Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Google's Android hacking contest fails to draw exploits

Google's Android hacking contest fails to draw exploits

Latest Govt. Jobs 15:43:00 News Edit
p1200739

Six months ago, Google offered to pay US$200,000 to any researcher who could remotely hack into an Android device by knowing only the victim's phone number and email address. No one stepped up to the challenge.
While that might sound like good news and a testament to the mobile operating system's strong security, that's likely not the reason why the company's Project Zero Prize contest attracted so little interest. From the start, people pointed out that $200,000 was too low a prize for a remote exploit chain that wouldn't rely on user interaction.
"If one could do this, the exploit could be sold to other companies or entities for a much higher price," one user responded to the original contest announcement in September.
"Many buyers out there could pay more than this price; 200k not worth for finding needle under haystack," said another.
Google was forced to acknowledge this, noting in a blog post this week that "the prize amount might have been too low considering the type of bugs required to win this contest." Other reasons that might have led to the lack of interest, according to the company's security team, might be the high complexity of such exploits and the existence of competing contests where the rules were less strict.
In order to gain root or kernel privileges on Android and fully compromise a device, an attacker would have to chain multiple vulnerabilities together. At the very least, they would need a flaw that would allow them to remotely execute code on the device, for example within the context of an application, and then a privilege escalation vulnerability to escape the application sandbox.
Judging by Android's monthly security bulletins, there's no shortage of privilege escalation vulnerabilities. However, Google wanted for exploits submitted as part of this contest to not rely on any form of user interaction. This means the attacks should have worked without users clicking on malicious links, visiting rogue websites, receiving and opening files, and so on.
This rule significantly restricted the entry points that researchers could use to attack a device. The first vulnerability in the chain would have had to be located in the operating system's built-in messaging functions like SMS or MMS, or in the baseband firmware -- the low-level software that controls the phone's modem and which can be attacked over the cellular network.
One vulnerability that would have met these criteria was discovered in 2015 in a core Android media processing library called Stagefright, with researchers from mobile security firm Zimperium finding the vulnerability. The flaw, which triggered a large coordinated Android patching effort at the time, could have been exploited by simply placing a specially crafted media file anywhere on the device's storage.
One way to do that involved sending a multimedia message (MMS) to targeted users and didn't require any interaction on their part. Merely receiving such a message was enough for successful exploitation.
Many similar vulnerabilities have since been found in Stagefright and in other Android media processing components, but Google changed the default behavior of the built-in messaging apps to no longer retrieve MMS messages automatically, closing that avenue for future exploits.
"Remote, unassisted, bugs are rare and require a lot of creativity and sophistication," said Zuk Avraham, founder and chairman of Zimperium, via email. They're worth much more than $200,000, he said.
An exploit acquisition firm called Zerodium is also offering $200,000 for remote Android jailbreaks, but it doesn't put a restriction on user interaction. Zerodium sells the exploits it acquires to their customers, including to law enforcement and intelligence agencies.
So why go to the trouble of finding rare vulnerabilities to build fully unassisted attack chains when you can get the same amount of money -- or even more on the black market -- for less sophisticated exploits?
"Overall, this contest was a learning experience, and we hope to put what we’ve learned to use in Google’s rewards programs and future contests," Natalie Silvanovich, a member of Google's Project Zero team, said in the blog post. To that end, the team is expecting comments and suggestions from security researchers, she said.
It's worth mentioning that despite this apparent failure, Google is a bug bounty pioneer and has run some of the most successful security reward programs over the years covering both its software and online services.
There's little chance that vendors will ever be able to offer the same amount of money for exploits as criminal organizations, intelligence agencies, or exploit brokers. Ultimately, bug bounty programs and hacking contests are aimed at researchers who have an inclination toward responsible disclosure to begin with.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Vodafone partners with Tecno to off...

