Rabu, 26 September 2012

Just Clicking a Link Could Wipe Some Android Phones

Did you know there's an 11-digit code that can wipe certain phones from the dialer? It looks like this:

It's actually an intentional feature, which uses the USSD protocol mobile operators use to provide basic services through their phone networks. One of those services, which certain phones enable and others don't, is a hard-reset of the phone.

The problem: some Android dialer apps will execute these codes straight from the browser, without user confirmation. So just clicking on a link like this or scanning a malicious QR-code could wipe your phone.

Scary stuff.

The source of the problem was a bug in the Android dialer, which was actually fixed several months ago. Samsung, whose flagship GS3 was temporarily thought to be the only phone with the problem, told the Telegraph that its most recent software update fixed the issue. But depending on carrier and manufacturer, the fix hasn't made it to all Android devices. Samsung's Galaxy S2 and S Advance and some HTC and Motorola phones still appear to be vulnerable.

Wondering if you're at risk? This site will test your phone by executing a different (harmless) USSD code. If you are vulnerable, we recommend downloading any available updates and (if you're still vulnerable,) an alternative dialer app. And keep your phone backed up.

Jon Fox is a Seattle hipster who loves polar bears and climbing trees. You can follow him on Twitter and IGN.


Source : feeds[dot]ign[dot]com

Tidak ada komentar:

Posting Komentar