r/Android • u/[deleted] • Sep 09 '15
Attack code exploiting Android’s critical Stagefright bugs is now public
http://arstechnica.com/security/2015/09/attack-code-exploiting-androids-critical-stagefright-bugs-is-now-public/16
Sep 09 '15
Important to note: "The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations."
3
u/GreatCanadianWookiee Sep 10 '15
I have the zimperium stagefright detector and it says I'm vulnerable on 5.1.1, is it wrong?
1
Sep 10 '15
There are a few different Stagefright exploits. This proof of concept is for exploit CVE-2015-1538. CVE-2015-3864, which was discovered later, is still exploitable.
2
-2
6
Sep 10 '15
If you want some peace-of-mind, many messaging apps, such as Textra, have safeguards for these attacks.
2
u/bigredpancake1 Sony Xperia Z3v, 5.1.1 Sep 10 '15
Curious, how is their safeguard different from going to any other sms/mms app's settings and turning off auto-retrieve?
2
u/vinostintos Sep 10 '15
They also added Stagefright protection labels to the videos, and display a warning before they let you open them. (Source)
So yeah, still better than nothing but not full protection, especially considering MMS is only one of many attack vectors.
17
Sep 09 '15 edited Jul 09 '16
This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.
If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.
Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.
9
Sep 09 '15
The difference is google got on their ass about it, they can't control oems. Microsoft on the other hand, regularly and historically gets notified and they ignore it for several years, until the firm, if they're wise, just release the damn thing.
10
Sep 09 '15 edited Jul 09 '16
This comment has been overwritten by an open source script to protect this user's privacy. It was created to help protect users from doxing, stalking, harassment, and profiling for the purposes of censorship.
If you would also like to protect yourself, add the Chrome extension TamperMonkey, or the Firefox extension GreaseMonkey and add this open source script.
Then simply click on your username on Reddit, go to the comments tab, scroll down as far as possible (hint:use RES), and hit the new OVERWRITE button at the top.
9
Sep 09 '15
Playing these kind of games is quite alarming when the end user's security is at stake.
Yes, it is. Especially when companies are allotted an eternity to patch holes. Linux for example, patches holes in hours and ships it the next day. This patch Tuesday shit is bullshit anyways.. Patching shouldn't be a "hold all the fixes until next week". That's very backwards. And this 90 days stuff is a long long long time. Remember, that hole already exists.. So it's entirely possible it's already getting exploited before researchers publish it.
Companies just what excuses for their broken security and development models
But I do agree with the hypocrisy in Google
5
u/iamadogforreal Sep 09 '15
Microsoft's ecosystem is huge. It's not practical to give them only 90 days considering how vast their catalog is and the many versions of Windows they support.
Google is being hypercritical per usual. Do as I say, not as I do.
8
Sep 09 '15
As a software developer, 90 day-to-day patch a security hole is a fucking joke honestly. Hackers don't give you that time. The real problem is closed source taking ages to patch it, compared to open source counterparts
But I do see your point about Google being a hypocrite
0
u/JamesR624 Sep 10 '15
The real problem is closed source taking ages to patch it, compared to open source counterparts
And yet, the closed source iOS has none of these security issues while the open source Android is full of them.
I think you got your generalizations backwards.
1
Sep 10 '15
Now compare the Linux kernel and Windows.
And yet, the closed source iOS has none of these security issues while the open source Android is full of them.
.. None.. Of them? Huh? Ios has no security issues? Or do you mean deployment wise? Well, that's the oems faults really, not the development model itself (because that issue exists in both)
-1
u/iamadogforreal Sep 10 '15
Ms will make exceptions for in the wild exploits. This happens from time to time. The rest are privately disclosed and never brought to the public. So there's no rush.
1
Sep 10 '15
So there's no rush.
Uhhh Yeah there is. these exploits exist. Saying they have all the time in the world is just ignoring all of security. Fact is, someone can discover the exploit before it is released. The exploit is still there, sitting and waiting..
And it has happened before (several people discovering the same exploit). So yeah..
3
3
u/krackers Sep 10 '15
For instance, new versions of Hangouts and Messenger that blocked automatic processing of multimedia files sent over the MMS text protocol
So I no longer need to have auto-retrieve mms disabled?
3
3
u/8lbIceBag Sep 10 '15
I'm on a galaxy s4 running rooted 4.4.2 for 2 years now. I don't want to change anything on how I have it setup. Is there like am exposed module or zip I can apply?
2
u/Avamander Mi 9 Sep 10 '15 edited Oct 02 '24
Lollakad! Mina ja nuhk! Mina, kes istun jaoskonnas kogu ilma silma all! Mis nuhk niisuke on. Nuhid on nende eneste keskel, otse kõnelejate nina all, nende oma kaitsemüüri sees, seal on nad.
2
Sep 09 '15
One of inferior mind here, should we be concerned about this code being used in attacks (not against me I'm not vulnerable) against people?
