Android phones can be hijacked by malicious text messages - G4 General

Anybody worried about this new one?
http://arstechnica.com/security/201...s-can-be-hijacked-by-malicious-text-messages/

That is a pretty worrisome bug. Not just it's a security issue, but also probably there will be an OTA update soon, which might ruin all the hard work people have done recently to get root!
I wonder why there doesn't seem to be an update for Hangouts to fix this? Is that not where the actual bug is?

I was just surprised there are not more people talking about it.

i just read about this yesterday

From what I have read, you can avoid the problem by disabling automatic download of multimedia content. Uncheck "Auto-retrieve MMS" in settings if you are using hangouts for text messages. The verizon messaging app has a similar option. If you get an MMS message from an unfamiliar source, delete it without opening.

I heard it on npr couple days ago. Problem in using hangouts as your default sms mms is that it preproccess video sent via mms thus auto infecting. Atleast with default messaging app you have to actually open the message.

We need updated stagefright .so files we can drop in /system/lib(64)/hw
That's where the defect is. It's in the binary not in an apk.

I don't claim to know the details of this vulnerability.
I'm using the stock LG Messaging app (yellow icon). But for peace of mind, if nothing else, I set it to not auto-retrieve multimedia messages. At least if I get one from an unknown source, it would give me a way to delete the message without a risk of downloading it.
For all of Android's advantages over iOS (and I feel it's a better system, at least for what I want from a device), the fragmentation and multiple layers between a possible Google patch, and it getting to consumers (Google->manufacturers->carriers, for a lot of us) definitely adds to the challenge of fixing this quickly.

