DEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android Vendors @HackersOnBoard
DEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android Vendors  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 18 minutes ago
Nearby sharing apps are very convenient and fast when you want to transfer files and have been pre-installed on billions of devices. However, we found that most of them will also open a door for attackers to steal your files and even more.

First, we did a comprehensive research about all top mobile vendors' pre-installed nearby sharing apps by reverse engineering. Many serious vulnerabilities are found on most of them and reported to vendors. Algorithm and design flaws in these apps can lead to file leaking and tampering, privacy leaks, arbitrary file downloads and even remote code execution. We will present all the related vulnerabilities' details and exploit techniques. Next, we conducted the same research on lots of third-party file sharing apps and found that they are even worse about security and are used by surprising more than 1 billion users. Files transferred between them are nearly naked when our MITM attack devices are nearby. Finally, we will summarize all the attack vectors and two common attack models. We will also present the attack demos and related tools.

Besides, we will present our practical mitigations. Currently, we are working with most of the top vendors to mitigate these vulnerabilities. Through this talk, we want to notify users and mobile vendors to pay more attention to this serious situation and fix it better and sooner.
DEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android VendorsBlack Hat USA 2018 - Attacking Client Side JIT CompilersBlack Hat USA 2018 - Return of Bleichenbachers Oracle Threat (ROBOT)Black Hat USA 2018 Keynote Parisa TabrizDEF CON 27 - Hila Cohen - Malproxy Leave Your Malware at HomeDEF CON 27 - Behind the Scenes The Industry of Social Media Manipulation Driven by MalwareBlack Hat USA 2018 - Finding Xori Malware Analysis Triage with Automated DisassemblyBlack Hat USA 2018 - Your Voice is My PassportBlack Hat USA 2018 - Stop that Release, Theres a Vulnerability!Black Hat USA 2018 - SirenJack Cracking a Secure Emergency Warning Siren SystemDEF CON 27 - Alon Weinberg - Please Inject Me a x64 Code InjectionBlack Hat USA 2018 - I, for One, Welcome Our New Power Analysis Overlords
HackersOnBoard |

DEF CON 27 - Bug Finding And Exploit Techniques On File Transfer App Of All Top Android Vendors

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER