StageFright and Android...FYI (NOT FIXED)

Thai

Elite Member
Link: https://blog.exodusintel.com/2015/08/13/stagefright-mission-accomplished/

"We notified Google of the issue on August 7th but have not had a reply to our query regarding their release of an updated fix. Due to this, as well as the following facts, we have decided to notify the public of our findings here on the Exodus Intelligence blog.

"1. We notified Google of the issue on August 7th but have not had a reply to our query regarding their release of an updated fix. Due to this, as well as the following facts, we have decided to notify the public of our findings here on the Exodus Intelligence blog.

2. The flaw was initially reported over 120 days ago to Google, which exceeds even their own 90-day disclosure deadline.

3. The patch is 4 lines of code and was (presumably) reviewed by Google engineers prior to shipping. The public at large believes the current patch protects them when it in fact does not.

4. The flaw affects an estimated 950 million Google customers.

5. Despite our notification (and their confirmation), Google is still currently distributing the faulty patch to Android devices via OTA updates.

6. There has been an inordinate amount of attention drawn to the bug–we believe we are likely not the only ones to have noticed it is flawed. Others may have malicious intentions.

7. Google has not given us any indication of a timeline for correcting the faulty patch, despite our queries.

8. The Stagefright Detector application released by Zimperium (the company behind the initial discovery) reports “Congratulations! Your device is not affected by vulnerabilities in Stagefright!” when in fact it is, leading to a false sense of security among users.

The (un)surprising outcome being that given all the exposure this vulnerability received combined with essentially infinite resources on the vendor side, effective security mitigations were still not deployed. Google employs a tremendously large security staff, so much so that many members dedicate time to audit other vendor’s software and hold them accountable to provide a code fix within a deadline period. If Google cannot demonstrate the ability to successfully remedy a disclosed vulnerability affecting their own customers then what hope do the rest of us have?"
 
Last edited:
Register to hide this ad
A few notes to all Android users (>95%; basically all current Android users):

- The media has largely focused on the MMS attack method, but even MP4 videos embedded in web pages or apps could compromise your phone or tablet.

- Typical Android text messaging apps automatically retrieve incoming MMS messages. This means you could be compromised just by someone sending you a message over the telephone network. With your phone compromised, a worm using this vulnerability could read your contacts and send malicious MMS messages to your contacts, spreading like wildfire like the Melissa virus did back in 1999 using Outlook and email contacts.

- This vulnerability is in the “mediaserver” component and a malicious MP4 file embedded on a web page could exploit it — yes, just by navigating to a web page in your web browser. An MP4 file embedded in an app that wants to exploit your device could do the same.

- Android antivirus apps won’t save you from Stagefright attacks.

- Google also cannot update the Google Play Services component in Android to fix this bug, a patchwork solution Google often employs when security holes show up.

- To really prevent yourself from being compromised, you need to prevent your messaging app of choice from downloading and launching MMS messages. In general, this means disabling the “MMS auto-retrieval” setting in its settings.

- If the MMS is from someone you don’t know, definitely ignore it. If the MMS is from a friend, it would be possible their phone has been compromised if a worm does begin to take off. It’s safest to never download MMS messages if your phone is vulnerable.
 
Last edited:
Okay, so I won't even try and tell you if I understand what you just wrote. Not that you weren't clear but rather my lack of computer and just plain new tech gadgets is poor, if not down right embarrassing!

I for one think I am okay because I have an iPhone and iPad, that I do most all my playtime and communications with.

I think it's awesome what you are doing to inform everyone about this problem, people that might be in trouble but, just haven't realized it yet. [MENTION=2]Thai[/MENTION], thank you for spending the time to actually sit down and figure this out, and to stay on top of it.

Thank You,
 
Okay, so I won't even try and tell you if I understand what you just wrote. Not that you weren't clear but rather my lack of computer and just plain new tech gadgets is poor, if not down right embarrassing!

I for one think I am okay because I have an iPhone and iPad, that I do most all my playtime and communications with.

I think it's awesome what you are doing to inform everyone about this problem, people that might be in trouble but, just haven't realized it yet. [MENTION=2]Thai[/MENTION], thank you for spending the time to actually sit down and figure this out, and to stay on top of it.

Thank You,

No problem. The issue is that Android users may have a false sense of security with the latest patch to "fix" this vulnerability. Just be careful with your data.
 
No problem. The issue is that Android users may have a false sense of security with the latest patch to "fix" this vulnerability. Just be careful with your data.

So is this specific to the newest patch? Because most OEM are behind on Android versions usually.
 
StageFright...version 2.0: New Stagefright attack targets Android phones with phony audio files | The Verge

Zimperium security a new way to exploit Stagefright that isn't covered by existing patches, first reported by Motherboard. The new vulnerability works by encoding a malicious program into an audio file, delivered over mp3 or mp4. Once a user previews the file or visits a page where that file is embedded, Android's audio preview will activate the program, infecting the device. Even more troubling, the virus an also be deployed by an attacker on a public Wi-Fi network, potentially enabling a self-replicating or wormed version of Stagefright. Because some version of the preview function exists in most versions of Android, nearly every Android device is susceptible to the bug
 
So the "pure" Android OS Nexus devices run is better than the ones tweaked by manufacturers--with maybe the exception of LG who has been in bed with google for years making their Nexus phones...

Actually, Samsung made the first Nexus phone I believe. The scores are based on how often a device gets updated through its life and also what software it comes with when you first buy it. Note that Nexus score is far from perfect...Google rolls out update to their Nexus devices over a course of 2-3 weeks...and end of support for Nexus is 18 months.
 
Here it comes...AGAIN

Link: Stagefright-based 'Metaphor' exploit can take control of your phone in just 15 seconds - Android Authority

Actual study: https://www.exploit-db.com/docs/39527.pdf

The old Android malware beastie is at it again, with researchers uncovering a new Stagefright-based exploit that can be used to take control of your Samsung, LG or HTC phone in just 15 seconds. The working exploit has been dubbed “Metaphor” by the Israeli research team that discovered it.

When executed, Metaphor allows malware to be injected into a device that can access, copy and even delete data on the infected device. What’s worse is Metaphor can also be used to take control of the microphone and camera so hackers can spy on the owner and even track their location by turning on GPS.

The research team have successfully run it on the Nexus 5, Galaxy S5, LG G3 and HTC One on Android versions 2.2 to 4.0, as well as on Android 5.0 and Android 5.1.
 

Members online

Forum statistics

Threads
278,309
Messages
3,554,070
Members
248,016
Latest member
Advally Service

Trending content

Back
Top