what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Android Wipe Failure

Android Wipe Failure
Posted Mar 19, 2012
Site hatforce.com

Hatforce has discovered that the "wipe" function on Android does not reliably delete data on all devices. On a Nexus S running Android 2.3.6, they were able to recover user data after running a "wipe" both using the "factory data reset" from the menu and by wiping the device from recovery.

tags | advisory
SHA-256 | 59bc3a21027ec7b9d9d7d0f559c6aa74b0ff627bbfa549221a1f9ad1d3644ba5

Android Wipe Failure

Change Mirror Download
We have discovered that the "wipe" function on Android does not reliably
delete data on all devices. On a Nexus S running Android 2.3.6, we were
able to recover user data after running a "wipe" both using the "factory
data reset" from the menu and by wiping the device from recovery.

To recover data, the device must be rooted. This can be done after the
wipe by using e.g. the zergRush root exploit. (Note that the official
way which includes unlocking the bootloader must not be used - that one
does securely wipe the memory).

After rooting the device, the memory can be dumped using
cat /dev/block/platform/s3c-sdhci.0/by-name/userdata
Move the dump to a PC by piping the cat output into nc, then recover
using any common recovery software.

This means that if a locked device affected by this is lost/stolen, it
is possible to access the data by first wiping the device (to remove the
screen lock), then rooting and recovering.

Note that we do not know the full range of affected devices.
Manufacturers may have made customizations that fix this, and Android
3.x and 4.x (Honeycomb/ICS, about 5% of devices) seem to have fixes
according to the code.

The Android security team has been notified.

Further details can be found in our blog post:
https://www.hatforce.com/blog/android/wipe

Kind regards,
Jan, from the Hatforce team

Hatforce (https://www.hatforce.com) is the first crowd-sourced security
testing startup world-wide. The services comprise web- and mobile
application pentests. Since its launch, Hatforce got extensive positive
feedback, especially from the Forbes magazine: "This service is stroke
of genius! [...] This is a great business concept and one that could
make a huge difference in how safe your application, and brand, is."
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close