Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations //

Identity & Access Management

3/11/2015
03:15 PM
Connect Directly
Twitter
RSS
E-Mail
100%
0%

DroppedIn Vuln Links Victims' Androids To Attackers' DropBoxes

DropBox released a patch quick, but unpatched vulnerable Android apps that use the DropBox SDK may let attackers open up a two-way highway between victim Droids and their own Boxes.

Researchers at IBM X-Force have discovered a vulnerability in the DropBox software development kit (SDK) for Android that allows attackers to connect a victim's Android apps to an attacker's own DropBox account. The "DroppedIn" vulnerability affects any Android app developed with the DropBox SDK versions 1.5.4 through 1.6.1.

The flaw is in the implementation of the authentication mechanism used to give the app access to DropBox. It's supposed to work like this: while the user is providing their username-password combo to log in, the SDK is generating a large random number (a cryptographic nonce) to authenticate the device to DropBox. The trouble is, the proof-of-concept exploit the researchers have created "lets attackers insert an arbitrary access token into the SDK, completely bypassing the nonce protection," as they explain.

A victim could either be tricked into downloading a malicious app or infected via drive-by download. Either way, once the device is infected, the attacker has an open path from the victim's Droid to the attacker's DropBox -- through which the attacker could steal sensitive personal data and files from the device. This access would also go in the opposite direction -- the attacker could push out their own DropBox files, including malware.

To clarify, this exploit would not be a problem for the DropBox documents a user adds from their desktop machine, just files and data residing on their Android device. 

Fortunately, DropBox has already released a patch -- just four days after they learned of the vulnerability. Plus, if the DropBox app is installed on the user's Android device, then the SDK vulnerability cannot be exploited anyway. 

The trouble, of course, is that average users who don't use the DropBox app might assume they're not vulnerable. According to IBM X-Force, 1.4 percent of the top 500 Android apps use the DropBox SDK, including Microsoft Office Mobile and Agile Bits 1Password. 

Mobile malware is a growing problem, especially for Android. In a separate report released this week, Veracode found that the average global enterprise has approximately 2,400 unsafe applications in its mobile environment.

Of the unsafe apps Veracode studied, 85 percent expose sensitive device data, 35 percent obtain or share personal information about the user, and 37 perform suspicious security actions, such as "checking to see if the device is rooted or jailbroken, allowing applications to perform superuser actions such as recording conversations, disabling anti-malware, replacing firmware or viewing cached credentials such as banking passwords."

“On average, 3 percent of apps on employee devices are malicious," says Veracode vice-president of mobile Theodora Titonis. She is a bit surprised to find that 35 percent of apps were sharing personal information of the user. “That number is increasing.”

Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
3/12/2015 | 9:54:11 AM
Discover
Is there a quick way to determine if your phone is vulnerable? Scanning app from either drop box or android perhaps.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-8344
PUBLISHED: 2020-09-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2020-8347
PUBLISHED: 2020-09-24
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's browser if a crafted url is visited, possibly through phishing.
CVE-2020-8348
PUBLISHED: 2020-09-24
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's current browser session if a crafted url is visited, possibly through phishing.
CVE-2020-15850
PUBLISHED: 2020-09-24
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access the Nakivo Director web interface and gain root privileges. This occurs because the database containing the users of the web application and the password-recovery secret value i...
CVE-2020-15851
PUBLISHED: 2020-09-24
Lack of access control in Nakivo Backup & Replication Transporter version 9.4.0.r43656 allows remote users to access unencrypted backup repositories and the Nakivo Controller configuration via a network accessible transporter service. It is also possible to create or delete backup repositories.