Related

The Sprint Hero Lost SMS Debacle

I was all set to finally take the plunge and sign a contract with Sprint for the new Hero - just waiting for my prepaid cellphone account to run out of money. Now more and more reports have started coming in about the Sprint Hero and its issues with losing SMS, and possible MMS too. Some sauces:
Engadget's questioning > and the scary responses: http://www.engadget.com/2009/10/26/htc-hero-having-intermittent-text-messaging-problems/
Sprint Community's ongoing thead: http://community.sprint.com/baw/thread/22913?tstart=0
SprintUser.com's ongoing thead (there are many): http://www.sprintusers.com/forum/showthread.php?t=195769
Slightly older but still the same problem from here from XDA: http://forum.xda-developers.com/showthread.php?t=572134
A few observations (feel free to add your own):
-UK/GSM Hero users are experiencing this, though to a much lesser extent
-A common, but not completely sweeping assessment is that affected users are using task killer programs or did at one time, even before a hard reset
-Soft resets tend to help the problem, though only temporarily (for some)
-People are getting the same issues on brand new phones that they exchanged for old ones.
Any thoughts? Do you have any personal experiences with this? I'm hoping to hold out till HTC/Sprint releases a patch or some sort of announcement about this problem but in the meantime, what has your experience, as a CDMA/Sprint Hero user, been like in regards to losing/delayed SMS and MMS messages?
From my experiance running Hero on the G1 lost text messages were due to the messeges app failing due to many things running and causing it to crash.
I can't speak for the sprint Hero, though I have not experienced any lost text messages I am aware of.
Maybe its a network issue?
I actually experienced it once. From what it appears, I downloaded a task manager and selected to kill all running apps. After I rebooted my phone though I have yet to experience any text message loses. Originally I was blaming it on a 3rd party messaging service, however now I really think it was as a result of killing the messaging app. This happened about a week and a half ago and so far *knocks on wood* have not experienced any other issues. Aside from that, I still love my hero. I honestly think that it is the best phone I have ever owned.
My biggest issue with SMS messages is that I've had up to a 3-4 minute delay between the timestamp on the message and when i get the notification. But AFAIK, I haven't lost any messages.
I think its a great phone so far. If Android keeps picking up as it appears to be, I think it can trump apple and iphone.
I have not lost any texts. I tested with texts to and from different carriers and area codes. I have not run any task killers. For what it's worth, I have not had any of the battery problems that people have run into either.
i had lost all of my SMS messages on my Sprint Hero after i installed Handcent SMS and used it for a couple days ( which so happened to be exactly a week after i bought the phone the messages were gone)
your sms's are still there, but they are in your messenger app, handcent doesn't access stuff that's already there, just the new stuff comming in. I don't belive it's possible to import the sms's that are already there, or at least there's not a known procedure on how to do so.
you can access them if you pull up your original messenger app, just no way to import/export. Sorry, probably not the answer you were looking for, but it is the correct one.
I had this problem when I first got my Hero, no text messages were being received, third party SMS app or not. My Hero said 'with Google' on the back. I exchanged it for one that just says 'htc', haven't had the problem since.
im worried
ive had the phone for 2 weeks.three days later i got the dreaded calls from friends and girlfriend that i havent been answering back to text. ive installed handcent sms and smstomailbox. from then on the problem has stopped.although i have sent myself some text and im yet to receive them no one has told me they cannot contact me. i just moved to sprint because i recently got a job as an assistant. my boss contacts me strictly through text. (you can imagine the magnitude of this issue) after all the forums ive read, i dont know what to do regarding this. my 30 days is almost up. i cant imagine a patch is not already on the works, but ive read this has been a known problem for some time. with Htc pumping out phones by the dozen and 1.6. / 2.0 updates taking the spotlight, i wonder if i should return my phone. the phone is real nice and i dont want a flimsy pre. seems too much stress for a device you pay good money for.i have the sprint hero with the "with google" in the back. seems like a bad time to get a phone with sprint since theres no news on wether this phone will be upgradeable or patched and the other phones are going to get upgraded soon. (HD2)
!!!
on another thread someone posted that the problem had been acknowledged . the post pointed to a flaw in the sms app that did not send a "memory full" notification back to the sms database server. so it seems theres a limit to the sms app capacity and it kinda locks down or something along those lines. lol (sorry ill post the link when i find it again) in other news 2.0 is coming to the hero. so i guess ill deal with the issues till then.
I purchased a Hero on launch day [early run device, without 'with Google' branding, only 'HTC' on the back cover] and quickly encountered the intermittent text message delivery debacle.
Bottom line, there were extended periods of time in which text messages being sent to me were simply not appearing on my phone. [Side note, this includes individuals both on and off the Sprint Network.] Turning the phone off and on usually alleviated the non-delivery / appearance problem but any messages sent during that time were gone. There was no flood of messages post restart.
I should note that on two occasions I did notice that I had received a text in the top notification bar but when I opened the Messaging App, the text was no where to be found.
It appears that the messages may indeed have been delievered... but the app is 'eating' them, so to speak. This *could* explain why on Sprint's end, everything looks fine on the network... or so I was told, which I believe.
My temp solution, as advised by forum / discussion posts by other Hero users was to install an alt Messaging App [I used Handcent SMS] and use this rather than the stock Messaging app. Additionally, I added 'SMS To Mail Lite' which forwarded a copy of my incoming texts to an email address. I experienced no intermittent outages / delivery failures / abductions at all. Both Handcent and the email inbox matched. While this 'worked' I was unable to replicate the bug but since I was using Handcent this might have been why.
Later, after spending some time on the phone w/Sprint Advanced Tech Support, they determined it was not a network issue and was due to the phone itself [as their system showed all my messages being delivered]. They set up a trouble ticket and I was able to swap my Hero for a new one at my local store. Caveat, I was still under the 30 day trial which made things much easier when I got to the store.
I was told by Advanced Tech Support that HTC has recognized this intermittent text delivery issue and they are working on a solution. I only mention 'Advanced' b/c the first individual I spoke with from regular Text Messaging Support had zero knowledge of this issue and was quick to deny any problems whatsoever. No one at the store knew anything about it either, but I wasn't expecting it. So if you speak with anyone at Sprint, expect that they might not know yet and be nice. You might even get a replacement phone.
Currently, I'm still using Handcent and really like it. Tried ChompSMS but just prefer the other. They're on par w/one another so be sure to check them both out if you prefer to go this route. Also, I used the 'My Backup Pro' app to restore my new phone to the original configuration. Certainly worth the $5.
Hope this helps.

