用于验证 CVE-2015-6606 的简单漏洞利用程序
这是一个简单的漏洞利用程序,用于验证 SEEK 智能卡服务 3.1.0 及以下版本中存在的代码注入漏洞(CVE-2015-6606,Google 内部缺陷编号 ANDROID-22301786)。该漏洞允许特制的 Android 应用程序包将任意代码注入到智能卡系统服务的执行上下文中。这些代码会继承授予该系统服务的所有权限,其中包括通常不会授予第三方应用的签名级或系统级权限。
更多详细信息请参阅我们的报告 Executing Arbitrary Code in the Context of the Smartcard System Service(见下方文献部分)。
免责声明
您使用此应用程序需自行承担风险。我们对因本应用程序、错误使用或本手册中的不准确之处所造成的任何损害概不负责。
文献
- CVE-2015-6606
- Google: Nexus Security Bulletin - October 2015
- M. Roland: "Executing Arbitrary Code in the Context of the Smartcard System Service," arXiv:1601.05833 [cs.CR], Computing Research Repository (CoRR), arXiv.org/corr, University of Applied Sciences Upper Austria, JR-Center u'smile, January 2016.
- M. Roland and M. Hlzl: "Open Mobile API: Accessing the UICC on Android Devices," arXiv:1601.03027 [cs.CR], Computing Research Repository (CoRR), arXiv.org/corr, University of Applied Sciences Upper Austria, JR-Center u'smile, January 2016.
License: GNU General Public License v3.0