It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Android at the mercy of AT commands Android at the mercy of AT commands
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Android at the mercy of AT commands
Reply
 
Thread Tools
Old 28th August 2018, 09:19   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 153,575
Stefan Mileschin Freshly Registered
Default Android at the mercy of AT commands

ATtention, ATtention... I just love ATtention

Boffins from the University of Florida, Stony Brook University, and Samsung Research America, have looked into what types of AT commands, or the Hayes command set, are currently supported on modern Android devices and found they are all vulnerable to attack.

AT (ATtention) commands are a collection of short-string commands developed in the early 1980s that were designed to be transmitted via phone lines and control modems. Different AT command strings can be merged together to tell a modem to dial, hang up, or change connection parameters. Smartphones include a basic modem component inside them, which allows the smartphone to connect to the Internet via its telephony function.

While international telecommunications bodies have standardised basic AT commands, dictating a list that all smartphones must support, vendors have also added custom AT command sets to their own devices —commands which can control some pretty dangerous phone features such as the touchscreen interface, the device's camera, and more.

According to Beeping Computer the boffins looked at more 2,000 Android firmware images from eleven Android OEMs such as ASUS, Google, HTC, Huawei, Lenovo, LG, LineageOS, Motorola, Samsung, Sony, and ZTE.

They say they discovered that these devices support over 3,500 different types of AT commands, some of which grant access to very dangerous functions. These AT commands are all exposed via the phone's USB interface, meaning an attacker would have to either gain access to a user's device, or hide a malicious component inside USB docks, chargers, or charging stations.

Once an attacker is connected via the USB to a target's phone, s/he can use one of the phone's secret AT commands to rewrite device firmware, bypass Android security mechanisms, exfiltrate sensitive device information, perform screen unlocks, or even inject touch events solely through the use of AT commands.

https://fudzilla.com/news/mobile/470...of-at-commands
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
'Overwatch' update downgrades Mercy, adds 4K on Xbox One X Stefan Mileschin WebNews 0 4th February 2018 11:50
Philips Hue now responds to your Siri commands Stefan Mileschin WebNews 0 6th October 2015 07:56
Android Lollipop lets you tweak some settings using voice commands Stefan Mileschin WebNews 0 22nd February 2015 16:06
Upgraded GPS Now Accepts Voice Commands Stefan Mileschin WebNews 0 17th February 2015 06:56
Dacor's Android ovens will take voice commands from your app Stefan Mileschin WebNews 0 5th January 2015 19:30
A List of All the Google Now Voice Commands Stefan Mileschin WebNews 0 4th August 2014 17:43
'OK Google' voice commands are coming to your Android lockscreen Stefan Mileschin WebNews 0 27th June 2014 08:54
Android is reportedly getting voice commands everywhere Stefan Mileschin WebNews 0 28th April 2014 09:27
You can wake up the Nexus 5 with voice commands Stefan Mileschin WebNews 0 1st November 2013 10:01
What actually happens when you type the commands Format C: in windows? jmke WebNews 0 3rd November 2004 13:18

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 09:08.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO