13.04.2015 Views

Android OEM's applications (in)security and backdoors ... - QuarksLAB

Android OEM's applications (in)security and backdoors ... - QuarksLAB

Android OEM's applications (in)security and backdoors ... - QuarksLAB

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Android</strong> <strong>in</strong>troduction <strong>Android</strong> <strong>security</strong> model Methodology Toward a backdoor without permission Post-exploitation<br />

SMS/MMS send<strong>in</strong>g <strong>and</strong> files exfiltration<br />

Vuln1 - SecMms.apk<br />

The malwares <strong>and</strong> premium SMS<br />

Current <strong>Android</strong> malwares ask for the SEND SMS permission<br />

Easily detectable <strong>and</strong> suspect for an user<br />

What about a malware which can send premium SMS without ask<strong>in</strong>g<br />

for permission?

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!