METAPHOR- Another stagefright



METAPHOR  - “NorthBit” is a Israeli software research company, claimed that it had properly exploited the Android bug and  is described as the "Worst Ever Discovered".

Stagefright is a multimedia playback library, which is written in C++. It is built inside the Android OS to process, record and play multimedia files such as videos.

Millions of Android users could be at risk from this 'Stagefright' flaw. Researchers claim to have made a working exploit that can remotely take control of a device and spy on victims within 10 seconds.

Metaphor give hackers the ability to inject malware that can copy, steal and delete data on the device, take over the smartphone's microphone, camera for spying purposes and even track a user's movements via GPS.


HOW IT WORKS:

Victims are sent a message linking to a website containing a video file that crashes the phone's media software and force it to restart.

 Then, JavaScript on the page sends all known information about the device to the attacker's server.

After this, another video file is sent to the device which executes a malware - ridden payload to give the attacker control over the device completely.


According to the researchers, Millions of Android devices are vulnerable to the exploit that successfully bypasses security defenses offered by Android OS. Here’s the PDF document.



Comments

Popular posts from this blog

INSTALL TIGHTVNC ON KALI LINUX RASPBERRY PI

ENABLE AUTOSTART FOR X11VNC

INSTALL X11VNC ON KALI LINUX RASPBERRY PI