[Q] SMS Random Selection Bug

I've been reading about this bug for awhile now and it finally hit me. What happens is if contact A sends you a txt message and you respond. The message thread will show that your response went to contact A, but the reality is that A may not have received the response, however C,D,E,F, Z,Y and X did! It seems to be totally random, will happen regardless of the SMS app or ROM you use and can be quite dangerous. This bug renders my N1 virtually useless. Anyone else experience this or has an update on the fix for this dangerous bug?
I recommend anyone with an Android phone to be use extreme caution when sending txts or mms messages as you never know who may actually get it
Have read about it, but it's never happened to me.
Can you reproduce the bug reliably?
Can you dump the logs (/proc/kmsg and logcat, or bugreport) immediately after it happens?
Any pattern connecting recipient A and the rest?
Nightmare!
Sent from my Nexus One using XDA App
How come that not even one person from those reporting having "this bug", wants to help find out, what it is? Very interesting.
I have found that using handcent resolves this problem for me.
Sent from my Nexus One using XDA App
My wife have experienced the problem twice with Galaxy S, I haven't have similar troubles with my N1, although every now and then it takes time for some messages to go through. That is probably due the carrier, not the device.
Sent from my Nexus One using XDA App
The only trouble with messaging i have is that sometimes when i select to open the thread at the top of the list, the one at the very bottom of the screen opens. Frustrating!!!
cymru said:
The only trouble with messaging i have is that sometimes when i select to open the thread at the top of the list, the one at the very bottom of the screen opens. Frustrating!!!
Click to expand...
Click to collapse
I have this too in a pre 6.1 nightly...
But it's not the first time i hear the bug that SMS are sent to everyone, so it definitely exist
Sent from my Nexus One using XDA App
I saw the "reports" on the net popping up once in a huge while, but I never saw anyone that would report this bug and actually try to solve it, or assist anyone in solving it. Doesn't look like a normal bug report to me, and doesn't look like there is a bug. I know over 15 people with all kinds of Android, at least 6 with Nexus, and it never happened to anyone. The "bug" looks very fishy.
Jack_R1 said:
I saw the "reports" on the net popping up once in a huge while, but I never saw anyone that would report this bug and actually try to solve it, or assist anyone in solving it. Doesn't look like a normal bug report to me, and doesn't look like there is a bug. I know over 15 people with all kinds of Android, at least 6 with Nexus, and it never happened to anyone. The "bug" looks very fishy.
Click to expand...
Click to collapse
I can assure it is a bug and a major one. It is well documented if you google it. It appears to be across many different hardware platforms and therefore is most likely a source code issue written incorrectly in the android OS. And just because the 15 people you know aren't having the issue does not mean the rest of the world isn't. This is my 3rd android phone and this is the only one that does it and from I've been reading there are many others who are also having this random issue...I assure you, this isn't something that someone can do by mistake or accident...
In that case, if it's so well documented, how come that nobody has ever assisted anyone else in debugging it, yourself included?
It's happened to me.
I receive certain friend's facebook updates as sms. One time I got the facebook sms. I closed it then replied to another friend's sms. Guess what happened.... what I sent to my friend got sent as a comment to my friend's facebook status.
Looking back at the sms log, I definately wrote my reply to my friend, not the facebook sms, but somehow it was replied to the facebook sms.
This bug has been around since Android existed.
There's really no way to debug this I don't think, unless you only have a few contacts that will text u if you write something weird... cuz having a phone full if phone numbers, your text can be sent to any number, even non mobile phones, you wont know since you thought u texted the right person.
Sent from my Nexus One
There's a ton of ways to debug everything, including even specifically modified SMS app for dumping debug data - it's an open OS, yes? If I got some beta application versions for debugging from app devs to test things, I'm sure Google wouldn't do less to debug it.
For starters, the next SMS I'll check the records in kernel log and see if there's any useful data to start from there.
