NFC (Near-Field Communication Technology) provides convenience while hiding great dangers. Do you realize this?
The main role of NFC technology at present. Currently, mobile phone manufacturers, including Samsung, Sony, Nokia, and rim, have launched smart phones that support NFC, and NFC has reached the verge of explosion. Users can use NFC to quickly transfer files, perform geographical check-in, perform predefined actions, and perform mobile payment. In today's fast society, NFC provides convenient functions to greatly facilitate our lives.
However, it is often shot out of the head. Hackers have long been eager to use NFC to intrude into smartphones. According to arstechnica, at the black hat Technology Conference held on Wednesday, Charlie Miller, Chief Consultant of accuvant, a security consulting firm, conducted six months of painstaking research, finally, I discovered how to use NFC technology and the corresponding vulnerabilities on the smart phone to complete the intrusion attacks on the smart phone.
Android is the first option. Miller uses a custom NFC tag, and after the Android phone connects to the tag, it will send a malicious message like a mobile phoneCode. This malicious code allows the mobile phone to open malicious files or malicious webpages, allowing hackers to fully control the mobile phone.
Miller explained that most Android mobile phones currently have some NFC vulnerabilities. In the android 4.0 system, Google also adds an android beam function to mobile phones with NFC features. Using the NFC vulnerability and the android beam function, you can automatically download files or open webpage links when you are in touch with or close to NFC tags.
With this vulnerability, hackers can use special NFC tags to open a mobile browser and access malicious web pages without any operation or permission from users. Miller said that this attack did not intrude into the NFC protocol stack, but attacked the web browser in the mobile phone and asked the web browser to do everything he wanted to do. Imagine that your mobile phone is completely exposed to the other end of the network when you are unknown. This is quite scary.
Currently, many vulnerabilities are available in Android 2.3. In Android 4.0 and Android 4.1, Google has fixed some vulnerabilities. However, NFC attacks can still be carried out using unrepaired vulnerabilities.
In addition to Android, Nokia rarely appeared in hacking targets. This time it was shot by NFC. Previously, Nokia launched the NFC feature. Miller said using NFC technology to attack Vivo is simpler than Android. Let's look back at the introduction of Edison last year. It mentioned that the first time that Edison connected to a bluetooth device via NFC, there was no need for manual equipment. This was the most dangerous thing.
By default, the NFC function of the queue is disabled. However, once enabled, the hacker can use NFC to accept malicious files without any prompts. Moreover, Vivo supports the function of establishing connections between NFC and Bluetooth, which is more easily exploited by hackers. Hackers can connect to the hacker through the computer's bluetooth, and then use other possible vulnerabilities to force the hacker to perform certain operations. Unauthorized Bluetooth connections can be denied only when you change the settings.
Fortunately, NFC-based attacks are not widely used. Miller has also reported problems to Google and Nokia. Basically, this type of problem can be solved through system upgrade. In addition, developing a good software usage habit is also a good way to prevent hacker attacks.