Re: [Full-disclosure] "Data-Clone" -- a new way to attack android apps

2013-03-17 Thread IEhrepus
http://www.80vul.com/android/data-clone.txt update thx jonn Horn(jannh...@googlemail.com) hitest 2013/3/18 IEhrepus <5up3r...@gmail.com> > “I'm pretty sure that this is wrong. Apps on the SD card are encrypted. The > > crypto is flawed, but not so flawed that this kind of attack would > be

Re: [Full-disclosure] "Data-Clone" -- a new way to attack android apps

2013-03-17 Thread IEhrepus
“I'm pretty sure that this is wrong. Apps on the SD card are encrypted. The crypto is flawed, but not so flawed that this kind of attack would be possible. Also, apps on the device even need an exploit just to be able to read the encrypted data.” yes,"apps install on SDcard" is wrong :( apps insta

Re: [Full-disclosure] "Data-Clone" -- a new way to attack android apps

2013-03-17 Thread Jann Horn
On Sun, Mar 17, 2013 at 06:09:09PM +0800, IEhrepus wrote: > "Data-Clone" -- a new way to attack android apps > > Author: super...@www.knownsec.com [Email:5up3rh3i#gmail.com] > Release Date: 2013/03/16 > References: http://www.80vul.com/android/data-clone.txt > Chinese Version: > http://blog.knowns

[Full-disclosure] "Data-Clone" -- a new way to attack android apps

2013-03-17 Thread IEhrepus
"Data-Clone" -- a new way to attack android apps Author: super...@www.knownsec.com [Email:5up3rh3i#gmail.com] Release Date: 2013/03/16 References: http://www.80vul.com/android/data-clone.txt Chinese Version: http://blog.knownsec.com/2013/03/attack-your-android-apps-by-webview/ --[ I - Introductio