BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Create custom audits for Android devices. Come on, all the cool kids are doing it.

Posted July 18, 2012    Carter Jones

Have you ever wanted to root your Android device, so you could be like all the other cool kids on the block? If you did your research, you learned that it makes it easier for attackers to keep their malware on your device, if it were to be infected, through the use of a rootkit. Therefore, in the interest of security, you made the choice not to root your device. Well, that’s a good first step, but it won’t protect you from all rootkits.

Researchers have managed to find and exploit a vulnerability in the Launcher component of the Android framework. This varies from the normal type of rootkit that would typically exploit a component of the core operating system. In a demonstration video of their work, the researchers show how a UI redressing attack can be performed by hijacking the Android Launcher. A UI redressing attack (aka: clickjacking attack) is a way for attackers to get you to click on something that looks legitimate in nature, but is actually tricking you into performing some other action of the attacker’s choosing. In the case of this rootkit, the clickjacking technique can be used to hide malicious apps from the user, so that the user has no idea something nefarious is on their device.

It needs to be made clear that 1) this does not involve any rooting of the device, 2) no privilege escalation is taking place, 3) no modifications to userland or the kernel are made, and 4) no processes other than the Launcher are controlled. This makes it very different from certain types of malware that rely on a phone being rooted in order to take over the mobile device.

There’s your security, but now we’ll put it in context.

This is a technique that researchers have discovered. It was not reported as something observed in the wild. The researchers are “working on ways to protect against attacks like these” (we hope this means that they will be working directly with the Android framework developer team). Details of the how the researchers managed to hijack the Launcher are non-existent at this point in time, so malware authors have very little to work with.

To help you stay secure, we’ve built the ability to create custom audits for Android devices into Retina. Once further information becomes available about this Android vulnerability, you’ll be able to audit your Android devices, so you can defend against this vulnerability, helping to maintain a strong security posture for you and your organization.

Tags:
, , , , , , ,

Leave a Reply

Additional articles

VMware Hardening Guidelines-img3

How to Audit VMware ESX and ESXi Servers Against the VMware Hardening Guidelines with Retina CS

Posted February 27, 2015    BeyondTrust Research Team

Retina CS Enterprise Vulnerability Management has included advanced VMware auditing capabilities for some time, including virtual machine discovery and scanning through a cloud connection, plus the ability to scan ESX and ESXi hosts using SSH. However, in response to recent security concerns associated with SSH, VMware has disabled SSH by default in its more recent…

Tags:
, , , ,
dave-shackleford-headshot

Privileged Passwords: The Bane of Security Professionals Everywhere

Posted February 19, 2015    Dave Shackleford

Passwords have been with us since ancient times. Known as “watchwords”, ancient Roman military guards would pass a wooden tablet with a daily secret word engraved from one shift to the next, with each guard position marking the tablet to indicate it had been received. The military has been using passwords, counter-passwords, and even sound…

Tags:
, , ,
Privileged Account Management Process

In Vulnerability Management, Process is King

Posted February 18, 2015    Morey Haber

You have a vulnerability scanner, but where’s your process? Most organizations are rightly concerned about possible vulnerabilities in their systems, applications, networked devices, and other digital assets and infrastructure components. Identifying vulnerabilities is indeed important, and most security professionals have some kind of scanning solution in place. But what is most essential to understand is…

Tags:
, , , , ,