Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,154,182 members, 7,821,996 topics. Date: Thursday, 09 May 2024 at 12:22 AM

Android Lockscreen Can Be Bypassed By Overloading With Massive Password - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / Android Lockscreen Can Be Bypassed By Overloading With Massive Password (2178 Views)

Security Firm Bypassed Iphone X Face ID With 3D Face Mask Model / Apple Iphone X Face ID Fooled And Bypassed By Security Firm Using A Face Mask / Post The Screenshot Of Your Lockscreen (2) (3) (4)

(1) (Reply) (Go Down)

Android Lockscreen Can Be Bypassed By Overloading With Massive Password by shegsrules(m): 5:32pm On Sep 16, 2015
A bug has ben found which allows anyone in possession of an Android smartphone running Lollipop to unlock the device by bypassing the lockscreen with a very long password.
The vulnerability, discovered by researchers at Texas University in Austin, potentially affects 21% of Android devices in use and requires the attacker to simply overload the lockscreen with text.
The bug affects only those users with smartphones running Google’s Android Lollipop using a password to protect their devices – Pin or pattern unlock are not affected.
The attacker need only enter enough text into the password field to overwhelm the lockscreen and cause it to crash, revealing the homescreen and giving full access to the device, whether encrypted or not.
John Gordon from Texas university said: “By manipulating a sufficiently large string in the password field when the camera app is active an attacker is able to destabilise the lockscreen, causing it to crash to the home screen.”
Google released a fix for the security hole on Wednesday for its line of Nexus devices, describing the bug as of “moderate” severity, but that it was not actively being exploited by attackers according to the company’s knowledge.
The researchers demonstrated the attack on a Google Nexus 4, and required the attacker to use the emergency call function to copy hundreds of characters to the clipboard. By using the camera, the settings pull down menu and prompting the password entry screen the long text string could be pasted into the password box causing it to crash.
The Guardian could not replicate the bug on a Google Nexus 6 or a Motorola Moto G – and entering that much text proved difficult and time consuming.
About 20% of the billion or so Android devices across the world run Google’s latest version called Lollipop, including new devices from Samsung, LG and Sony.
These devices will require a software update to fix the bug, but users will have to rely on the manufacturer of the smartphone and their mobile phone operator to roll out the update, rather than Google directly.
The attack requires physical access to the smartphone, and cannot be performed remotely. Users worried by the attack can change their lockscreen preferences to a pattern unlock or Pin code, which can be up to 16 characters long, instead of a password.
After the Stagefright security vulnerability, Google, Samsung, LG and other Android smartphone manufacturers recently pledged to release monthly security updates for their latest devices, in an attempt to help prevent this kind of attack being used.


http://www.theguardian.com/technology/2015/sep/16/android-lockscreen-password

1 Like

Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by ademega(m): 5:53pm On Sep 16, 2015
technology sha
Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by Whizpeter(m): 7:34pm On Sep 16, 2015
Hackers always have their way of bypassing things

2 Likes

Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by Nobody: 11:43pm On Sep 16, 2015
Buffer Overflow.
Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by dxpat4reel: 4:53am On Sep 17, 2015
pls be aware of this. There is always a bug in every software or operating system.... Thats why dey keep upgrading
Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by GrAnDwEeZ(m): 6:29am On Sep 17, 2015
I jez tried it. Didn't unlock. Or how long should the text be, cuz I tried ova 100letters
Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by Thayay(m): 6:49am On Sep 17, 2015
I tried it on my phone with almost 300 letters.... Didn't work
Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by Youngpo413: 7:19am On Sep 17, 2015
Windows rocks

1 Like

Re: Android Lockscreen Can Be Bypassed By Overloading With Massive Password by Nobody: 8:47am On Sep 25, 2015
huh.... I no dey lollipop

(1) (Reply)

Can Airtel N300 Social Plan Power Youtube? / What Music App Is Best For Android For Music Lover / Samsung A80 To Win Best Camera Smartphone In 2019

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 17
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.