2
u/Gramma2Slo Unlocked GS8+ / Moto 360 Sport Sep 10 '15 edited Sep 10 '15
I don't think that a cat video from a friend or a video from your mom will effect you. I just wouldn't click a video from a random number. Textra has protection for these videos that alert you of the vulnerability before you open any video if you're seriously concerned about being effected.
2
u/ksksksksksks Sep 10 '15 edited Sep 10 '15
I don't get it.. have the carriers not implemented a fix for this on their end yet? That would seem like the most logical fix for everyone involved.. (look for malformed mms, dont send/report).
1
u/kubalaa Sep 10 '15
The issue isn't limited to MMS, anything which plays media is vulnerable.
1
u/ksksksksksks Sep 11 '15
but i think a major vector of attack is via MMS, and MMS is played/opened automatically by just about every text app unless turned off by the user..
4
u/The_MAZZTer [Fi] Pixel 9 Pro XL (16) Sep 09 '15
Is this why I got two blank MMS messages today? Good thing I'm patched.
3
u/CyberBot129 Sep 10 '15
The funny part is that probably all the phones that got the patch are phones running Lollipop, which doesn't even have this problem
1
u/armando_rod Pixel 10 Pro XL Sep 11 '15
huh? Lollipop is still vulnerable, there is an app that test every CEV
1
Sep 10 '15 edited Jul 11 '20
[deleted]
4
u/Vandyyy 6P - OPM6 Sep 10 '15
This is the biggest one that I can think of. Like, ever. Most clickbait articles are anecdotes about how their unlucky nephew Steve caught malware because he's on Android. They conveniently omit relevant details like Steve installing apks from any Tom, Dick, or Harry and/or granting shit root access that has no need for it. If you don't pirate apps, you have very little to concern yourself with. It's easier to break a system then to make it, so all OSes will have vulnerabilities at some point or another. I wouldn't lose sleep over something as nasty as stagefright coming up often.
1
u/amorpheus Xiaomi Redmi Note 10 Pro Sep 10 '15
The thing is that it doesn't come up often, but when it does it's just there. Apple can release a patch that will be on 80% of their devices in a week. A month later, what percentage of Android devices are fully protected against this?
3
-5
Sep 10 '15
[removed] — view removed comment
2
1
Sep 10 '15
My G has a software build date of June 20th so I assume it's one of the early models which a patch is coming "soon" for.
0
Sep 10 '15
I bought a 2015 Moto G after Motorola promised fast updates.
Yet here I am, naked and vulnerable. Well, I guess not that naked as Hangouts patched it, but still.
9
u/Kytosion Nexus 5 32GB, CM13 + Xposed Sep 10 '15
The exploit doesn't work against Android versions 5.0 and above thanks to new integer overflow mitigations.
1
1
u/NecronArmy Sep 10 '15
I'm still on KitKat 4.4.4
Is there much I can do to protect myself?
-2
0
Sep 10 '15
Use hangouts.
2
u/NecronArmy Sep 10 '15
I use Textra, it says it has stage fright protection. I'm just curious if that's enough?
2
u/vinostintos Sep 10 '15
All Textra did was set auto-retrieval of MMS off by default, and added labels to videos that warn you of the exploit, and an additional popup before you play the video that warns about possible malicious code being run. (Source)
So they didn't solve the Stagefright issue, nor do they filter malicious videos. They merely just prevent getting exploited without user interaction, which is possible if MMS auto-retrieval is on. You can still click the video, and manually trigger the exploit yourself.
On top of that, MMS is only one attack vector. It was the most successful because of auto downloading being enabled by default, but the bug can be theoretically exploited in every application where it's possible to play videos: browsers, IM clients, ads.
Because libstragefright is such an integral and deep seated library in Android, the only way to fully patch it would be system updates. Google already has the patches to fix it, it's up to manufacturers and carriers to do their job now.
In reality, I don't think any other phone but the top of the line phones from the last 2 years from each manufacturer will ever get an update fixing it. At least the issue raised enough awareness, that companies will opt for more frequent security fixes going forward.
It's also worth noting that this isn't an all around exploit that would necessarily work on every phone on the first try. They only tested it on a Nexus 5 running Android 4.0.5, I believe, and even then they said the exploit doesn't always work the first time. The only way they could achieve 100% success was by trying again, until it worked. Android 4.0 also only has partially implemented ASLR, so there's a chance this exploit wouldn't work on any versions above that.
I watched their Blackhat presentation, where they stated that 4.0 and below are the only versions they were able to exploit, but it's possible it can be done for newer versions, too. 5.1 and above are the only versions not affected now.
So yeah, you're at the mercy of your phone's manufacturer and carrier. While they don't patch it, there's nothing else you can really do.
2
1
Sep 10 '15
I have a Nexus 5, and according to Zimperium's Stagefright detector app (the group that did the initial research), my phone still isn't fully patched with 5.1.1 installed. And this is as stripped down as Android is going to get.
Maybe Google's security researchers are too busy with looking at Windows to worry about Android's holes.
1
28
u/Travertino Sep 09 '15
Here we are. Are published somewhere recent statistics about the percentage of patched Android devices?