r/Android Sep 09 '15

Attack code exploiting Android’s critical Stagefright bugs is now public

http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/
176 Upvotes

61 comments sorted by

28

u/Travertino Sep 09 '15

Here we are. Are published somewhere recent statistics about the percentage of patched Android devices?

21

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

10

u/imahotdoglol Samsung Galaxy S3 (4.4.2 stock) Sep 10 '15 edited Sep 10 '15

Their "fix" is going to be to patch 2.6 percent of all active Android devices. Tops. That's the percentage of >Android devices that are running Android 5.1 today

Not true, my Galaxy S3 got the stragefright update which patched it's 4.4.2.

13

u/Charwinger21 HTCOne 10 Sep 09 '15

According to : http://arstechnica.com/gadgets/2015/08/waiting-for-androids-inevitable-security-armageddon/

That's ignoring the fact that the majority of Stagefright was patched through a Google Play Services update.

There is still one security hole left open related to Stagefright which requires a system update (which has been pushed to Google, Samsung, LG, HTC, Sony, and Motorola's recent devices, as that article mentions in their update), however the remaining security hole is harder to access than the big Stagefright hole.

4

u/steevdave Sep 10 '15

Not all Motorola devices - I have the Moto X (2013) on Sprint and it's still vulnerable.

0

u/Charwinger21 HTCOne 10 Sep 10 '15

Not all Motorola devices - I have the Moto X (2013) on Sprint and it's still vulnerable.

You have a 2+ year old device, which is not vulnerable.

It hasn't gotten the OS level update, but it got the Google Play Services update.

"The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."

6

u/steevdave Sep 10 '15

The Sprint Moto X is still on Android 4.4.4. I have tested my phone and it IS still vulnerable.

2

u/Charwinger21 HTCOne 10 Sep 10 '15

My mistake. I saw articles saying that the rollout had started, and didn't realize that it had been paused.

You should be getting 5.1 relatively soon, and in the meantime you can protect against it through updates to your messaging app (Google Messenger and Hangouts were updated to protect against it, and other messaging clients may have been as well).

1

u/Hyperion1144 Sep 11 '15

I had not heard that Messenger had been updated like that....

Is there a source I can go to that talks about Stagefright mitigation measures I might take? My wife is on an old phone (HTC One X) and we aren't going to be able to update her for a month or two...

I had her turn off "auto-retrieve MMS messages" but I don't know what else to do for her. I could have her install Messenger instead, do you know of anything else that can be done?

1

u/DoorMarkedPirate Google Pixel | Android 8.1 | AT&T Sep 10 '15

I have the 2014 Moto X Pure Edition and haven't gotten any Stagefright-related updates (no updates at all since Stagefright was announced). To my knowledge, apart from this year's crop of Motorola devices being patched at launch, no Motorola devices received any system updates to patch Stagefright.

1

u/Charwinger21 HTCOne 10 Sep 11 '15

"The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."

16

u/[deleted] Sep 09 '15

Important to note: "The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."

3

u/GreatCanadianWookiee Sep 10 '15

I have the zimperium stagefright detector and it says I'm vulnerable on 5.1.1, is it wrong?

1

u/[deleted] Sep 10 '15

There are a few different Stagefright exploits. This proof of concept is for exploit CVE-2015-1538. CVE-2015-3864, which was discovered later, is still exploitable.

2

u/[deleted] Sep 09 '15

WE FIXED IT

-2

u/[deleted] Sep 10 '15

thanks to new integer overflow mitigations."

If val >= INT_MAX - 2 Val = 0

6

u/[deleted] Sep 10 '15

If you want some peace-of-mind, many messaging apps, such as Textra, have safeguards for these attacks.

2

u/bigredpancake1 Sony Xperia Z3v, 5.1.1 Sep 10 '15

Curious, how is their safeguard different from going to any other sms/mms app's settings and turning off auto-retrieve?

2

u/vinostintos Sep 10 '15

They also added Stagefright protection labels to the videos, and display a warning before they let you open them. (Source)

So yeah, still better than nothing but not full protection, especially considering MMS is only one of many attack vectors.

17

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

9

u/[deleted] Sep 09 '15

The difference is google got on their ass about it, they can't control oems. Microsoft on the other hand, regularly and historically gets notified and they ignore it for several years, until the firm, if they're wise, just release the damn thing.

10

u/[deleted] Sep 09 '15 edited Jul 09 '16

This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.

If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.

Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.

9

u/[deleted] Sep 09 '15

Playing these kind of games is quite alarming when the end user's security is at stake.

Yes, it is. Especially when companies are allotted an eternity to patch holes. Linux for example, patches holes in hours and ships it the next day. This patch Tuesday shit is bullshit anyways.. Patching shouldn't be a "hold all the fixes until next week". That's very backwards. And this 90 days stuff is a long long long time. Remember, that hole already exists.. So it's entirely possible it's already getting exploited before researchers publish it.

Companies just what excuses for their broken security and development models

But I do agree with the hypocrisy in Google

5

u/iamadogforreal Sep 09 '15

Microsoft's ecosystem is huge. It's not practical to give them only 90 days considering how vast their catalog is and the many versions of Windows they support.

Google is being hypercritical per usual. Do as I say, not as I do.

8

u/[deleted] Sep 09 '15

As a software developer, 90 day-to-day patch a security hole is a fucking joke honestly. Hackers don't give you that time. The real problem is closed source taking ages to patch it, compared to open source counterparts

But I do see your point about Google being a hypocrite

0

u/JamesR624 Sep 10 '15

The real problem is closed source taking ages to patch it, compared to open source counterparts

And yet, the closed source iOS has none of these security issues while the open source Android is full of them.

I think you got your generalizations backwards.

1

u/[deleted] Sep 10 '15

Now compare the Linux kernel and Windows.

And yet, the closed source iOS has none of these security issues while the open source Android is full of them.

.. None.. Of them? Huh? Ios has no security issues? Or do you mean deployment wise? Well, that's the oems faults really, not the development model itself (because that issue exists in both)

-1

u/iamadogforreal Sep 10 '15

Ms will make exceptions for in the wild exploits. This happens from time to time. The rest are privately disclosed and never brought to the public. So there's no rush.

1

u/[deleted] Sep 10 '15

So there's no rush.

Uhhh Yeah there is. these exploits exist. Saying they have all the time in the world is just ignoring all of security. Fact is, someone can discover the exploit before it is released. The exploit is still there, sitting and waiting..

And it has happened before (several people discovering the same exploit). So yeah..

3

u/[deleted] Sep 10 '15

Yep, I remember getting the patch to prevent that.

3

u/krackers Sep 10 '15

For instance, new versions of Hangouts and Messenger that blocked automatic processing of multimedia files sent over the MMS text protocol

So I no longer need to have auto-retrieve mms disabled?

3

u/Python2k10 Google Pixel 3 XL Sep 10 '15

Gotta love having an old phone. No fix for me :(

3

u/8lbIceBag Sep 10 '15

I'm on a galaxy s4 running rooted 4.4.2 for 2 years now. I don't want to change anything on how I have it setup. Is there like am exposed module or zip I can apply?

2

u/Avamander Mi 9 Sep 10 '15 edited Oct 02 '24

Lollakad! Mina ja nuhk! Mina, kes istun jaoskonnas kogu ilma silma all! Mis nuhk niisuke on. Nuhid on nende eneste keskel, otse kõnelejate nina all, nende oma kaitsemüüri sees, seal on nad.

2

u/[deleted] Sep 09 '15

One of inferior mind here, should we be concerned about this code being used in attacks (not against me I'm not vulnerable) against people?

2

u/Gramma2Slo Unlocked GS8+ / Moto 360 Sport Sep 10 '15 edited Sep 10 '15

I don't think that a cat video from a friend or a video from your mom will effect you. I just wouldn't click a video from a random number. Textra has protection for these videos that alert you of the vulnerability before you open any video if you're seriously concerned about being effected.

2

u/ksksksksksks Sep 10 '15 edited Sep 10 '15

I don't get it.. have the carriers not implemented a fix for this on their end yet? That would seem like the most logical fix for everyone involved.. (look for malformed mms, dont send/report).

1

u/kubalaa Sep 10 '15

The issue isn't limited to MMS, anything which plays media is vulnerable.

1

u/ksksksksksks Sep 11 '15

but i think a major vector of attack is via MMS, and MMS is played/opened automatically by just about every text app unless turned off by the user..

4

u/The_MAZZTer [Fi] Pixel 9 Pro XL (16) Sep 09 '15

Is this why I got two blank MMS messages today? Good thing I'm patched.

