Black Hat 2011

   
Black Hat 2011:
Android attacks and smartphone privacy leaks
February 25, 2010
In this video from the Black Hat 2011 security conference, Neil Daswani, CTO and co-founder of Dasient talks about his conference presentation. Daswani and his team demonstrated a drive-by attack on Google Android smartphones using a vulnerability in Webkit and a coding error in Skype. The exploit bypasses the Android platform sandboxing security features, allowing an attacker to take complete control of the smartphone to steal contact information, account credentials and other sensitive data. While the hole used in Webkit has been patched, Daswani believes more weaknesses exist in the browser engine. In addition, Daswani explains the results of his team’s behavioral analysis of more than 10,000 Android applications. The study found widespread privacy leaks.