|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


  Home | Information Security News
   
 

Systematic Detection of Capability Leaks in Stock Android Smartphones

 

It has been observed that there is an increase in the adoption of smartphones. Android provides a permission based security model which requires each application to request permissions before it can be installed to run in order to manage information and features on smartphones. An analysis consisting of eight Android Smartphones was conducted and researchers have discovered that the stock phone images do not properly enforce the permission model. A number of privileged permissions are exposed to other applications that do not require request for using them. Researchers have developed a tool known as Woodpecker to identify these leaked permissions or capabilities. The results have demonstrated that an untrusted application can exploit these leaked permissions to wipe out user data, send SMS messages or record user conversion on the vulnerable smartphones without user permission.

Read more: http://www.csc.ncsu.edu/faculty/jiang/pubs/NDSS12_WOODPECKER.pdf

Source:

Team Cymru

http://www.team-cymru.org/News/

North Carolina State University

http://www.csc.ncsu.edu/faculty/jiang/pubs/NDSS12_WOODPECKER.pdf

 

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

 

 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +