[Full-disclosure] Data-Clone -- a new way to attack android apps

2013-03-17 Thread IEhrepus
Data-Clone -- a new way to attack android apps Author: super...@www.knownsec.com [Email:5up3rh3i#gmail.com] Release Date: 2013/03/16 References: http://www.80vul.com/android/data-clone.txt Chinese Version: http://blog.knownsec.com/2013/03/attack-your-android-apps-by-webview/ --[ I - Introduction

Re: [Full-disclosure] Data-Clone -- a new way to attack android apps

2013-03-17 Thread Jann Horn
On Sun, Mar 17, 2013 at 06:09:09PM +0800, IEhrepus wrote: Data-Clone -- a new way to attack android apps Author: super...@www.knownsec.com [Email:5up3rh3i#gmail.com] Release Date: 2013/03/16 References: http://www.80vul.com/android/data-clone.txt Chinese Version:

Re: [Full-disclosure] Data-Clone -- a new way to attack android apps

2013-03-17 Thread IEhrepus
“I'm pretty sure that this is wrong. Apps on the SD card are encrypted. The crypto is flawed, but not so flawed that this kind of attack would be possible. Also, apps on the device even need an exploit just to be able to read the encrypted data.” yes,apps install on SDcard is wrong :( apps

Re: [Full-disclosure] Data-Clone -- a new way to attack android apps

2013-03-17 Thread IEhrepus
http://www.80vul.com/android/data-clone.txt update thx jonn Horn(jannh...@googlemail.com) hitest 2013/3/18 IEhrepus 5up3r...@gmail.com “I'm pretty sure that this is wrong. Apps on the SD card are encrypted. The crypto is flawed, but not so flawed that this kind of attack would be