ExtremeHacking
Today : | Time : | safemode : ON
> / Main Website / Cyber Surakha Abhiyan / Hackers Charity / Linkedin / facebook / twitter /
Name Author Perms Com Modified Label

Critical flaw in Viber app allows full access to Smartphones Unknown rwxr-xr-x 0 4/25/2013

Filename Critical flaw in Viber app allows full access to Smartphones
Permission rw-r--r--
Author Unknown
Date and Time 4/25/2013
Label
Action
Ethical Hacking Institute in Pune
./Arizona Team

More than 50 millions of Smartphone users worldwide are facing a risk posed by a critical flaw in Viber app. The security company Bkav announced that it has found a way to gain full access to Android phones using the popular Viber messaging app.
Unlike the Samsung lockscreen issue we reported on earlier, this attack doesn't take any fancy finger work. Instead, all it needs is two phones, both running Viber, and a phone number.

"The way Viber handles to popup its messages on smartphones' lock screen is unusual, resulting in its failure to control programming logic, causing the flaw to appear," said Mr. Nguyen Minh Duc, Director of Bkav's Security Division.




























Steps to exploit:

1.Send Viber message to victim
2.Combine actions on Viber message popups with tricks like using victim's notification bar, sending other Viber messages, etc. to make Viber keyboard appear
3.Once Viber keyboard has appeared, to fully access the device, create missed call to victim (with HTC Sensation XE), press Back button (with Google Nexus 4, Samsung Galaxy S2, Sony Xperia Z), etc.


POC VIDEO:


As the above videos demonstrate, the latest vulnerability affects a variety of handsets as long as they have Viber installed. People rely on their smartphones to keep their e-mails, contacts, and other sensitive information, so Company plan to release a fix the issue next week.

www.arizonainfotech.com
CEH CHFI ECSA ENSA CCNA CCNA SECURITY MCITP RHCE CLOUD ANDROID IPHONE NETWORKING HARDWARE TRAINING INSTITUTE IN PUNE

 

Cyber Suraksha Abhiyan | Sadik Shaikh © 2015 Sadik Shaikh | CEH V9 | ETHICAL HACKING Course Training Institute in India-Pune
Extreme Hacking Template design by Sadik Shaikh | Cyber Suraksha Abhiyan