|
Interesting attack vector
|
|
01-21-2011, 05:54 AM
Post: #1
|
|||
|
|||
| Interesting attack vector | |||
|
01-21-2011, 01:20 PM
Post: #2
|
|||
|
|||
|
RE: Interesting attack vector
Thanks for the link Skooter! That surreptitious inter-App communication is a fancy trick indeed
![]() Frankly, its pretty obvious that having a sound recording app running while entering credit card details is a BAD idea. Even if you were entering into a website using the onscreen keyboard its possible (as shown by some recently released App that I've totally forgotten the name of that maps sounds that you make by tapping the phone case to actions you want) to map the case sounds of pressing each key, so this isn't just a problem when phonecalls are made. Google Nexus One @ froyo [2.2.1]| Huawei IDEOS u8150 @ froyo [2.2]| HTC Wildfire @ eclair [2.1-update1] | emulator @ whatever Android releases: - WeatherCell.net Australia BETA - SnowCell.net Australia Ski Slopes |
|||
|
01-22-2011, 02:31 AM
Post: #3
|
|||
|
|||
RE: Interesting attack vector
(01-21-2011 01:20 PM)coder Wrote: Thanks for the link Skooter! That surreptitious inter-App communication is a fancy trick indeed Agreed. But I think the point is that you don't have the recording app running when entering credit card details; the attacker could use the recording app as an excuse for the required permissions then have the attack fire up in the background whenever it registers a vocal input/touch input. |
|||
|
01-25-2011, 11:47 AM
Post: #4
|
|||
|
|||
|
RE: Interesting attack vector
"The collector monitors the phone state and makes a
short recording of the calls it deems interesting based on a profile database." So FauxRecordingApp is running all the time anyway, hence capable of mapping the sound of touching the case of phone when using the browser, for example...which was my point, this is not just limited to phonecalls. Another thing is the 2nd App needs to be installed (User needs to be duped into installing it, and unless it is a "must have" addition to the FauxRecordingApp, that is going to be a tricky task). Google Nexus One @ froyo [2.2.1]| Huawei IDEOS u8150 @ froyo [2.2]| HTC Wildfire @ eclair [2.1-update1] | emulator @ whatever Android releases: - WeatherCell.net Australia BETA - SnowCell.net Australia Ski Slopes |
|||
|
01-25-2011, 08:58 PM
Post: #5
|
|||
|
|||
|
RE: Interesting attack vector
Yep this is true.
The FauxRecordingApp could be a real recording app, but with a Service running in the background to listen for phonecalls/button beeps. Thankfully, its not a flaweless attack vector, but a pretty open one. |
|||
|
« Next Oldest | Next Newest »
|

Search
Member List
Calendar
Help




![[-]](images/collapse.gif)
