Notice: You have been identified as a bot, so no internal UID will be assigned to you. If you are a real person messing with your useragent, you should change it back to something normal.

Minichan

Topic: FAO: Android users [SECURITY BULLETIN]

r04r started this discussion 12 years ago #36,543

If any of you are still using the "Browser" (literally what it's called) instead of the "Chrome" app, or any of the alternative browsers then I strongly urge you to switch, at least until further notice.

A critical security vulnerability has been uncovered which allows any webpage to execute code within the context of another webpage. That means minichan (or some ad network, or any other website that you visit in that browser) could read your email or banking details if you're logged into those websites at the time (the tab doesn't have to be open, just the cookies present).

So yeah, switch.

Source: https://community.rapid7.com/community/metasploit/blog/2014/09/15/major-android-bug-is-a-privacy-disaster-cve-2014-6041

You can test if you are vulnerable by visiting http://ejj.io/SOP.php and clicking the button. If you see an alert message, you are vulnerable and will want to use another browser (at least for the time being).

(Edited 2 minutes later.)

HaikerensGuide !dBGi/iH4eY joined in and replied with this 12 years ago, 8 minutes later[^] [v] #497,561

Seems Android 4.4.x is safe...

(Edited 34 seconds later.)

r04r (OP) replied with this 12 years ago, 2 minutes later, 10 minutes after the original post[^] [v] #497,562

@previous (HaikerensGuide !dBGi/iH4eY)
It appears to be, I missed that at first. The source article mentions "in AOSP browser before Android 4.4". Additionally I've seen comments online that android 2.x devices are not affected, but I still recommend anyone to check for themselves using http://ejj.io/SOP.php

(Edited 18 seconds later.)

Ks !KansasxqvM joined in and replied with this 12 years ago, 38 minutes later, 49 minutes after the original post[^] [v] #497,564

Yikes, thanks for the heads up r04r.

squeegee joined in and replied with this 12 years ago, 30 minutes later, 1 hour after the original post[^] [v] #497,568

i don't appear to be getting an alert message. so i guess i'm cool. thanks for the info r04r

(Edited 23 seconds later.)

r04r (OP) replied with this 12 years ago, 10 minutes later, 1 hour after the original post[^] [v] #497,569

@previous (squeegee)
Out of curiousity, what android version are you running? You can find out in the settings under about. And using "Browser", right?

Anonymous E joined in and replied with this 12 years ago, 55 minutes later, 2 hours after the original post[^] [v] #497,575

> Chrome

Why are you trying to give me a virus?

squeegee replied with this 12 years ago, 10 minutes later, 2 hours after the original post[^] [v] #497,577

@497,569 (r04r)
4.4.2 it says. and yeah, just the default browser.

r04r (OP) replied with this 12 years ago, 1 minute later, 2 hours after the original post[^] [v] #497,578

@previous (squeegee)
Alright, yeah those are confirmed to have (most likely) been fixed.

Syntax joined in and replied with this 12 years ago, 2 hours later, 5 hours after the original post[^] [v] #497,592

@previous (r04r)
Posted by Tod Beardsley in Metasploit on Sep 15, 2014 11:48:04 AM

There has been no acknowledgement of the bug from Google, as far as we can tell. There's no listing of this bug on CVEDetail's readout of Android issues, and no chatter (we could find) in the Android security community about this bug.

Hummmmmm So like Tod missed this?

http://googleonlinesecurity.blogspot.com/2014/04/google-services-updated-to-address.html

Google Services Updated to Address OpenSSL CVE-2014-0160 (the Heartbleed bug)


Posted: Wednesday, April 9, 2014
Posted by Matthew O'Connor, Product Manager

You may have heard of “Heartbleed,” a flaw in OpenSSL that could allow the theft of data normally protected by SSL/TLS encryption. We’ve assessed this vulnerability and applied patches to key Google services such as Search, Gmail, YouTube, Wallet, Play, Drive, Apps, App Engine, AdWords, DoubleClick, Maps, Maps Engine, Earth, Analytics and Tag Manager. Google Chrome and Chrome OS are not affected. We are still working to patch some other Google services. We regularly and proactively look for vulnerabilities like this -- and encourage others to report them -- so that that we can fix software flaws before they are exploited.

If you are a Google Cloud Platform or Google Search Appliance customer, or don’t use the latest version of Android, here is what you need to know:

Cloud SQL
We are currently patching Cloud SQL, with the patch rolling out to all instances today and tomorrow. In the meantime, users should use the IP whitelisting function to ensure that only known hosts can access their instances. Please find instructions here.

Google Compute Engine
Customers need to manually update OpenSSL on each running instance or should replace any existing images with versions including an updated OpenSSL. Once updated, each instance should be rebooted to ensure all running processes are using the updated SSL library. Please find instructions here.

Google Search Appliance (GSA)
Engineers have patched GSA and issued notices to customers. More information is available in the Google Enterprise Support Portal.

Android
All versions of Android are immune to CVE-2014-0160 (with the limited exception of Android 4.1.1; patching information for Android 4.1.1 is being distributed to Android partners).

We will continue working closely with the security research and open source communities, as doing so is one of the best ways we know to keep our users safe.

Apr 12: Updated to add Google AdWords, DoubleClick, Maps, Maps Engine and Earth to the list of Google services that were patched early, but inadvertently left out at the time of original posting.

Apr 14: In light of new research on extracting keys using the Heartbleed bug, we are recommending that Google Compute Engine (GCE) customers create new keys for any affected SSL services. Google Search Appliance (GSA) customers should also consider creating new keys after patching their GSA. Engineers are working on a patch for the GSA, and the Google Enterprise Support Portal will be updated with the patch as soon as it is available.

Also updated to add Google Analytics and Tag Manager to the list of Google services that were patched early, but inadvertently left out at the time of original posting.

Apr 16: Updated to include information about GSA patch.

Apr 28: Updated to add Google Drive, which was patched early but inadvertently left out at the time of original posting.


Now my comment - As IF this is the very first or will be the very last bug exploited by hackers. Its a good thing no hacks have taken place since I left for France or returned nor do I expect any updates for my Virus protections. Good 2 no everyone is using the most up2date O/S and browsers money can buy.

As I lafff at not being shocked

Catherine Grace !7vPs6NSJEY joined in and replied with this 12 years ago, 14 hours later, 20 hours after the original post[^] [v] #497,676

I get "SharkMarks" for Chrome, Dolphin, and UC Browser.
Am I safe?

r04r (OP) replied with this 12 years ago, 2 hours later, 22 hours after the original post[^] [v] #497,751

@previous (Catherine Grace !7vPs6NSJEY)
It's not very hard Catherine, I said it a few times already: Click the button, if you get an alert you need to use another browser. Did you get an alert? Is the "sharkmarks" message part of an alert? If no, you are safe. If yes, you are not. This isn't too complicated, right?

Anonymous H joined in and replied with this 12 years ago, 3 minutes later, 22 hours after the original post[^] [v] #497,759

@previous (r04r)
lolol

Killer Lettuce !!iNo3FkiZx joined in and replied with this 12 years ago, 7 minutes later, 22 hours after the original post[^] [v] #497,767

r04r- I am using Safari on an Apple iPod. Am I safe from this thing???

Anonymous J joined in and replied with this 12 years ago, 55 seconds later, 22 hours after the original post[^] [v] #497,768

@previous (Killer Lettuce !!iNo3FkiZx)
You should probably switch, just to be safe.

r04r (OP) replied with this 12 years ago, 3 seconds later, 22 hours after the original post[^] [v] #497,769

@497,767 (Killer Lettuce !!iNo3FkiZx)
No. It is best to throw it out of the window before it can infect the rest of your devices, and then buy a brand new Android 6.0 integrated brainset.

Syntax replied with this 12 years ago, 15 minutes later, 22 hours after the original post[^] [v] #497,780

@previous (r04r)
2nd post of morning n last post b4 daily beach run.

r04r is anyone safe (long term) when they dare trust a computer?

I do trust my Sun Work stations - The ones that only connect to servers on ISDN lines and never the net. Anything else is destined to be a headache at some point.

A food blender failed yesterday and I keep getting failures of espresso machines. None of them have browsers and yet they fail. If I were to go with schtick, and find a way to insert a browser in2 one of my new espresso machines, I am confident this will...

I am sure there is a good ending to this schtick/spam reply about safety on the internet and will contemplate such as my feet hit the morning sand on this beach.

r04r (OP) replied with this 12 years ago, 4 minutes later, 22 hours after the original post[^] [v] #497,787

@previous (Syntax)
Long term? No. Humans will always make mistakes, including those building the computer systems. At some point in time there'll be less and less unintentional bugs because best practises and programming languages including safety features will protect us from most of that, but bugs will always exist. And that's just unintentional ones, there's plenty of (state) actors that have much to gain from there being exploitable bugs that only they know about.

