Skip to main content

Bug allows complete lock screen bypass on Samsung Galaxy S III


Following claims that the lock screen in the Galaxy Note II can be briefly bypassed, another Samsung owner has stepped up to claim that the bug goes much farther, and can allow full access to the device.
In a separate post on the Full Disclosure mailing list, Sean McMillian posted a variation on the method that the original discoverer of the bug, Terence Eden, had used to briefly access the home screen on his Galaxy Note II.
Instead of launching an application on the home screen, McMillian wrote that if an attacker locks the screen and then unlocks it again, the bug would allow full access to the phone.
McMillian also tested the device on three separate Galaxy S III devices, highlighting that the issue is likely more related to Samsung's software, rather than a widespread Android issue.
ZDNet was able to confirm the complete bypass on an S3 running Android 4.1.2, although the timing to replicate the issue is very small and difficult to replicate at first. Once bypassed, the bug appears to persist, even when the phone's screen is turned back off, no longer challenging the user for their PIN, password, or pattern.
ZDNet's tests on a Galaxy Note II running Android 4.1.1 confirmed the earlier brief bypass, but we could not replicate the complete bypass bug on this device.
Samsung has still not returned ZDNet's earlier requests to comment.
Eden also previously claimed to have contacted several Samsung relationship mangers and emailed the company directly, but after not hearing anything back for five days, he decided to release the information publicly.
For those wanting to verify whether their own devices are vulnerable, McMillian's instructions are as follows:
  1. On the code entry screen, press Emergency Call
  2. Press Emergency Contacts
  3. Press the Home button once
  4. Just after pressing the Home button, press the power button quickly
  5. If successful, pressing the power button again will bring you to the S3's home screen.
The flaw comes shortly after it was revealed that the lock screen in iOS 6.1 can be completely bypassed, again using the emergency call feature.

Comments

  1. This is how vulnerable is Samsung now for any one can easily bypass it......this is actually a treat when you have something that your hiding of for any one. After reading this news on this site i got worried. http://www.oneclickroot.com/android-security/samsung-galaxy-s3-bug-allows-anyone-to-bypass-the-lock-screen/

    ReplyDelete

Post a Comment

Popular posts from this blog

How to Hack a Website in Four Easy Steps

Every wondered how Anonymous and other hacktivists manage to steal the data or crash the servers of websites belonging to some of the world biggest organisations? Thanks to freely available online tools, hacking is no long the  preserve of geeks , so we've decided to show you how easy it is to do, in just four easy steps. Step 1: Identify your target While  Anonymous  and other online hacktivists may choose their targets in order to protest against perceived wrong-doing, for a beginner wanting to get the taste of success with their first hack, the best thing to do is to identify a any website which has a vulnerability. Recently a hacker posted a list of 5,000 websites online which were vulnerable to attack. How did he/she identify these websites? Well, the key to creating a list of websites which are likely to be more open to attack, is to carry out a search for what is called a Google Dork. Google Dorking , also known as Google Hacking, enables you find sen

How to Hack Facebook Password in 5 Ways

Check out the following post from  fonelovetz blog  on facebook account hacking. This is one of the most popular questions which I'm asked via my email.And today I'm going to solve this problem one it for all.Even though i have already written a few ways of hacking a facebook password.Looks like i got to tidy up the the stuff here.The first thing i want to tell is.You can not hack or crack a facebook password by a click of a button.That's totally impossible and if you find such tools on the internet then please don't waste your time by looking at them! They are all fake.Ok now let me tell you how to hack a facebook account. I'll be telling you 5 of the basic ways in which a beginner hacker would hack.They are: 1.Social Engineering 2.Keylogging 3.Reverting Password / Password Recovery Through Primary Email 4.Facebook Phishing Page/ Softwares 5.Stealers/RATS/Trojans I'll explain each of these one by one in brief.If you want to know more about them just

How to Hack Someone's Cell Phone to Steal Their Pictures

Do you ever wonder how all these celebrities continue to have their private photos spread all over the internet? While celebrities' phones and computers are forever vulnerable to attacks, the common folk must also be wary. No matter how careful you think you were went you sent those "candid" photos to your ex, with a little effort and access to public information, your pictures can be snagged, too. Here's how. Cloud Storage Apple's iCloud service provides a hassle free way to store and transfer photos and other media across multiple devices. While the commercial exemplifies the G-rated community of iPhone users, there are a bunch of non-soccer moms that use their iPhones in a more..."free spirited" mindset. With Photo Stream enabled (requires OS X Lion or later, iOS 5 or later), pictures taken on your iPhone go to directly to your computer and/or tablet, all while being stored in the cloud. If you think the cloud is safe, just ask Gizmodo

How to Hack Samsung Phone Screen Lock

I have discovered  another  security flaw in Samsung Android phones. It is possible to completely disable the lock screen and get access to any app - even when the phone is "securely" locked with a pattern, PIN, password, or face detection. Unlike another recently released flaw, this doesn't rely quite so heavily on ultra-precise timing. Video . Of course, if you are unable to download a screen unlocker, this security vulnerability still allows you to  dial any phone number and run any app ! HOWTO From the lock screen, hit the emergency call button. Dial a non-existent emergency services number - e.g. 0. Press the green dial icon. Dismiss the error message. Press the phone's back button. The app's screen will be briefly displayed. This is just about long enough to interact with the app. Using this, you can run and interact with any app / widget / settings menu. You can also use this to launch the dialler. From there, you can dial any phone