Application Exploiting the Dirty Cow Vulnerability for Android OS
Aplikace využívající zranitelnost Dirty Cow pro operační systém Android
Authors
Supervisors
Reviewers
Editors
Other contributors
Journal Title
Journal ISSN
Volume Title
Publisher
České vysoké učení technické v Praze
Czech Technical University in Prague
Czech Technical University in Prague
Date of defense
Abstract
Tato práce se zabývá zranitelností linuxového jádra CVE-2016-5195, zvanou též Dirty Cow, na operačním systému Android. V textu jsou analyzována stávající řešení útoků a na základě toho je vytvořena instalovatelná aplikace, která zranitelnost využije a umožní útočníkovi vzdálený přístup k napadenému zařízení. Jedná se o příklad útoku zevnitř. Aplikace byla testována na virtuálních zařízeních s architekturami x86 a x86-64 a na emulovaných zařízeních s architekturami x86, x86-64 a ARM64.
This thesis focuses on Linux kernel vulnerability CVE-2016-5195 (also known as ``Dirty Cow'') on Android operating system. The state-of-the-art attacks are analyzed and this analysis serves as a basis to the runnable application that is being developed as one of the goals of this thesis. This application exploits the vulnerability and allows remote access for the attacker to the target device -- this is an insider type of attack. The application has been tested on virtual devices with x86 and x86-64 architectures and on emulated devices with x86, x86-64 and ARM64 architectures.
This thesis focuses on Linux kernel vulnerability CVE-2016-5195 (also known as ``Dirty Cow'') on Android operating system. The state-of-the-art attacks are analyzed and this analysis serves as a basis to the runnable application that is being developed as one of the goals of this thesis. This application exploits the vulnerability and allows remote access for the attacker to the target device -- this is an insider type of attack. The application has been tested on virtual devices with x86 and x86-64 architectures and on emulated devices with x86, x86-64 and ARM64 architectures.
Description
Keywords
Android,CVE-2016-5195,zranitelnost Dirty Cow,vzdálený přístup,neoprávněný přístup,neoprávněné spouštění kódu,zvýšení oprávnění,assembler x86,assembler x86-64,assembler ARM64, Android,CVE-2016-5195,Dirty Cow vulnerability,remote access,unauthorized access,arbitrary code execution,escalation of privilege,x86 assembly language,x86-64 assembly language,ARM64 assembly language
Citation
Underlying research data set URL
Permanent link
Rights/License
A university thesis is a work protected by the Copyright Act of the Czech Republic. Extracts, copies and transcripts of the thesis are allowed for personal use only and at one`s own expense. The use of thesis should be in compliance with the Copyright Act.
Vysokoškolská závěrečná práce je dílo chráněné autorským zákonem. Je možné pořizovat z něj na své náklady a pro svoji osobní potřebu výpisy, opisy a rozmnoženiny. Jeho využití musí být v souladu s autorským zákonem v platném znění.
Vysokoškolská závěrečná práce je dílo chráněné autorským zákonem. Je možné pořizovat z něj na své náklady a pro svoji osobní potřebu výpisy, opisy a rozmnoženiny. Jeho využití musí být v souladu s autorským zákonem v platném znění.