How does Android reproduce major vulnerabilities?

Source: Internet
Author: User

How does Android reproduce major vulnerabilities?

A report from VICE confirms that Zimperium zLabs investigator Joshua Drake found the Stagefright 2.0 vulnerability in the Android operating system. This vulnerability contains two bugs that can be embedded with malicious code from attackers through MP3 audio and MP4 videos. Stagefright 2.0 can affect 1.4 billion Android users. Fortunately, no hackers have used it to launch attacks.

This is not the first vulnerability in Stagefright.

Stagefright is not a vulnerability, but a core framework of the Android operating system. It is mainly used to process, play, and record multimedia files. Because the Stagefright framework can process any media files received by the operating system, it also provides various methods for hackers to intrude into users' mobile phones.

In July this year, Joshua Drake discovered the first version of the vulnerability in the Stagefright framework. However, the working principle of this vulnerability is different from that of Stagefright 2.0. We have also reported that:

What makes it amazing is that hackers only need to know your mobile phone number and send a MMS Message to intrude into your mobile phone, and execute code remotely to read and control the content on your mobile phone, you don't even need to open this MMS.

However, in August 15, the Stagefright 1.0 vulnerability was submitted to Google and fixed shortly after it was discovered.

In addition to multimedia files, hackers can also use another channel of Stagefright 2.0 to intrude into others' mobile phones: When hackers and the target are in the same WiFi network (such as public WiFi in a coffee shop ), malicious Code can be implanted into the victim's mobile phone through an unencrypted network, eliminating the need to induce a user to open a specific multimedia file, or being able to launch an attack completely concealed.

What should mobile phone manufacturers do?

Based on security considerations, Zimperium has not published more technical details about the Stagefright 2.0 vulnerability, but has reported it to Google. A Google spokesman said they will push updates to Nexus mobile phone users on March 13, October 5 to block vulnerabilities. The released Nexus 5X and Nexus 6 P phones are pre-installed with the Stagefright 2.0 patch.

Weibo user Zackbuks released a message this morning, saying Sony has pushed the 23.4.a.1.20.version firmware. After the upgrade, the firmware has been detected by Stagefright Detector, which can effectively avoid being affected by the vulnerability.

Some Moto X users said they had received the OTA patch update with the version 222.27.5 as early as the end of September.

How to avoid attacks?

As we know, hackers can launch attacks through public WiFi, MP3/MP4 multimedia files, and webpages with unknown paths. Therefore, before installing patches, Android users should note:

  1. Do not click webpages with unknown origins. These web pages may contain multimedia files implanted with malicious code. Therefore, you must check the web page source when browsing the website.
  2. Avoid using public WiFi. When your mobile phone is connected to public WiFi, hackers will always be able to intrude into your mobile phone. Therefore, it is wise to cut off the channel for malicious code transmission.
  3. Update the system in time. If the operating system is not updated, even the best security patches will not provide protection for your mobile phone.

Although the Stagefright 2.0 vulnerability has turned 1.4 billion users into potential victims, many mobile phone manufacturers seem to have known the vulnerability and started to provide solutions. Therefore, you only need to pay more attention to it during daily use, this vulnerability does not evolve into a major security crisis.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.