Уровень 0 · материалов: 4
В кластер входят документы, описывающие уязвимости смартфонов и мобильных модемов, и не входят документы об уязвимостях операционных систем общего назначения (Windows, Linux).
Общие признаки: безопасность Android, атаки через USB, компрометация мобильных устройств, аппаратные уязвимости
Группа выше: Атаки на мобильные устройства и периферию
Смысл: The main idea is that legacy communication protocols (AT-commands) can be exploited to bypass modern Android security and remotely control devices via USB, proving that architectural flaws in hardware can override software-level protections.
Researchers found a way to remotely control Android phones via public USB chargers using undocumented AT-commands to bypass lock screens and simulate user input.
Смысл: The main idea is to demonstrate how a cheap microcontroller can be programmed as a HID device to perform an automated 'BadUSB' attack, gaining remote access to a Windows machine in seconds.
A tutorial on building a low-cost USB Rubber Ducky clone using Arduino and Metasploit to execute rapid, stealthy remote access attacks on Windows computers.
Смысл: The text describes a security vulnerability in Android smartphones where researchers used extreme cooling (freezing) to preserve data in RAM, allowing them to perform a cold boot attack and extract encryption keys and private user data.
Researchers demonstrated that freezing an Android phone can preserve encryption keys in RAM, allowing them to be extracted via a custom bootloader.
Смысл: The main idea is that widespread vulnerabilities in 4G USB modems and SIM cards allow remote attackers to compromise both the mobile account and the host computer, posing a significant risk to individual users and critical infrastructure.
Positive Technologies revealed that most 4G USB modems and 20% of SIM cards are vulnerable to attacks that can lead to full computer takeover and traffic decryption.