Mercredi, 18 Mai 2011 01:37
User Login Vulnerability Found In 99% of Android Handsets
Research from multiple universities is now warning that almost all smartphones that are running Google’s Android software could be allowing third parties access to digital tokens that could allow access to services such as Google Calendar and Contacts. The issue seems to affect all devices running versions of Android prior to 2.3.3 and is related to handling of the authentication protocol ClientLogin. According to researchers at the German University of Ulm, once a user enters their credentials, the programming interface retrieves its token in clear text. The token is valid for 14 days and a window appears where attackers could use their new found access however they like. The whole process seems to be relatively easy to exploit according to the researchers. “We wanted to know if it is really possible to launch an impersonation attack against Google services and started our own analysis,” “The short answer is: Yes, it is possible, and it is quite easy to do so.” The results come after a professor at Rice University demonstrated a similar flaw affecting Facebook, Twitter, and once again Google Calendar. This time though, the hack could only be carried out on an unsecured Wi-Fi network. Google has patched that specific hole in Android 2.3.4 but failed to plug the whole when it comes to Picasa, which allows web albums to potentially transmit sensitive data in the clear. As of right now, Google claims to be working on a fix. Android’s fragmentaton issues cause potential security holes to be further exacerbated. The fragmentation causes phones to remain on older software long after patches have been released. With carriers and device manufacturers insisting on meddling with Google’s operating system, updates can take several months to get past their own software engineers, this results in a massive 99% o Android devices still being wide open to being hacked. Google recently mentioned that it will work more closely with carriers to try and reduce the time it takes for updates to be rolled out fully. As usual, stay tuned for more tech news and info by following us on Facebook, Twitter, and/or subscribing to our RSS feed. Read More Authors:
Read 3475 times
Published in
News Technologique-Tech News
More in this category:
« Sony’s “Welcome Back” Package Announced For PSN Users
Widgets For The iOS In Development »
Last WebBuzz
-
WebBuzz du 04/12/2015: Animation stroboscopique de Scultures: Blooms-Blooms Strobe-Animated Sculptures
Read 15018 times
-
WebBuzz du 03/12/2015: Le challenge mobil 1: 240cm avec Jenson button-Mobil 1 challenge 240 cm with Jenson button
Read 14644 times
-
WebBuzz du 02/12/2015: Carpes et poissons chat à Tchernobyl-Chernobyl catfishes and carps
Read 15762 times
-
WebBuzz du 01/12/2015: La porte des étoiles par le groupe playmid-The Playmid's star gate
Read 16732 times
-
WebBuzz du 30/11/2015: Vie sauvage en artique filmé par drone-Wild life in artic recorded by a drone
Read 15186 times
-
WebBuzz du 27/11/2015: Les migrants de Calais: la réalité-The truth about Calais emigrants
Read 12992 times
-
WebBuzz du 26/11/2015: Un batteur vole la veddette-Best drummer ever
Read 9292 times
-
WebBuzz du 25/11/2015: Une cheminée s'écroule sur une pelleteuse-A chimney collapsed on a excavator
Read 14645 times
-
WebBuzz du 24/11/2015: Un cargo perd son ancre-A freighter loose its anchor
Read 10325 times
-
WebBuzz du 23/11/2015: Destruction du super star destroyer en LEGO-Giant Star Wars LEGO Super Star Destroyer Shattered
Read 9078 times
Accusé de reception
bancaires
bilan
cheval
configuration
Confirmation de lecture
copie
copies
Dolibarr
duplicata
EDF
Excel
exim
facture
factures
Firefox
Google cloud print
hameçonnage
IE6
IE7
impression
informatique
itunes
java
linux
luxembourgeois
mac os
MAJ
micosoft
microsoft
Office
Outlook
phishing
quicktime
rappels
relances
seamonkey
serveurs
spécifique
Sécurité
Tentative
thunderbird
troie
utilisant
V322
Vista
Windows
Windows 7
XP/2000 : Activer le pavé numérique
établissements








