The Register® — Biting the hand that feeds IT

Feeds

Android adware capability a vulnerability, claim boffins

  • alert
  • print
  • comment
  • tweet

Ad push code can spoof SMSs

Free whitepaper – Operationalizing Information Security

North Carolina State University researchers have revealed a vulnerability in Android that allows SMS messages to be sent from one app to another without going over the air, something they say could be used for SMS phishing attacks.

The Xuxian Jiang-led team is the same group that gave the world the Android click-jacking rootkit, a phone-call bugging vulnerability, and identified a dozen malicious apps on Google Play in 2011.

The team's latest announcement is characterised as a “WRITE_SMS capability leak”, because it can be exploited without an attacker having to request any permissions. The vulnerability is demonstrated in the video below.

“This vulnerability allows a running app on an Android phone to fake arbitrary SMS text messages, which will then be received by phone users. We believe such a vulnerability can be readily exploited to launch various phishing attacks,” the group writes.

Symantec points out that the ability to use an app to generate what looks like an SMS has been known since 2010, but hadn’t been considered a vulnerability. It seems to be a classic case of “this is a feature, not a bug”: the vast majority of apps using the code, the A-V company says, “use the code to deliver advertisements”.

Symantec says there are currently 200 apps on Google Play, recording millions of combined downloads, that send ads to users as spoofed SMSs. ®

Free whitepaper – A private Cloud-based approach

Spotlight

Body which issues CISSP tin stars set for shakeup?
Analysis How DID the super-weapon flee Iran's nuke plant?
image via SXC
Write Once, Exploit Everywhere
Analysis First hacktivist-style assault to use malware?
Analysis 90,000 people work on the dark side of the Net
apple logo
Open... and Shut Everything's fine, can't hear you from the top of my cash mountain
Megaphone
Analysis 'Supernodes' are not for spooks, they're to make service better for YOU