Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Wednesday September 06 2017, @10:07AM   Printer-friendly
from the there's-more-where-that-came-from dept.

Android bootloader components from five major chipset vendors are affected by vulnerabilities that break the CoT (Chain of Trust) during the boot-up sequence, opening devices to attacks.

The vulnerabilities came to light during research carried out by a team of nine computer scientists from the University of California, Santa Barbara.

The research team looked into the shadowy world of Android bootloaders, components that are hard to analyze because they are closed-source and tend to lack typical metadata (such as program headers or debugging symbols) that are usually found in normal programs and help reverse engineering and security audits.

Most of the team's work focused on developing a new tool named BootStomp specialized in helping test and analyze bootloaders.

The goal of BootStomp is to automatically identify security vulnerabilities that are related to the (mis)use of attacker-controlled non-volatile memory, trusted by the bootloader's code. In particular, we envision using our system as an automatic system that, given a bootloader as input, outputs a number of alerts that could signal the presence of security vulnerabilities. Then, human analysts can analyze these alerts and quickly determine whether the highlighted functionality indeed constitute a security threat.

By using BootStomp to find problematic areas of the previously obscure bootloader code, and then having the research team look over the findings, experts said they identified seven security flaws, six new and one previously known (CVE-2014-9798). Of the six new flaws, bootloader vendors already acknowledged and confirmed five.

https://www.bleepingcomputer.com/news/security/vulnerabilities-discovered-in-mobile-bootloaders-of-major-vendors/


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: -1, Offtopic) by Anonymous Coward on Wednesday September 06 2017, @11:07AM (1 child)

    by Anonymous Coward on Wednesday September 06 2017, @11:07AM (#564105)

    fruit loops within!

    Starting Score:    0  points
    Moderation   -1  
       Offtopic=1, Total=1
    Extra 'Offtopic' Modifier   0  

    Total Score:   -1  
  • (Score: -1, Offtopic) by Anonymous Coward on Wednesday September 06 2017, @11:14AM

    by Anonymous Coward on Wednesday September 06 2017, @11:14AM (#564106)

    bet you can't rub one off shooting through the air and landing in my mouth