Jack_R1 said:
In that case, if it's so well documented, how come that nobody has ever assisted anyone else in debugging it, yourself included?
Click to expand...
Click to collapse
Well I think you bring up two entirely non-related issues... First, if you google it, you will find a vast amount of people all having that same issue, which in my mind establishes the "well documented" part of my statement. Secondly, as far as me or anyone else participating in debugging, I would love to, but it's a little out of my sphere of knowledge. If you could give me a little insight into what needs to be done, I would be more than happy to do what I can to help solve the problem. This $500 phone is totally useless to me if I can't be certain who will be receiving my txt messages. Mainly, I've been waiting and watching in the hopes that google would get involved and resolve this issue without my having to get involved. It would appear that this goes back a considerable amount of time.
Can you list out a step by step process to go about this so that all who are having this issue can also participate? What should be my next step
To even try to start with debug, you have to have a rooted phone.
The useful place to look at would be /proc/kmsg. The question is - how much data it contains after sending sms. I didn't try to dump it after SMSing yet, didn't have time for it. I'll try to find time over the weekend.
If it won't contain enough data, modification in SMS application is needed, to dump the data there to help with debug. This is much harder for me, because I'm not an app dev, and I'll have a hard time trying to find and understand the relevant data structures to dump there. Basically, when you hit "reply", some kind of indicator of current SMS thread needs to be dumped, and everything else that might result in wrong number being selected - all the chain that determines the number that the SMS goes to. Then, once the SMS was sent to wrong recipient, the info needs to be dumped and checked.
The later part is "slightly" beyond my skills. It requires knowledge of SMS application and its data structures.
It obviously happens only to those that have their Facebook contacts integrated, so the mechanisms that take care of joined contacts might be something to look at.
It never happened to me, and I've sent 12000 sms from my Nexus. Try using Handcent until this is officially fixed. Handcent is free and many people say it's not affected by the bug.
Jack_R1 said:
To even try to start with debug, you have to have a rooted phone.
The useful place to look at would be /proc/kmsg. The question is - how much data it contains after sending sms. I didn't try to dump it after SMSing yet, didn't have time for it. I'll try to find time over the weekend.
If it won't contain enough data, modification in SMS application is needed, to dump the data there to help with debug. This is much harder for me, because I'm not an app dev, and I'll have a hard time trying to find and understand the relevant data structures to dump there. Basically, when you hit "reply", some kind of indicator of current SMS thread needs to be dumped, and everything else that might result in wrong number being selected - all the chain that determines the number that the SMS goes to. Then, once the SMS was sent to wrong recipient, the info needs to be dumped and checked.
The later part is "slightly" beyond my skills. It requires knowledge of SMS application and its data structures.
It obviously happens only to those that have their Facebook contacts integrated, so the mechanisms that take care of joined contacts might be something to look at.
Click to expand...
Click to collapse
This is why I haven't, as you say, participate in resolving the issue...the level of of debugging required to get to the source of the problem is deeper than a non-developer like myself can go. And for the record, this is NOT related to the facebook app in anyway as I do not even have that app installed. This is 100% an Android code issue...
Are all your contacts Gmail-synced contacts?
Does it happen frequently enough to try to debug?
This is what happens with my N1:
I get a new text message, alerted in my notification bar
Rather than open it from the notification bar, I open the messaging app and tap the first message (just a habit, I guess)
The ninth message opens instead of the first one​
I'm not sure if this happens every single time, but it does happen frequently.
I'm wondering if it might be a bug in CyanogenMod instead, I've only started noticing it recently.
PS: I do not have a Facebook account nor any accounts synced with it. The only contacts I sync are my Google contacts.

