상세 보기
초록
Anonymous attackers have been targeting the Android ecosystem for performing severe malicious activities. Despite the complement of various vulnerabilities by security researchers, new vulnerabilities are continuously emerging. In this paper, we introduce a new type of vulnerability that can be exploited to hide data in an application file, bypassing the Android’s signing policy. Specifically, we exploit padding areas that can be created by using the alignment option when applications are packaged. We present a proof-of-concept implementation for exploiting the vulnerability. Finally, we demonstrate the effectiveness of VeileDroid by using a synthetic application that hides data in the padding area and updates the data without re-signing and updating the application on an Android device. Copyright © 2022 The Institute of Electronics, Information and Communication Engineers.
키워드
- 제목
- Hiding Data in the Padding Area of Android Applications without Re-Packaging
- 저자
- Jeon, G.; Yi, J.H.; Cho, H.
- 발행일
- 2022-11
- 유형
- Article
- 권
- E105D
- 호
- 11
- 페이지
- 1928 ~ 1929