[Cialug] Android security

Josh More MoreJ at alliancetechnologies.net
Thu Jan 20 11:24:13 CST 2011


You could install metasploit and use the module linked in the initial post.

I don't know of an easier "go here to see if you're vulnerable" page... but wouldn't trust it if I did.

Josh More | Senior Security Consultant - CISSP, GIAC-GSLC Gold, GIAC-GCIH
Alliance Technologies | www.AllianceTechnologies.net<http://www.AllianceTechnologies.net>
400 Locust St., Suite 840 | Des Moines, IA 50309
515.245.7701 | 888.387.5670 x7701

Blog: Not The Usual Security Predictions: 2011
http://www.alliancetechnologies.net/blogs/morej

How are we doing? Let us know here:
http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey
________________________________
From: cialug-bounces at cialug.org [cialug-bounces at cialug.org] on behalf of Matthew Nuzum [newz at bearfruit.org]
Sent: Thursday, January 20, 2011 10:57
To: Central Iowa Linux Users Group
Subject: Re: [Cialug] Android security

Some Android phones use a feature-enhanced browser by default. Do you know of a way to test your browser to see if it is susceptible (without actually giving my stuff away to strangers on the web)

On Wed, Jan 19, 2011 at 12:54 PM, Josh More <MoreJ at alliancetechnologies.net<mailto:MoreJ at alliancetechnologies.net>> wrote:
 I do not recall if we were discussing at the meeting or on the IRC channel, so I am posting it here.

There is now a metasploit module to take advantage of the Android browser flaw.  This would be a good time to upgrade to 2.3 or replace the default browser with Firefox or Dolphin.

Details are here:  http://blog.metasploit.com/2011/01/mobile-device-security-and-android-file.html

Josh More | Senior Security Consultant - CISSP, GIAC-GSLC Gold, GIAC-GCIH
Alliance Technologies | www.AllianceTechnologies.net<http://www.AllianceTechnologies.net>
400 Locust St., Suite 840 | Des Moines, IA 50309
515.245.7701 | 888.387.5670 x7701

Blog: Not The Usual Security Predictions: 2011
http://www.alliancetechnologies.net/blogs/morej

How are we doing? Let us know here:
http://www.alliancetechnologies.net/forms/alliance-technologies-feedback-survey

_______________________________________________
Cialug mailing list
Cialug at cialug.org<mailto:Cialug at cialug.org>
http://cialug.org/mailman/listinfo/cialug




--
Matthew Nuzum
newz2000 on freenode, skype, linkedin, identi.ca<http://identi.ca> and twitter

"An investment in knowledge pays the best interest." -Benjamin Franklin

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://cialug.org/pipermail/cialug/attachments/20110120/64e2f380/attachment.htm 


More information about the Cialug mailing list