Exchange Services - SmsRelayService HELP!!!!!

Someone please help! Having read the very little amount of content I can find so far, I am extremely concerned that somehow some or all of my text messages are being relayed to an email account via the Service (SmsRelayService) that is running under the app Exchange Services.
I don't seem to be able to find anything conclusive, but what I have found is that it is likely to be relaying text messages to an Exchange Account?
I can stop the Service and it stays 'stopped' until a text message is received and it starts running again.
Now have a Note 4, having upgraded because my last handset appeared to have been tampered with and was also behaving in this manner, as well as my Google Location History recording me in places that I never was. On that handset there were even more questionable apps running, one of which appeared to be some form of spyware when searched in Google!
Is there any way that you can dig deep into the operating system of the device and see what is going on?
Is there any way of identifying is my suspicions and those of others that I have seen post similar stories are correct?
One of the reasons I started to question it initially and then look into it was because I was receiving overly descriptive and some unnecessary text messages from someone and at the same time, another device nearby was demonstrating email notification sounds!
Not only that, but certain things that I had not discussed with certain people, but had discussed over text with others (in no way related or connected) were being brought up!
Help please.... is SmsRelayService under the app Exchange Services something to be worried about?????
I was also shocked by the lack of information on this "SmsRelayService" There are tunz of questions out there about it.
After much research and messing with my phone I feel the service is stock BUT can be hijacked by some unknown application to send all texts to a 3rd party. My x was getting my text messages somehow. In her email account i found she had set up a service on her own phone first to test and she would receive every text on the phone and also location. I assume she set it up on her own phone first to figure it out then she put it on my phone. I have a rooted phone with a custom rom. strangely the SmsRelayService had permission for EVERYTHING on my phone. From sms to photos and every single admin right possible. I doubt this is normal for that service. my custom Rom has a "App ops" menu that shows what the service has used or not. In my case it looks like she was only accessing my sms messages. Killing the service did not help as when a new text came in it started back up and accessed the new messages. Once i removed all the permissions for "SmsRelayService" in the "App ops" menu i no longer had the problem of the service accessing the texts. Without this menu option i don’t know how i would have stopped it. I'd assume there is an app or process killer out there that would have been able to shut it down but it'd take someone else with a normal rom to let us know.
in my case I’m lucky it was only sms's. It looks as though whatever she put on my phone was only getting sms's. the app having access to all rights on the phone a better or more in depth spy app/program could have accessed much more. Only spying my sms activity i did not notice ANY extra battery drain. Also this app is known with Microsoft exchange and that messes up a lot of the research. I have never setup any other account but a gmail account so without a link there i don’t know why else it'd been activated in the first place if not for a spy app. I'll try and post back in a few weeks after i'v been able to see if she suddenly doesn’t have information that she shouldn’t know.

SMS limit removal

I send out the same text to a group of people quite often and I get a message saying messenger is sending a large amount of messages do you want to allow this? I have to click on it for each message that goes out. Is there any possible way to change the limit? I know you used to be able to set it to anything you want in settings/security but it's not there anymore. Any help would be greatly appreciated...this is so annoying.
Have you tried GoSMS Pro?
Maybe I've never sent to as many as you, but I've never encountered that warning or behavior. I've used GoSMS for several years.
I've only seen this when I send many messages in quick succession (either with Google Messenger or something like Tasker). There should be a checkbox that says to always allow.
I'm also looking for a solution. I was using ResurrectionRemix (a CM based ROM) and it has an option to set the text restriction. So, it CAN be done. We just need to know WHERE the code is so that it can be changed. I can't find any search results explaining how to accomplish this. That SMS Limit Unlock app doesn't work on later ROMS.
After hours of searching today - it appears that the setting has been moved into the framework?
com.android.internal.telephony
https://android.googlesource.com/pla...geMonitor.java
I hope I'm wrong as I'm no Android dev.... But, if I'm correct the only way I know of to "fix" it is to make the change in a custom Android build/ROM.
This SUCKS as I use mass texting for business purposes (communicating with many individuals who sign up for contract work). I really like Android N (along with AndroidPay) - but, looks like I'll be going back to M (on a custom ROM)...
If anyone locates/determines a way to alter that file using RootExplorer/Sqlite or some other way - please let me know.

