8 ms·
Hackers can pwn your Android in 10 seconds, if you use Bing App in Starbucks
- xinbenlv 13y agoThat is shocking
- eric_hu 13y agoMSFT sucks big time, and I'm glad someone found out about it.. Many thanks to trustlook.com
- zhongjiewu 13y agoSounds like very dangerous attack and not very difficult to implement. DNS hijacking: 1. Quicker DNS response than router to pollute the Android's DNS 2. Rouge AP that pretend to be common free public wifi like "att", "starbucks", "cablewifi" or "Free Public WiFi" 3. De-authenticate valid AP connections and force user to try rouge WIFI MITM attack: 1. ARP spoofing
- trustlook 13y agoCorrect ;-)
- vezzy-fnord 13y agoThat's a universal network attack though, how is it an exclusive vulnerability to this app?
- zhongjiewu 13y agoYou would never be able to install an app without user click "install" etc. This one uses Javascript Bridge vulnerability to execute high privilege code in your Android. The attack code is javascript to be interpreted to Java calls in Android. You wouldn't be able to do that in iPhone though.
- lstamour 13y agoBit confused as to how this can't happen on iOS "just because," as iOS apps could be targeted in a similar way. Really the message here should be that SSL with certificate-pinning is a must for apps that inherently run in untrusted environments with an inability to easily inspect the security of the network traffic without MITMing it yourself. Wish this was a security feature on the app store -- if, in automated testing or in device logs, an app was entirely secure or insecure with its communication, just as we've padlock icons in browsers today.
- gress 13y agoiOS apps cannot be targeted in this way because they don't have the JavaScript bridge.
- void-star 13y agoNot exactly. iOS 7+ introduced Cocoa<->Javascript bridging capabilities in the public APIs. Before that, similar iOS APIs had existed as "private" ones (so, very uncommonly used outside of apple's own apps). iOS doesn't bridge Javascript to _Java_ which is why this particular attack wouldn't work. But the JS<->Cocoa stuff is still pretty young, so wait and see ;)
- robterrell 13y agoThe JS-Cocoa bridge isn't young at all, it's the same bridge that has been on Mac OS X for years. And it's opt-in -- on the native side you have to specify which classes can be bridged and what methods can be called. It's not the case that any bridged webview exposes all of Cocoa for your JS injection pleasure. You could write an app that specifically exposed some dangerous API, but you'd know you had done so.
- lstamour 13y ago> You could write an app that specifically exposed some dangerous API, but you'd know you had done so. Few people write insecure code on purpose. Of course the same is true of Safari or networking/parsing code. I still maintain certificate pinning is the answer here, to try and defend as much as possible against MITM in the first place.
- iagox86 13y ago"There's a horrible vulnerability in the Bing app! ...but we're not going to give you any details." I hate stories like that.
- trustlook 13y agogoogle "addJavascriptInterface vulnerability"
- stormbrew 13y agoThere's a bing app? (sorry, had to do it)
- click170 13y ago"Warning: infected app! download and install our app to protect yourself!" thank god there is an app to protect... wait a minute... where have I seen these tactics used before...
- zhongjiewu 13y agoI wouldn't comment on their AntiVirus stuff but I think the vulnerability in the Bing App is real.
- joshbaptiste 13y agoHmm.. interesting, well luckily I don't use Bing app, I don't even use Bing on a normal browser. It just sounds wierd to me for some reason .. "Ok Ima Bing that information right now!".
- brokenparser 13y agoI rather quack it :)
- 0x0 13y agoSo it seems the story here is that in older versions of android, if you export a Java class to a webview with "addJavascriptInterface", the js code can get arbitrary code exec by calling exportedObject.getClass().forName("java.lang.Runtime").exec() or similar? And if you can mitm/spoof on public wifis, you can inject js to exploit this in apps that export to their webviews?
- zhongjiewu 13y agoThis is exactly how it works. And a lot of apps use this JS bridging technic to make their app easy to maintain. Dirty hack becomes technical debt
- majiaguan 13y agoPlease disclose more technical detail
- trustlook 13y agoIt's a vulnerability on Android Webview component, which supports a "addJavascriptInterface" method. This method allows you to call the Java native method by using a Javascript object inside the webpage. And, there is a trick that can bypass the restriction on classes that JSInterface object could access. You can call any method in any Java class. Such as Java.lang.Runtime.exec. You can google "addJavascriptInterface vulnerability". It's not a new vulnerability, but lots of app haven't fix it yet.
- sleepyK 13y agoWell to be honest almost nobody on Android uses Bing..... Google search is default, and for those looking for alternatives, there's also an excellent DuckDuckGo app.
- dudus 13y agoDoes this bug affect only android phones that are rooted? It flashes saying that the bing App got root permission. I think that's disabled unless the phone was jailbroken.
- trustlook 13y agoCorrect. Even for the not rooted phones, attackers can send SMS, record audio or access SD card due to the permissions the target app applied. Also you may exploit some privilege escalation vulnerability on Android after you got a shell. It's phone-specific and app-specific though.
- majiaguan 13y agolol, Microsoft need to learn how to write Android app, especially in Java programming
- stephen_john 13y agomicrosoft like c#,lol
- stephen_john 13y agoi do not want to use bing any more. how can i protect my android phone?
- wangsanli 13y agoPlease disclose more info about how to fix it, thx.
- Joanne_jiang 13y agowow...unbelievable! would like to hear your next finding