• Home
  • Reviews
  • Featured
  • Archives
  • Videos
  • Devices
  • Tegra
  • Send Tips
  • Contact
  • AndroidCommunity on Twitter AndroidCommunity on Facebook AndroidCommunity on Google+ AndroidCommunity RSS Feed

Android Community

    • MUST READ

      STORIES

    • Skip the Google Edition, just give us the stock option

      May 21, 2013

    • Will Android ever compete with Xbox?

      May 21, 2013

    • Samsung Galaxy S III carrier availability set to expand in June

      May 21, 2013

  • Trending Topics
  • Jelly Bean
  • NVIDIA
  • Galaxy S 4
  • HTC One
  • Nexus 7
  • Sell Your Used Phone

Android exploit opens SD card to data theft [Video]

0
  • By Chris Davies
  • on 24 Nov, 2010

Android exploit opens SD card to data theft [Video]

An Android security flaw has been identified which, if exploited, could allow unauthorized access to data saved on a user’s memory card and, in some cases, on the device’s own storage. Spotted by Thomas Cannon, there are certain limitations to the exploit – hackers must know the name of the files they wish to steal, not terribly difficult if you’re dealing with system-named files like photos – but already the Android security team are cooking up a fix.

  • The Android browser doesn’t prompt the user when downloading a file, for example “payload.html”, it automatically downloads to /sdcard/download/payload.html
  • It is possible, using JavaScript, to get this payload to automatically open, causing the browser to render the local file.
  • When opening an HTML file within this local context, the Android browser will run JavaScript without prompting the user.
  • While in this local context, the JavaScript is able to read the contents of files (and other data).

The flaw has been independently verified by Heise.de, and Google says it will be rolling a fix into Android 2.3 Gingerbread. That could be released as soon as December 6 2010. Until then, be wary of unexpected downloads or HTML code in emails from users you don’t know.

[vimeo]http://vimeo.com/17030639[/vimeo] [via rigelt]
Share
  • Student wins science fair with 30-second phone battery charger
  • Hisense Sero 7 Pro with Tegra 3, Android 4.2 takes on Google's Nexus 7
  • Verizon HTC One reality returns as DROID DNA offer pops up

Tags: securityvideos

  • Search

  • REVIEWS

    • AT&T LG Optimus G Pro ReviewAT&T LG Optimus G Pro Review
    • Iron Man 3 game Review: what you need to knowIron Man 3 game Review: what you need to know
    • Samsung GALAXY S 4 ReviewSamsung GALAXY S 4 Review
    • Samsung Galaxy Note 8.0 ReviewSamsung Galaxy Note 8.0 Review
    • Pebble review: Two weeks with a smartwatchPebble review: Two weeks with a smartwatch
  • HANDS-ON & QUICK LOOKS

    • Opera for Android exits beta, we go hands onOpera for Android exits beta, we go hands on
    • NVIDIA Tegra 4i demos i500 LTE modem on Cat 4: 150Mbps of speedNVIDIA Tegra 4i demos i500 LTE modem on Cat 4: 150Mbps of speed
    • HP Slatebook x2 Tablet hands-onHP Slatebook x2 Tablet hands-on


  • T-Mobile G1 Accessories
  • RECENT COMMENTS

  • About
  • Contact
  • Terms of Use
  • Privacy Policy
  • Advertise

Copyright 2013 Android Community