ADB Backup APK Injection

Discussion in 'News Aggregator' started by Packet Storm, 11 Jul 2015.

  1. Packet Storm

    Packet Storm Guest

    The Android ABD utility backup manager, which invokes the custom BackupAgent, does not filter the data stream returned by the applications. While a BackupAgent is being executed during the backup process, it is able to inject additional applications (APKs) into the backup archive without the user's consent. The BackupAgent needs no Android permissions. Upon restoration of the backup archive, the system installs the injected, additional application (since it is part of the backup archive and the system believes it is authentic) with escalated privileges. Proof of concept code included.

    Continue reading...
     

Share This Page

Loading...