Android Phone Flaw Allows Attackers to Divert Email

  /     /     /  
Publicated : 23/11/2024   Category : security


Android Phone Flaw Allows Attackers to Divert Email


Researchers find that a spoofing a service message from the phone carrier is simple and effective on some brands of Android smartphones.



Using text messages with embedded links, security researchers from Check Point Software Technologies recently discovered that spoofing messages from a phone carrier could be used to configure certain features, including e-mail and the directory server, of several brands of Android phones.
The attack uses over-the-air (OTA) provisioning messages, a technique used by carriers to deploy certain configurations to phones for their network: but the malicious attack exploits design weaknesses on several brands of Android phones, including Samsung, Sony, LG, and Huawei.
While OTA provisioning has been used in the past to set up wireless access point proxies to hijack traffic, this is the first time that an attack has been shown to hijack email on mobile phones, says Slava Makaveev, a security researcher with Check Point. 
The ability to configure email and directory servers is a vendor-specific extension for the protocol, he says. The email server provisioning is a design weakness. 
The security flaw puts users of the phones at risk if they trust the source of any over-the-air update. On a Samsung phone, an attacker could, without any sort of authentication check, change the MMS message server, the proxy address for Internet traffic, the browser homepage and bookmarks, the email server, and any directory servers for synchronizing contacts and calendar.
Sony, LG, and Huawei phones, meanwhile, pose only slightly higher hurdles for an attacker — a valid IMSI (international mobile subscriber identity), which is specific to the phone, but could be retrieved by an application with the right permissions, according to Check Point.
Even without the IMSI, there is a way to fool the user. For those potential victims whose IMSI could not be obtained, the attacker can send each victim two messages, Makkaveev
wrote in Check Points technical brief
. The first is a text message that purports to be from the victims network operator, asking him to accept a PIN-protected OMA CP, and specifying the PIN as an arbitrary four-digit number. Next, the attacker sends him an OMA CP message authenticated with the same PIN.
The underlying design flaw is that while requiring the user to accept the changes, all of these provisioning methods appear with all the trappings of an official message from the phone carrier - with the specific dialog box labeled New Settings.
When you first join a new carrier network, youll get a warm, welcome message from your carrier — do not trust it, Check Points Makkaveev said in statement. People naively think those messages are safe. Simply, we cant trust those texts anymore. 
OTA provisioning is not part of the basic Android distribution but many carriers implement their own, as specified in the Open Mobile Alliance Client Provisioning (OMA CP) standard. However, the standard includes only a few ways to authenticate messages and makes the security check optional. 
Weak Authentication
Check Point researchers found that Samsung phones dont perfrom authentication checks on client-provisioning messages, and several other phone makers — including Huawei, LG, and Sony — have weak authentication using the IMSI, a semi-private identifier for the phone. Because of the weak authentication, the source of any over-the-air provisioning messages that come in cannot be verified, Check Point stated in its advisory.
A recipient cannot verify whether the suggested settings originate from her network operator or from a dangerous imposter looking to read their emails,
the company said

Check Point notified each phone provider in March and gave them a chance to update their software. Samsung patched its software in May and LG released a fix in July, according to Check Point. Huawei plans to fix the next version of their phones, and Sony did not consider the issue to be a vulnerability, Check Point said. 
In the past, patching of firmware has been a laborious process for Android phones. The original software maker has to patch the issue, the hardware make has to approve the fix, as does the carrier, and then the use has to update. For that reason, Check Point does not know how widespread the issue currently is, says Makaveev.
We dont know how many people have downloaded the latest patches provided by Samsung and LG — we highly recommend they do that, he says. Holders of Huawei and Sony devices are not protected at all.
Related Content:
Android Malware Triada Most Active on Telco Networks
47% of Android Anti-Malware Apps Are Flawed
Malware Found in Android App with 100M Users
New Android Toast Vuln Makes Overlay Attacks Easier
Check out
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
It Takes Restraint: A Seasoned CISOs Sage Advice for New CISOs
 

Last News

▸ DHS-funded SWAMP scans code for bugs. ◂
Discovered: 23/12/2024
Category: security

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Android Phone Flaw Allows Attackers to Divert Email