Skip to main content

Almost 1 billion Android phones at risk, can be hacked by text



Cyber security firm Zimperium has warned of a flaw in the world's most popular smartphone operating system that lets hackers take control with a text message.
"Attackers only need your mobile number, using which they can remotely execute code via a specially crafted media file delivered via MMS (text message)," Zimperium Mobile Security said in a blog post.

"A fully weaponized successful attack could even delete the message before you see it. You will only see the notification."
Android code dubbed "Stagefright" was at the heart of the problem, according to Zimperium.
Stagefright automatically pre-loads video snippets attached to text messages to spare recipients from the annoyance of waiting to view clips.
Hackers can hide malicious code in video files and it will be unleashed even if the smartphone user never opens it or reads the message, according to research by Zimperium's Joshua Drake.
"The targets for this kind of attack can be anyone," the cybersecurity firm said, referring to Stagefright as the worst Android flaw discovered to date.
"These vulnerabilities are extremely dangerous because they do not require that the victim take any action to be exploited."
Malicious code executed by hackers could take control of smartphones and plunder contents without owners knowing.
Stagefright imperils some 95 percent, or an estimated 950 million, of Android phones, according to the security firm.
Zimperium said that it reported the problem to Google and provided the California Internet firm with patches to prevent breaches.
"Google acted promptly and applied the patches to internal code branches within 48 hours, but unfortunately that's only the beginning of what will be a very lengthy process of update deployment," Zimperium said.
It did not appear as though hackers had taken advantage of the Stagefright vulnerability, according to Zimperium.
Updating Android software powering mobile devices is controlled by hardware makers and sometimes telecommunication service carriers, not Google.
While Apple controls the hardware and software in iPhones, iPads, and iPods powered by its mobile operating system, Google makes Android available free to device makers who customize the code and update it as they see fit.
More about Drake's research was to be disclosed at a Black Hat computer security conference taking place in Las Vegas early in August.

Comments

Popular Posts

Police find eight-year-old girl living with monkeys

An eight-year-old girl who cannot speak and behave like normal humans has been rescued by the police in India, The Times of India reported. Police personnel in Bahraich, Uttar Pradesh rescued the girl from the monkeys after one of them, a sub-inspector, who was on patrol near the Katarniaghat Wildlife Sanctuary spotted her with the monkeys. According to the report, when he tried to rescue the girl, the monkeys and the girl screeched. They, however, got her away eventually and took her to a hospital where she was placed on admission. The report said the girl gets scared at the sight of humans and is often violent. Also, she walks like animals, using her hands and legs together and eats directly from her mouth. The girl can neither speak nor understands any language, and gets scared at the sight of human beings. The doctors treating her said that she often gets violent. They, however, said she was showing improvements. --punchng.com

SHORT STORY: The Snake Prince: The Glitter Of Death

Once upon a time, there lived a king who had a daughter called Aminat. She was the most beautiful girl in town. Aminat was asked for her hand in marriage by so many young men, but she refused. Her expectation was for a ready-made handsome young man with riches.

Happy New Year From The Church Of Scientology

Today, The Church Of Scientology International, Los Angeles, shared their warmest New Year's greetings on their twitter handle. They wrote: "Happy New Year! The Church of Scientology wishes you and yours an incredible and rewarding 2018!"..