To Write or not Write, that is the Question - Abusing of Leaked Data and Vulnerable User Assets on Android

No ratings

Presented at BSidesBudapest 2019 by

Thought data leakage through Android shared folders is not a new topic, it generally focused on Android stock apps and how to steal user credentials or abusing of flawed device reset mechanisms. In this talk, we will show how these studies can be extended to consider both active devices and any apps installed by the user. By "simply" abusing of publicly shared assets, we will illustrate how it is possible to - infer app internal behavior and data format - retrieve user PII assets from leaked session tokens or simply directly from caches - retrieve / alter / delete user data - alter user data before sharing with partners and inject malicious payloads - perform replay session due to leaked session header or internal protocols Our work relies on research made on hundred of major Android apps, with around one third of them being at best partially flawed. Due to the associated disclosure policies, we will not reveal the name of the audited apps. However, we will also talk about vendor responses in order to illustrate how Android users should (attempt to) protect their privacy and data.