(Edited 18 seconds later.)

Killer Lettuce !!iNo3FkiZx replied with this 12 years ago, 6 minutes later, 22 hours after the original post[^] [v] #497,792

@497,768 (J)
@497,769 (r04r)
Okay, I have disposed of the offending device and upgraded to an Android phone running all of the latest and safest software. Thanks for the help, I could have been taken down by this thing otherwise!

Syntax replied with this 12 years ago, 5 hours later, 1 day after the original post[^] [v] #497,852

@497,787 (r04r)
The Virus business continues to grow which of course makes for the Anti Virus business. Me thinks long term Crooks R Us remains in business exploiting those who have cash in wallets.

> At some point in time there'll be less and less unintentional bugs because best practises and programming languages including safety features will protect us from most of that,

IF I had the tyme yet do not - Not until I finish my position paper on how Spectrum in USA should b ...which I should not even be ritting about in any open forum. I am being paid by those that oppose vs those that don't and all at the same tyme with each fully able to view the end results. Its a good thing I use paid editors to clean up my dyslexic English.

Last I looked which was just a few weeks ago - Microshit pushed Win 8 and 8.1 updates and crashed a huge number of computers on Planet Earth as they attempted to stop most recent exploitations.

You pointed out Android which up to now has been less exploited and Apple got away with far less messing with until all of a sudden so many smart phones existed that Crooks R Us said lets offer applications that can exploit so no need to mess with root kits etc on O/S.

I might be proven wrong but I have yet to see less people in the Anti-Virus biz and in fact more people diving in2 this biz and currently everyone in such work is looking for quality help.

Locally I have friends who work for a company few no about and they are Virus hunters with world wide offices
Corporate Headquarters and EMEA Operations Office (Bratislava, Slovakia)

North America Headquarters and Operations Office (San Diego, CA., USA)

Latin America Headquarters and Operations Office (Buenos Aires, Argentina)

Asia Headquarters and Operations Office (Singapore)

Odd thing is the company lists a small fraction of jobs they have open. Seems odd but it turns out the competition is doing the same. Every Anti Virus company in biz was at Comic Con looking for young and not necessarily degree~d coders.

So u really think
> best practises and programming languages including safety features will protect us from most of that,

Hope you're correct but Me not so sure its all of a sudden going to be that way very soon.

Triptych !IupsXZPnnU joined in and replied with this 12 years ago, 1 hour later, 1 day after the original post[^] [v] #497,865

Thanks for the heads up!

Anonymous L joined in and replied with this 12 years ago, 1 hour later, 1 day after the original post[^] [v] #497,876

@497,852 (Syntax)
do your satellites run norton?

Anonymous M joined in and replied with this 12 years ago, 1 hour later, 1 day after the original post[^] [v] #497,906

@497,852 (Syntax)
Cool story, bro.

Catherine Grace !TGirlYJKXM replied with this 12 years ago, 1 hour later, 1 day after the original post[^] [v] #497,966

@497,751 (r04r)
I assumed the "sharkmarks" wasn't apart of the alert, but then again, I don't know what the alert looks like.
I just assumed there would have been a large WARNING in bold and red text.

r04r (OP) replied with this 12 years ago, 1 minute later, 1 day after the original post[^] [v] #497,968

@previous (Catherine Grace !TGirlYJKXM)
An alert is a popup message in the browser. And it's *after* the button got pressed. THe text is there *before* the button gets pressed.

Syntax replied with this 12 years ago, 15 minutes later, 1 day after the original post[^] [v] #497,970

@497,876 (L)
The Globalstars are bent pipe repeaters. So YOU could send a phone call into such system and have many a virus piggybacked on such transmission and the Satellite wood simply pass all through the pipe so as someone could spot the virus and clean it up.

So NO need for any Virus protection! Satellites that is!

Anonymous N joined in and replied with this 12 years ago, 5 hours later, 1 day after the original post[^] [v] #498,120

> not using L
> 2014

Anonymous O joined in and replied with this 12 years ago, 2 days later, 4 days after the original post[^] [v] #499,049

> not using chrome on every mobile device


except for iphone because i still use safari on that
:

Please familiarise yourself with the rules and markup syntax before posting.