3rd Party Messaging Apps will not receive text

Hello All!
I've been having this problem for a few weeks now and im all out of ideas of what to do.
Carrier: T-Mobile
Wearable: S3 Rugged
Extra Service: DIGITS
Coming From: LGV20 which never had these issues with the same plans and accesories
So to start, when i got the phone inittially during setup of the google accounts i noticed that my OTP SMS Pushes were not being received, or auto filling the information. I skipped past all of that and noticed that anywhere that OTP text were suppose to autofill in different applications, it would not even when i received the text and got a notification.
So after a while of using TEXTRA which was working fine, one day i stopped receiving ALL text not just mms. I was able to send but never was I able to get anything from anyone. I ditched TEXTRA and went back to the stock Samsung app and noticed that all text were there, even though it was not default. After using the Samsung messages app i decided to go back to textra, heres whats funny. After Textra did it's initial setup, it only showed half of the recieved text from up to that day. Messages were incomplete, some just had one reply from a user and nothing else. So I also tried this with Android Messages and it had the EXACT same message log as textra. Both were not receiving the full logs from the server. Today Android Messaging was working for a good part of the day, then it just stopped all of sudden again.
Can someone help me with this, I've wiped the cache and factory reset the phone. Ive added and removed the multi-line settings in the samsung settings. I've tried the legacy settings on textra. I've called the DIGIT's customer service to see if they could fix it but they made and interesting point that it couldnt be digit because it wouldnt interfere with 3rd part messaging apps. When i switch apps i always make them default, i wipe the app cache etc.
I have a gut feeling this has something to do with something with the default Samsung Messages app and it somehow restricting use outside of it.
I just wanted to reply and say that I've been experiencing the exact same issue and haven't had any luck Google engineering my way around it. For me, I'm seeing the issue with Signal, so I don't believe it's the 3rd party app's problem. I can send messages (SMS/MMS), but the Samsung Messages app is the only one that "receives" them. A strange workaround I found was to download Android Messenger, set that as the default messaging app, then set Signal as the default messaging app again. This worked for a while, but I think the Samsung Messages app recently updated, and it broke this again until I repeated the above workaround.
It's annoying enough that, without a fix, I'll definitely be flashing a completely stripped ROM on this phone once we have the ability to do so to get away from all of the Samsung apps that I can't disable. And don't even get me started on Bixby...
wjm3982 said:
I just wanted to reply and say that I've been experiencing the exact same issue and haven't had any luck Google engineering my way around it. For me, I'm seeing the issue with Signal, so I don't believe it's the 3rd party app's problem. I can send messages (SMS/MMS), but the Samsung Messages app is the only one that "receives" them. A strange workaround I found was to download Android Messenger, set that as the default messaging app, then set Signal as the default messaging app again. This worked for a while, but I think the Samsung Messages app recently updated, and it broke this again until I repeated the above workaround.
It's annoying enough that, without a fix, I'll definitely be flashing a completely stripped ROM on this phone once we have the ability to do so to get away from all of the Samsung apps that I can't disable. And don't even get me started on Bixby...
Click to expand...
Click to collapse
I haven't had any issues with my At&t model...Been using Yaata since day one (about 2 months).
Also, there are some "package disabling" apps in the play store that will allow you to disable any app you want, you don't even need to be rooted. It cost me $1.99 (or around there), but was well worth it! You can even completely disable Bixby, so the button is even non-responsive.
Having the same issue and I may have fixed it. I logged completely out of Digits on the phone (settings/cloud accounts/multi line/hit the ... menu and choose log out.
I have this same issue. No matter which 3rd party SMS app I use I have missing text messages on the T-Mobile S8. Has anyone fixed this? It is driving me crazy. T-Mobile replaced my S8 and the new one does it (not as bad but it does it more than I'd like). How can I resolve this? My friend haf the same issue, he has an unlocked T-Mobile working on AT&T.
I don't use Digits or anything like that... any ideas?
hi guys
all you need to do
go to setings
device maintence
battery
scrool all the way down to unmonitored apps and add your 3rd party sms app
youre welcome
This still didn't work for me and I am having the same exact issues. I have tried installing 2 different 3rd party messaging (Textra and Mood) and both were not working properly. I can send messages out just fine but when I receive them they are delayed (like 5 minutes or longer). Sometimes, I don't get the messages at all. Of course, the Samsung Messaging app (which I hate) works just fine. I have even "Force Stopped" it! What to do?
go into the stock messaging app, and turn off advanced messaging
Has anyone found a solution? I've been using textra for years & suddenly in March I started having this problem but with sent messages. All incoming texts are displayed but my sent texts aren't. I did try the 2 suggestions above. On a note 8, Android 8.0.0,Samsung experience 9.0.
SOLVED. I had the same issues and found the solution. Before you install your 3rd party sms/MMS you need to disable the default messenger. I uninstalled signal, disabled the built-in messenger, reinstalled signal. Now I can receive texts. Also my phone is not a Samsung.

Categories

Resources