As the article says: Worst. Bug. Ever.

doc savage
Short version: for Android phones with firmware version 1.0 TC4-RC29 or earlier,

There's a root shell using the console as stdin, so all input on the physical keyboard on the phone is being interpreted by that shell (regardless of what application is being displayed, and regardless of whether it is responding to those keyboard presses itself).


In other words: you type 'reboot' on any bundled Android application, the phone reboots. Type 'telnetd', and you get a telnet daemon up and running as root.

Yes, I can't quite wrap my mind around it either.

If this is true (jwz post here, cf the link referenced there), this has to be one of the most embarrassing security bugs in the history of IT.

There's only one possible label for this: EPIC FAIL.

Tags:

Latest Month

December 2014
S M T W T F S
 123456
78910111213
14151617181920
21222324252627
28293031   

Tags

Syndicate

RSS Atom
Powered by LiveJournal.com
Designed by Tiffany Chow