AirDroid app fixes severe authentication vulnerability
The problem was fixed in an update released last month, wrote Matt Bryant, a consultant with the security company Bishop Fox, who discovered the flaw. Versions 3.0.4 and earlier of the tool are affected.
AirDroid lets people manage their phone from a Windows or Mac tablet or through a Web interface. To do that, it asks for a lot of permissions, such as the ability to send text messages, turn on a camera and have access to the phone, among many others.
Bishop Fox found it could take over a device running AirDroid by sending a person a malicious link over SMS, Bryant wrote.
The vulnerable versions of AirDroid use JavaScript Object Notation with padding, or JSONP, to request data from a server in a different domain, Bryant wrote. Web browsers usually prohibit this as a security precaution known as the same-origin policy.
"Due to JSONP being an insecure method of sharing data across origins, it is possible to hijack all of the AirDroid application functionality," Bryant wrote. "By doing this, other users' Android devices can be hijacked."
A successful attack means a hacker would have full control over an Android device and can see the phone's contacts, track the device using GPS and transfer photos.
Bryant wrote Bishop Fox tested AirDroid's patch "and have found it more than adequate."
Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk