查看: 1708|回复: 5
收起左侧

Galaxy S3 、 Note 2 漏洞来了!

 关闭 [复制链接]
firefox3
发表于 2012-12-18 11:37:50 | 显示全部楼层 |阅读模式
本帖最后由 firefox3 于 2012-12-18 11:41 编辑

Galaxy S3, Galaxy Note 2, other Android handsets featuring certain Samsung Exynos chipsin danger, as new exploit is found

来源:http://www.androidauthority.com/ ... ploit-found-140561/



We kept talking about Android malware these days, with various reports from security firms coming out to suggest that even more Android devices will be affected by malicious apps next year.

In addition to these reports, we have a new exploit discovery to show you, via xda-developers, that could prove to be harmful for various 2012 flagship Samsung products including the Galaxy S3 and Galaxy Note 2, but other devices that pack Exynos chips also.

xda user alephazin has discovered a vulnerability in Exynos processors version 4210 and 4412 that essentially allows any Android app to access and control the whole device:

Hi,

Recently discover a way to obtain root on S3 without ODIN flashing.
The security hole is in kernel, exactly with the device /dev/exynos-mem.

This device is R/W by all users and give access to all physical memory … what’s wrong with Samsung ? […]

The good news is we can easily obtain root on these devices and the bad is there is no control over it.

Ram dump, kernel code injection and others could be possible via app installation from Play Store. It certainly exists many ways to do that but Samsung give an easy way to exploit. This security hole is dangerous and expose phone to malicious apps. Exploitation with native C and JNI could be easily feasible.

Moreover, user Chainfire has already managed to come up with a one-click root method based on this exploit – called Exynos Abuse. And Samsung has been notified about the whole issue.

The company is yet to offer an explanation for this potentially harmful exploit, so meanwhile we’ll just list some of the devices that could be affected, at least in theory, by malicious apps that would target this exploit:

Samsung Galaxy S2 GT-I9100
Samsung Galaxy S3 GT-I9300
Samsung Galaxy S3 LTE GT-I9305
Samsung Galaxy Note GT-N7000
Samsung Galaxy Note 2 GT-N7100
Verizon Galaxy Note 2 SCH-I605 (with locked bootloaders)
Samsung Galaxy Note 10.1 GT-N8000
Samsung Galaxy Note 10.1 GT-N8010.
We’ll be back with more news once we have it.
zhhqlj
发表于 2012-12-18 12:11:29 | 显示全部楼层
貌似360、金山说已经被他们解决了。
firefox3
 楼主| 发表于 2012-12-18 12:17:56 | 显示全部楼层
zhhqlj 发表于 2012-12-18 12:11
貌似360、金山说已经被他们解决了。

我用的LBE,亲
思梦潮
头像被屏蔽
发表于 2012-12-18 12:59:25 | 显示全部楼层
手机实际上挺安全的,最不安全的就是被偷了
不过文章说的是内核漏洞,楼上说已被修复,这怎么修复,金山360也会做内核?XDA上找找有没有金山360发布的内核去
oceanroar
发表于 2012-12-18 13:32:38 | 显示全部楼层
这相当于制造了一个巨大的后门/漏洞,如果落到坏人手里,基本上可以想干嘛干嘛了。

太恐怖了。。。智能电子设备太不安全了。。。
L、stone
发表于 2012-12-18 15:28:51 | 显示全部楼层
oceanroar 发表于 2012-12-18 13:32
这相当于制造了一个巨大的后门/漏洞,如果落到坏人手里,基本上可以想干嘛干嘛了。

太恐怖了。。。智能电 ...

大饼真是太危险咯
吃不好就把自己噎死了
大饼太恐怖可 食物也不安全
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-9 01:52 , Processed in 0.117490 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表