| Thread Tools |
28th August 2018, 09:19 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Android at the mercy of AT commands ATtention, ATtention... I just love ATtention Boffins from the University of Florida, Stony Brook University, and Samsung Research America, have looked into what types of AT commands, or the Hayes command set, are currently supported on modern Android devices and found they are all vulnerable to attack. AT (ATtention) commands are a collection of short-string commands developed in the early 1980s that were designed to be transmitted via phone lines and control modems. Different AT command strings can be merged together to tell a modem to dial, hang up, or change connection parameters. Smartphones include a basic modem component inside them, which allows the smartphone to connect to the Internet via its telephony function. While international telecommunications bodies have standardised basic AT commands, dictating a list that all smartphones must support, vendors have also added custom AT command sets to their own devices —commands which can control some pretty dangerous phone features such as the touchscreen interface, the device's camera, and more. According to Beeping Computer the boffins looked at more 2,000 Android firmware images from eleven Android OEMs such as ASUS, Google, HTC, Huawei, Lenovo, LG, LineageOS, Motorola, Samsung, Sony, and ZTE. They say they discovered that these devices support over 3,500 different types of AT commands, some of which grant access to very dangerous functions. These AT commands are all exposed via the phone's USB interface, meaning an attacker would have to either gain access to a user's device, or hide a malicious component inside USB docks, chargers, or charging stations. Once an attacker is connected via the USB to a target's phone, s/he can use one of the phone's secret AT commands to rewrite device firmware, bypass Android security mechanisms, exfiltrate sensitive device information, perform screen unlocks, or even inject touch events solely through the use of AT commands. https://fudzilla.com/news/mobile/470...of-at-commands |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
'Overwatch' update downgrades Mercy, adds 4K on Xbox One X | Stefan Mileschin | WebNews | 0 | 4th February 2018 11:50 |
Philips Hue now responds to your Siri commands | Stefan Mileschin | WebNews | 0 | 6th October 2015 07:56 |
Android Lollipop lets you tweak some settings using voice commands | Stefan Mileschin | WebNews | 0 | 22nd February 2015 16:06 |
Upgraded GPS Now Accepts Voice Commands | Stefan Mileschin | WebNews | 0 | 17th February 2015 06:56 |
Dacor's Android ovens will take voice commands from your app | Stefan Mileschin | WebNews | 0 | 5th January 2015 19:30 |
A List of All the Google Now Voice Commands | Stefan Mileschin | WebNews | 0 | 4th August 2014 17:43 |
'OK Google' voice commands are coming to your Android lockscreen | Stefan Mileschin | WebNews | 0 | 27th June 2014 08:54 |
Android is reportedly getting voice commands everywhere | Stefan Mileschin | WebNews | 0 | 28th April 2014 09:27 |
You can wake up the Nexus 5 with voice commands | Stefan Mileschin | WebNews | 0 | 1st November 2013 10:01 |
What actually happens when you type the commands Format C: in windows? | jmke | WebNews | 0 | 3rd November 2004 13:18 |
Thread Tools | |
| |