main
Report a problem

G1 cellular phone security bug

franzon   on 09 November 2008 - 00:26 · 2 comments & 1884 views

Advertisement (Why?)
This week a security hole was discovered in Linux-based G1 cellular phone Android 1.0 that allowed you to gain root access to the device.

The trick was that you have to start up a telnetd server on the phone, and then anyone who knows your IP address can log into the machine without a password to an administrator account.

When the phone booted it started up a command shell as root and sent every keystroke you ever typed on the keyboard from then on to that shell. Thus every word you typed, in addition to going to the foreground application would be silently and invisibly interpreted as a command and executed with superuser privileges.

News source: zdnet.com

Post a comment · Send to friend Comments · There are 2 additional comments
#1 +CrimsonRedMk on 09 Nov 2008 - 04:36
Google patched it already. This was also in Main News a few days ago.
#2 Airlink on 09 Nov 2008 - 14:16
Not much of a flaw. Who the hell runs a cell phone as a telnet server anyways??

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)