Get a Pentest and security assessment of your IT network.

News

Second Android signature attack disclosed

Chinese security bloggers have disclosed alternative to Bluebox’s Android signature attack. The new Chinese attack works instead by modifying the classes.dex file which contains an application’s compiled code within the APK file. When validating, a bug in the reading code means that 0xFFFD is converted to -3 and the validation takes places starting at the “dex” part of the file name extension which also happens to be the opening header of the dex file format. The flaw exploits a confusion between short and int types and has been given the bug id 9695860.”]

Source: http://www.h-online.com/security/news/item/Second-Android-signature-attack-disclosed-1918061.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin