• Tips
Wireless and Mobile News

wireless and mobile news

  • Twitter
  • Facebook
  • RSS
You are here: Home » Droid »

Android Apps Open to Exploits Even without Permission in Android 4.0 ICS

By Lynn Walford 04/13/2012 Tweet
Android Apps Open to Exploits Even without Permission in Android 4.0 ICSAndroid apps even without permissions, can access data which could pose a security threat.  researcher  Paul Brodeur of Leviathan Security created an app that was able to find out all sorts of information about an Android device even without permission.
Brodeur created a ''No Permissions'' Android app that explores what data is available can be harvested from an Android device even when the installed app has no permissions.  The app was able to harvest data, open a browser and send the data over the web.
Information stored on microSD card can be read even Open VPN certificates.
Th app read the /data/system/packages.list file to determine what apps are currently installed on the device which can be scanned to so  show a list of installed apps and a list of any readable files then read some files belonging to other apps.
Even with no permission Brodeur was able grab identifiable information about the device itself, most importantly the Android ID.
The app could not read the IMEI or IMSI, however the GSM & SIM vendor IDs can still be read. The /proc/version pseudofile, which reveals the kernel version and possibly the name of the custom ROM installed, can also be read.  The Android ID,  is a 64-bit number randomly generated when a device is first booted and remains constant thereafter.
Without any permissions: the URI ACTION_VIEW Intent opens a browser. he found that the app is able to launch the browser allowing for transmission of large amounts of data by creating successive browser calls.

The app was tested against Android 4.0.3 and Android 2.3.5.  What can you? We suggest that you monitor your data, to see if it being used by apps as well as don't use any apps from unknown sources.  The in-app advertising also collects data.
If an app contains many ads, it may not be worth using because it is using you your data plan.  Apps that run without access the net will be the most data efficient.
In fact, most free apps scan for data. Research showed that ads in Android apps are risky business for privacy and security. Free apps drain batteries faster because  75% of an app's energy consumption was spent on powering advertisements.
Security expert Robert Sciiliano was able to find all sorts of information on Android phones bought on Craigslist including porn.

No Related News.

Tags:Android security

 

Sign up for our newsletter

Comments are closed

Latest News

  • Top Best: SG 4, BlackBerry Q10, HTC One, Lumia 521, iPhone 5, Nexus 4/5,
  • iPhone 5 Best Apple Share, Samsung Galaxy S III Best Android - Samsung Rules Prepaid iPhone 5 Best Apple Share, Samsung Galaxy S III Best Android - Samsung Rules Prepaid
  • HTC One + One + One Soon HTC One + One + One Soon
  • No Nexus 5 but Nexus 4 White-Washed at Google I/O: June 10 No Nexus 5 but Nexus 4 White-Washed at Google I/O: June 10
  • GS 4 Memory Loss to Be Fixed - Fastest Selling Samsung Galaxy GS 4 Memory Loss to Be Fixed - Fastest Selling Samsung Galaxy

WiMo News Posts Haste

Subscribe to our newsletter.

Most Popular News

  • BlackBerry Q10 Release Dates in June(Verizon T-Mobile) & Summer (Sprint)
  • HTC One + One + One Soon
  • Nokia Lumia 521 vs iPhone 5 Best Cheapest Deal Sold-Out
  • Cheapest iPhone 5 Got More Expensive, Still Best Deal vs Sprint, AT&T & Verizon
  • Next Nexus 4/5 Coming -Moto X XFON Nixed 4 Now or Droid?

Connect With Us

  •  Twitter
  •  Google+
  •  Pinterest
  •  Facebook
  •  YouTube
 

Related News

  • GS 4 Biggest Next Big Thing Best Smartphone vs iPhone Sales
  • Samsung Galaxy  S3 (III) Update to Android 4.1.2 Jelly Bean T-Mobile Samsung Galaxy S3 (III) Update to Android 4.1.2 Jelly Bean T-Mobile
  • Samsung Galaxy S2-4 Expands into Profit-Noted Universe Samsung Galaxy S2-4 Expands into Profit-Noted Universe
  • Next Samsung Galaxy: Note 3 (III) & S4 Models Sized, Rugged or Cameratastic?
  • Samsung Galaxy S II-III-Y-Note Bests RAZR Not iPhone, Yet Samsung Galaxy S II-III-Y-Note Bests RAZR Not iPhone, Yet

Reviews

  • Droid DNA Review vs Samsung Galaxy S4, iPhone 5 & HTC One Droid DNA Review vs Samsung Galaxy S4, iPhone 5 & HTC One
  • Nexus 10 Review vs iPad Ready 4 Android 5? - Best Deals Nexus 10 Review vs iPad Ready 4 Android 5? - Best Deals
  • Kindle Fire HD 8.9 Review Kindle Fire HD 8.9 Review
  • Samsung Galaxy Note 2 (II) Review AT&T vs Sprint  T-Mobile & Verizon Samsung Galaxy Note 2 (II) Review AT&T vs Sprint T-Mobile & Verizon
Wireless and Mobile News
  • HOME
  • iPHONE
  • MOBILE
  • ANDROID
  • APPS
  • DEALS
  • WIRELESS
  • RSS
  • Archives
  • Advertise
  • Privacy Policy
  • CONTACT
  • ABOUT
  • Tip Us
© Copyright 2013 — Wireless and Mobile News, LLC. All Rights Reserved