![]() |
Holy cow, we have been dirty for 9 years
http://arstechnica.com/security/2016...ctive-exploit/
Quite a massive number of devices that are vulnerable to this bug as it's quite an old feature and only discovered now. Then to think many android phones won't get an kernel-update probably. I am assuming android is just as vulnerable as any other linux distro with old kernel. |
Re: Holy cow, we have been dirty for 9 years
A distaster for the servers and a Holy Grail for the handhelds.
|
Re: Holy cow, we have been dirty for 9 years
AFAIU you first have to login via ssh(or similar) as normal user to the phone before you can gain root access I don't see it as critical on phone but worse on web sites.
"The exploits can be used against Web hosting providers that provide shell access" And how many of you give out ssh access to your phone? However I hope SFOS next release has the fix. |
Re: Holy cow, we have been dirty for 9 years
this exploit can be easily used by any malware application you install :)
|
Re: Holy cow, we have been dirty for 9 years
Apparently the "fix" was identified, any ideas when this will be backported to KP?
Not sure about 2.6.28, but backported to my 4.0.5 server, there had been changes so the patch in the commit wouldn't cleanly go in... but was close enough to easily figure out Supposedly it's been around since 2.6.22 but "harder" to exploit ... and as I don't have many random binaries I run on my N900, probably somewhat safe. The regular PCs with <koff>flashplayer and any with outward facing shell access I have to be worried about... |
Re: Holy cow, we have been dirty for 9 years
Quote:
BUT at the same time you could root your own phone if you need it and if the phone manufacturer prevents you from getting root access. So I find this vulnerability as somewhat good for the handhelds power users. Quote:
|
Re: Holy cow, we have been dirty for 9 years
Quote:
Honestly, if you install "Brain Test" applications, you're bound to get hacked in some way eventually. Every time these supposedly extreme security flaws come up, it turns out to be something you need to explicitly allow. That isn't a security problem, it's a user problem, and those have turned out to be impossible to fix. |
Re: Holy cow, we have been dirty for 9 years
Quote:
|
Re: Holy cow, we have been dirty for 9 years
9 years. So much for shallow bugs.
|
Re: Holy cow, we have been dirty for 9 years
Quote:
On an Android phone I assume with cyanogenmod (no gapps) and only install apps from the f-droid repo you will prevent installing any malicious software and are relatively safe. |
All times are GMT. The time now is 23:09. |
vBulletin® Version 3.8.8