USB Connection Vulnerabilities on Android smartphones
André Fernando Lopes Pereira · Open Repository of the University of Porto (University of Porto) · 2014
In this work, we enumerate a series of vulnerabilities in the USB connection of Android, specially vulnerabilities related with the customization done by the Android manufacturers. The crux of the discovered vulnerabilities is a consequence of the vendor customization of Android, where the serial AT commands processed by the cellular modem are extended to allow other functionalities. With this, we are able to flash a boot partition on the smartphone and obtain several objectives, including root access. These found vulnerabilities allow us to develop several attack vectors, which are ordered according with its efficacy, the objective in building an hierarchy that is able to produce the maximum efficacy attack according to the device. We develop a proof of concept and an attack scenario specially designed for USB attacks on Android. We made some tests with popular anti-virus for Android, to examine if they can prevent or detect the attacks. Finally, we develop an application capable of mitigating the discovered vulnerabilities, unfortunately the application needs root access to be activated. In case there is no root access, we prompt a warning to the user, notifying the dangers he may be in.