LG G7 with iPhone X-like notch

Oppo F7 India launch confirmed
Google's Android hacking contest fails to draw exploits Google's Android hacking contest fails to draw exploits Reviewed by Latest Govt. Jobs on 15:43:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • KingRoot 4.8.1 (136) APK Latest Version Download
    Download KingRoot Latest Version 4.8.1 In Tools by Developer KingRoot Studio ( 4.x / 5  average ...
  • 11 things you should understand approximately iOS 11
    Apple introduced the following version of its running system for the iPhone and iPad, iOS eleven ...
  • How to Upload Your Music Library to Google Play Music
    Google Play Music offers an unlimited music streaming subscription paired with YouTube Red ...
  • How to Disable Your Mac’s Touchpad When Another Mouse Is Connected
    Laptop trackpads can be annoying. Your palm hits them while you’re typing, moving your cursor ...
  • How to Gain Root Access of An Android Device via KingoRoot Software
    What Does Root Access Mean? Gaining root access of Android is the process of modifying the ...

Random Posts

  • Up to Rs 300 Cashback On HEBRON Bus Ticket Booking
    Up to Rs 300 Cashback On HEBRON Bus Ticket Booking
    24.02.2018 - 0 Comments
    Promocode: HEBRON300 Terms & Conditions: Get 10% Cashback up to ₹300 on bus ticket…
  • Samsung files trademark for ‘Gear Fit Pro’; hints at a new wearable device
    Samsung files trademark for ‘Gear Fit Pro’; hints at a new wearable device
    04.02.2017 - 0 Comments
    Samsung may be looking to launch a wearable device, dubbed the ‘Gear Fit Pro’. The news comes…
  • Best free Android games of 2017
    Best free Android games of 2017
    14.01.2017 - 0 Comments
    Here's our roundup of the very best free Android games available in the Google Play Store right now. Have…
  • Samsung Galaxy S8 Plus pre-order deals: what price should you expect to pay?
    Samsung Galaxy S8 Plus pre-order deals: what price should you expect to pay?
    09.03.2017 - 0 Comments
    The Samsung Galaxy S8 Plus is set to be announced alongside its smaller sibling later this month…
  • 10.OR E 32GB Smartphone
    10.OR E 32GB Smartphone
    25.01.2018 - 0 Comments
    The 10.or E 32GB mobile features a 5.5" (13.97 cm) display with a screen resolution of Full HD (1080 x 1920…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • How to Disable Your Mac’s Touchpad When Another Mouse Is Connected
    Laptop ...
  • Infocus Vision 3 review
    What happens when ...
  • Researchers trick 'CEO' email scammer into giving up identity
    Businesses ...
  • How to Gain Root Access of An Android Device via KingoRoot Software
    What Does Root ...
  • Tinyowl Freecharge Offer – Get 15% Cashback + extra 25% cashback using Freecharge [Ultimatez Tricks]
    Tinyowl Freecharge ...
  • EVGA redesigns its graphics cards following overheating concerns
    Following a ...

Random Posts

  • eBay - Rs.200 Off On Shopping of Rs.499 + 10% Cashback
    eBay - Rs.200 Off On Shopping of Rs.499 + 10% Cashback
    17.02.2018 - 0 Comments
    Offer Details:-eBay – Get Rs. 200 off on Shopping of Rs. 499 or more . Additional 10% Cashback via…
  • Tips to Increase Android Phone Battery Life | 10 Best proven ways to save
    Tips to Increase Android Phone Battery Life | 10 Best proven ways to save
    13.02.2016 - 0 Comments
    Smartphone specially Android batteries are designed in way that it will give you max output if you use them…
  • Trump seeking Republican breakthrough with wins in Florida, Ohio
    Trump seeking Republican breakthrough with wins in Florida, Ohio
    15.03.2016 - 0 Comments
    Donald Trump could take a giant step on Tuesday toward securing the Republican presidential nomination if he…
  • Samsung Galaxy S9, Galaxy S9+ could retain a 3.5mm headset jack
    Samsung Galaxy S9, Galaxy S9+ could retain a 3.5mm headset jack
    10.02.2018 - 0 Comments
    Samsung Galaxy S9, Galaxy S9+ launch is set for February 25 in Barcelona, ahead of the Mobile World Congress…
  • Jio Happy New Year Offer: How to Get Reliance Jio SIM Without Lyf Phone
    Jio Happy New Year Offer: How to Get Reliance Jio SIM Without Lyf Phone
    06.01.2017 - 0 Comments
    Reliance Jio's happy New year offer extends until March 31, 2017 all of the unfastened offerings that the…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!