Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Monday October 02 2017, @11:29AM   Printer-friendly
from the ground-beef dept.

Submitted via IRC for SoyCow5743

A serious vulnerability that remains unfixed in many Android devices is under active exploit, marking the first known time real-world attackers have used it to bypass key security protections built in to the mobile operating system.

Dirty Cow, as the vulnerability has been dubbed, came to light last October after lurking in the kernel of the Linux operating system for nine years. While it amounts to a mere privilege-escalation bug—as opposed to a more critical code-execution flaw—several characteristics make it particularly potent. For one, the vulnerability is located in a part of the Linux kernel that's almost universally available. And for another, reliable exploits are relatively easy to develop.

By the time it was disclosed, it was already under active exploit on Linux servers. Within days of its disclosure, researchers and hobbyists were using the vulnerability, indexed as CVE-2016-5195, to root Android phones.

Now, more than 1,200 apps available in third-party marketplaces are exploiting Dirty Cow as part of a scam that uses text-based payment services to make fraudulent charges to the phone owner, researchers from antivirus provider Trend Micro reported on Monday.

Source: https://arstechnica.com/information-technology/2017/09/in-a-first-android-apps-abuse-serious-dirty-cow-bug-to-backdoor-phones/


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by DannyB on Monday October 02 2017, @02:13PM (2 children)

    by DannyB (5839) Subscriber Badge on Monday October 02 2017, @02:13PM (#575897) Journal

    (code which also mutates at the whim of whoever controls the dev account via auto-updates)

    There are a lot of those whoevers. Not just one whoever. Each App has a 'whoever' that developed the app and can update it. So the number of whoevers can potentially match the number of installed apps. You could have several apps from the same whoever.

    There is a mapping between whoevers and apps. The set of whoevers is a non empty subset of the apps.

    don't drive like that! Let's try to get there in as few pieces as possible.

    --
    People today are educated enough to repeat what they are taught but not to question what they are taught.
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 3, Funny) by Whoever on Monday October 02 2017, @05:36PM (1 child)

    by Whoever (4524) on Monday October 02 2017, @05:36PM (#576011) Journal

    There are a lot of those whoevers. Not just one whoever.

    ... but only one here at Soylentnews. [soylentnews.org]

    • (Score: 2) by bob_super on Monday October 02 2017, @06:47PM

      by bob_super (1357) on Monday October 02 2017, @06:47PM (#576072)

      But there could be a whoevers, making us all wonder is you are that whoevers and therefore all the whoevers, or if somehow whoevers doesn't include just any whoever.