Android Vulnerabilities: Man-in-the-Disk Attacks Google Translate

Subscribers:
79,900
Published on ● Video Link: https://www.youtube.com/watch?v=M3rQ_J8rS7c



Duration: 0:32
7,186 views
11


Check Point Research discovers a shortcoming in the design of Android’s use of storage resources. Careless use of External Storage by applications may open the door to an attack resulting in any number of undesired outcomes, such as silent installation of unrequested, potentially malicious, apps to the user’s phone, denial of service for legitimate apps, and even cause applications to crash, opening the door to possible code injection that would then run in the privileged context of the attacked application.

In the case of Google Translate, developers failed to validate the integrity of data read from the External Storage. As such, our team was able to compromise certain files required by these apps, resulting in the crash of each of these applications, as seen in video of crashing Google Translate.

For more details on the Man-in-the-Disk, please visit: https://research.checkpoint.com/androids-man-in-the-disk/




Other Videos By Check Point Software


2018-09-10CloudGuard SaaS Zero-Day Threat Protection - Demo Snippets
2018-09-10CloudGuard SaaS Phishing Protection - Demo Snippets
2018-09-07CPX 360 2019 - Save the Date for the Premier Cyber Security Summit
2018-09-07Be a Part of CPX 360 - The Premier Cyber Security Summit & Expo
2018-09-06R80.10 Identity Awareness- DemoPoint Academy
2018-08-31Without the Best Security, Bad Things Happen, (Nacho Malware Edition)
2018-08-17Combating 5th generation cyber attacks w/ Check Point 23900 Security Gateway & SandBlast Mobile 3.0
2018-08-15Check Point R80.20 – Integrating Google Cloud Account
2018-08-12Hacking the Fax – Ground Breaking New Research in Cyber
2018-08-12Android Vulnerabilities: Man-in-the-Disk Attacks Google Voice Assistant
2018-08-12Android Vulnerabilities: Man-in-the-Disk Attacks Google Translate
2018-08-12Android Vulnerabilities: Man-in-the-Disk Attacks Xioami Browser
2018-08-12Android Vulnerabilities: Man-in-the-Disk Attacks Yandex Search
2018-08-12Yandex Translate
2018-08-08Harmony Mobile Architecture: Check Point Lightboard Series
2018-08-07FakesApp: A Vulnerability in WhatsApp
2018-08-06Check Point CloudGuard is Cloud Security
2018-08-02CloudGuard VMware NSX Demo- DemoPoint Academy
2018-08-01Understanding the Shared Responsibility Model, Check Point Lightboard Series
2018-07-26Check Point Lightboard Series: High Availability Architecture in Multi-Domain Environments
2018-07-24High Availability Architecture with R80.10 - Check Point Lightboard Series



Tags:
#Android #ManintheDisk #vulnerability #CheckPointResearch #DEFCON26