Jump to content


Photo

Samsung phones pwned by....well.. pretty much ANY APP!

Security Samsung Kernel flaw Exynos

  • Please log in to reply
2 replies to this topic

#1 eyecre8

eyecre8

    Mod/News Team Leader

  • Moderator
  • 108 posts
  • Google+:eyecre8
  • LocationOhio/Florida
  • Current Device(s):2 Razr's (xt912) & Asus TF700T

Posted 03 January 2013 - 09:07 AM

Please Login or Register to see this Hidden Content

 

Please Login or Register to see this Hidden Content

  34.64KB   33 downloads


A member of an XDA developers forum who goes by the handle 'Alephzain' claims to have found a flaw in several Samsung handsets and tablets that
could allow attackers to enjoy full access to the device's RAM.

The original post found here:

Please Login or Register to see this Hidden Content

states:

Please Login or Register to see this Hidden Content


Exynos-mem's file system permissions are wide-open. It can be read from and written to by ANY software running on the handheld, acting as a portal to the device's physical memory and allowing malicious code to do pretty much anything it wants.

Alephzain says the following about the bug:

Please Login or Register to see this Hidden Content


Another member of XDA forum, Chainfire, has thoughtfully provided an exploit for the flaw and warned:

Please Login or Register to see this Hidden Content


Devices in trouble are said to include:
  • Galaxy SIII
  • Galaxy Note
  • Galaxy Note 2
  • Galaxy 10.1 tablets.
Via:

Please Login or Register to see this Hidden Content


Chainfire's exploit code:

Please Login or Register to see this Hidden Content


My name is Eyecre8 and I approve this message!
Posted Image

#2 SPJESTER

SPJESTER

    Like A Boss

  • Members
  • PipPip
  • 169 posts
  • Twitter:mhowell34
  • Google+:mhowell34
  • LocationStarkvegas, Mississippi
  • Current Device(s):Galaxy S4 Active

Posted 03 January 2013 - 11:27 PM

samsung should umm. Fix this? haha

>> I'VE BEEN AROUND A WHILE. LETS GET TO IT <<
Current Device: AT&T Samsung Galaxy S4 Active 

Retired Devices: Moto Droid, VZW HTC Thunderbolt, VZW Moto Droid Bionic


#3 wulf

wulf

    Themer

  • Superuser
  • 929 posts
  • Twitter:@Wulf_X1
  • LocationMidwest

Posted 04 January 2013 - 03:36 AM

There is an app by chainfire that can grant you root and patch the security hole to protect the phone from malicious apps. If you dont want root you can still use it to apply the fix only.

Reportedly samsung is aware of the issue. Another workaround is apply a custom kernel that addresses this but you have to unlock bootloader first.

Sent from my SCH-I605 using Tapatalk 2






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users