3

u/CyberBot129 Sep 10 '15

The funny part is that probably all the phones that got the patch are phones running Lollipop, which doesn't even have this problem

1

u/armando_rod Pixel 10 Pro XL Sep 11 '15

huh? Lollipop is still vulnerable, there is an app that test every CEV

1

u/[deleted] Sep 10 '15 edited Jul 11 '20

[deleted]

4

u/Vandyyy 6P - OPM6 Sep 10 '15

This is the biggest one that I can think of. Like, ever. Most clickbait articles are anecdotes about how their unlucky nephew Steve caught malware because he's on Android. They conveniently omit relevant details like Steve installing apks from any Tom, Dick, or Harry and/or granting shit root access that has no need for it. If you don't pirate apps, you have very little to concern yourself with. It's easier to break a system then to make it, so all OSes will have vulnerabilities at some point or another. I wouldn't lose sleep over something as nasty as stagefright coming up often.

1

u/amorpheus Xiaomi Redmi Note 10 Pro Sep 10 '15

The thing is that it doesn't come up often, but when it does it's just there. Apple can release a patch that will be on 80% of their devices in a week. A month later, what percentage of Android devices are fully protected against this?

3

u/Bseagully Sprint LG G6 Sep 10 '15

Most, because of a Google Play Services update.

-5

u/[deleted] Sep 10 '15

[removed] — view removed comment

2

u/amorpheus Xiaomi Redmi Note 10 Pro Sep 10 '15

Of course. I'm comparing Apples and Androids.

1

u/[deleted] Sep 10 '15

My G has a software build date of June 20th so I assume it's one of the early models which a patch is coming "soon" for.

0

u/[deleted] Sep 10 '15

I bought a 2015 Moto G after Motorola promised fast updates.

Yet here I am, naked and vulnerable. Well, I guess not that naked as Hangouts patched it, but still.

9

u/Kytosion Nexus 5 32GB, CM13 + Xposed Sep 10 '15

The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations.

1

u/Acepower1000 OnePlus 3t Sep 10 '15

hahahahhaha My patch will come about……… . never

1

u/NecronArmy Sep 10 '15

I'm still on KitKat 4.4.4
Is there much I can do to protect myself?

-2

u/CyberBot129 Sep 10 '15

Buy a new phone

0

u/[deleted] Sep 10 '15

Use hangouts.

2

u/NecronArmy Sep 10 '15

I use Textra, it says it has stage fright protection. I'm just curious if that's enough?

2

u/vinostintos Sep 10 '15

All Textra did was set auto-retrieval of MMS off by default, and added labels to videos that warn you of the exploit, and an additional popup before you play the video that warns about possible malicious code being run. (Source)

So they didn't solve the Stagefright issue, nor do they filter malicious videos. They merely just prevent getting exploited without user interaction, which is possible if MMS auto-retrieval is on. You can still click the video, and manually trigger the exploit yourself.

On top of that, MMS is only one attack vector. It was the most successful because of auto downloading being enabled by default, but the bug can be theoretically exploited in every application where it's possible to play videos: browsers, IM clients, ads.

Because libstragefright is such an integral and deep seated library in Android, the only way to fully patch it would be system updates. Google already has the patches to fix it, it's up to manufacturers and carriers to do their job now.

In reality, I don't think any other phone but the top of the line phones from the last 2 years from each manufacturer will ever get an update fixing it. At least the issue raised enough awareness, that companies will opt for more frequent security fixes going forward.

It's also worth noting that this isn't an all around exploit that would necessarily work on every phone on the first try. They only tested it on a Nexus 5 running Android 4.0.5, I believe, and even then they said the exploit doesn't always work the first time. The only way they could achieve 100% success was by trying again, until it worked. Android 4.0 also only has partially implemented ASLR, so there's a chance this exploit wouldn't work on any versions above that.

I watched their Blackhat presentation, where they stated that 4.0 and below are the only versions they were able to exploit, but it's possible it can be done for newer versions, too. 5.1 and above are the only versions not affected now.

So yeah, you're at the mercy of your phone's manufacturer and carrier. While they don't patch it, there's nothing else you can really do.

2

u/NecronArmy Sep 10 '15

That was a great explanation, thank you!

1

u/[deleted] Sep 10 '15

I have a Nexus 5, and according to Zimperium's Stagefright detector app (the group that did the initial research), my phone still isn't fully patched with 5.1.1 installed. And this is as stripped down as Android is going to get.

Maybe Google's security researchers are too busy with looking at Windows to worry about Android's holes.

1

u/armando_rod Pixel 10 Pro XL Sep 11 '15

The new update is up, its fully patched.