Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
well, as it turns out, you're hosed, along with hundreds of millions of other people

http://blog.zimperium.com/experts-found-a-unicorn-in-the-heart-of-android/


quote:

Zimperium zLabs VP of Platform Research and Exploitation, Joshua J. Drake (@jduck), dived into the deepest corners of Android code and discovered what we believe to be the worst Android vulnerabilities discovered to date. These issues in Stagefright code critically expose 95% of Android devices, an estimated 950 million devices. Drake’s research, to be presented at Black Hat USA on August 5 and DEF CON 23 on August 7 found multiple remote code execution vulnerabilities that can be exploited using various methods, the worst of which requires no user-interaction.

Attackers only need your mobile number, using which they can remotely execute code via a specially crafted media file delivered via MMS. A fully weaponized successful attack could even delete the message before you see it. You will only see the notification. These vulnerabilities are extremely dangerous because they do not require that the victim take any action to be exploited. Unlike spear-phishing, where the victim needs to open a PDF file or a link sent by the attacker, this vulnerability can be triggered while you sleep. Before you wake up, the attacker will remove any signs of the device being compromised and you will continue your day as usual – with a trojaned phone.

you might be asking, "how do i protect myself? " short answer: you don't for now.

quote:

...fixes for these issues require an OTA firmware update for all affected devices. Such updates for Android devices have traditionally taken a long time to reach users. Devices older than 18 months are unlikely to receive an update at all. We hope that members of the Android ecosystem will recognize the severity of these issues and take immediate action. In addition to fixing these individual issues, we hope they will also fix any business processes that prevent or slow the uptake of such fixes.

Adbot
ADBOT LOVES YOU

Big Bowie Bonanza
Dec 30, 2007

please tell me where i can date this cute boy
YES

ItBurns
Jul 24, 2007
lmao if you think my phone can actually receive mms

Modulo16
Feb 12, 2014

"Authorities say the phony Pope can be recognized by his high-top sneakers and incredibly foul mouth."

Who will stop those pesky hacker from getting my pictures of cats and things I eat at restaurants now ?!

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Frank Viola posted:

Who will stop those pesky hacker from getting my pictures of cats and things I eat at restaurants now ?!

they can do way more than that, friend

Big Bowie Bonanza
Dec 30, 2007

please tell me where i can date this cute boy
you could probably enable a verizon user's integrated messaging with this and send a shitload of texts to premium numbers a+ security exploit would exploit again1

Tristesse
Feb 23, 2006

Chasing the dream.
poo poo, someone in the Ukraine will know how much pizza I order

Noblesse Obliged
Apr 7, 2012

These hackers must spend a lot of time looking up people's noses.

Stoic Commie
Aug 29, 2005

by XyloJW
i have the iphone

Stoic Commie
Aug 29, 2005

by XyloJW
does this mean i can see the titty pics? how do i hack?

Nigmaetcetera
Nov 17, 2004

borkborkborkmorkmorkmork-gabbalooins
i knew i should have stuck with a flip phone

criscodisco
Feb 18, 2004

do it
When I had an Android phone, there was an option to only show you the number of the person trying to send you an mms, before you opted to download it. Can't people just do that?

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

criscodisco posted:

When I had an Android phone, there was an option to only show you the number of the person trying to send you an mms, before you opted to download it. Can't people just do that?

don't think so

Diet Sodium
Apr 29, 2009
Lol if your not using a Nokia 3310

Adbot
ADBOT LOVES YOU

Blazing Ownager
Jun 2, 2007

by FactsAreUseless
The best part is because companies stop pushing Android fixes this will never go away

  • Locked thread