Get a Pentest and security assessment of your IT network.

News

Second Android signature attack disclosed

Chinese security bloggers have disclosed alternative to Bluebox’s Android signature attack. The new Chinese attack works instead by modifying the classes.dex file which contains an application’s compiled code within the APK file. When validating, a bug in the reading code means that 0xFFFD is converted to -3 and the validation takes places starting at the “dex” part of the file name extension which also happens to be the opening header of the dex file format. The flaw exploits a confusion between short and int types and has been given the bug id 9695860.”]

Source: http://www.h-online.com/security/news/item/Second-Android-signature-attack-disclosed-1918061.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Shamoon Malware, cyber espionage tool, cyber weapon or