page is opened. Once the video has played, attackers can bypass Chrome’s video auto-play disablement and gain complete control of the device. Malicious applications or MP4 files can also be crafted to exploit the vulnerability. Once downloaded and opened, attackers can take action.
“Google has released new versions of Hangouts and Messenger to prevent the automatic processing of multimedia files arriving via MMS,” the company said in a blog post. “We have reviewed these updates and are pleased to confirm that unassisted remote exploitation is prevented. However, this attack vector was only the worst of more than 10 different ways of potentially malicious media being processed by the Stagefright library. With these other vectors still present, the importance of fixing the codebase issues remains very high.”
During June and July, Zimperium zLabs’ VP of Research and Exploitation Platform, Joshua Drake, developed a live exploit to demonstrate that the Stagefright vulnerability can allow Remote Code Execution (RCE) without user interaction. It uses a Python script that creates an MP4 exploit exploiting one of the most critical vulnerabilities reported in the Stagefright library. The expected result of the exploit is a reverse shell as the media user. As detailed in Joshua Drake's Black Hat presentations and DEF CON presentations, this user also has access to other groups such as inet, audio, camera, and MediaDrm. These groups allow an attacker to take pictures or listen to the microphone remotely, without exploiting additional vulnerabilities.
The industry response is likely to be passionate. It should be noted that the code is not a generic exploit. Zimperium tested it to see if it worked only on a Galaxy Nexus device running Android 4.0.4 and containing only a partial implementation of ASLR.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS