Cloak & Dagger
From Two Permissions to Complete�Control of the UI Feedback Loop
Yanick Fratantonio
joint work with�Chenxiong Qian, Simon Chung, Wenke Lee
IEEE Symposium on Security and Privacy 2017
May 24th, 2017
UI Feedback Loop
Output channel
Input channel
Know what is currently displayed to the user
Modify what the user sees
Know what the user is clicking on
Inject user input
Cloak & Dagger Attacks
Two Permissions
SYSTEM_ALERT_WINDOW (“draw on top”)
BIND_ACCESSIBILITY_SERVICE (a11y)
A11y security mechanism
“Since an event contains the text of its source privacy can be compromised by leaking sensitive information such as passwords. To address this issue any event fired in response to manipulation of a PASSWORD field does NOT CONTAIN the text of the password.”
Why would a user grant these permissions?
Why would a user grant these permissions?
Why would a user grant these permissions?
The list of permissions is not even shown!
Unleashing Mayhem
Clickjacking 101
Click here
The “obscured flag” security mechanism
The “obscured flag” security mechanism
Attack: Context Hiding
Capture?
Attack: Context Hiding
Attack: Context Hiding
Back to the “obscured flag”...
Back to the “obscured flag”...
Attack: Invisible Grid Attack
Attack: Invisible Grid Attack
Attack: Invisible Grid Attack
1
3
4
2
Attack: Invisible Grid Attack
1
2
3
4
Where did the user click?
Attack: Invisible Grid Attack
MotionEvent
1
2
3
4
1
2
3
4
Overlay #
MotionEvent
MotionEvent
MotionEvent
Not obscured
Not obscured
Not obscured
Not obscured
Where did the user click?
Attack: Invisible Grid Attack
MotionEvent
1
2
3
4
1
2
3
4
Overlay #
MotionEvent
MotionEvent
MotionEvent
Obscured
Not obscured
Not obscured
Not obscured
Where did the user click?
Attack: Invisible Grid Attack
MotionEvent
1
2
3
4
1
2
3
4
Overlay #
MotionEvent
MotionEvent
MotionEvent
Obscured
Not obscured
Not obscured
Obscured
Where did the user click?
Attack: Invisible Grid Attack
MotionEvent
1
2
3
4
1
2
3
4
Overlay #
MotionEvent
MotionEvent
MotionEvent
Obscured
Not obscured
Obscured
Obscured
Where did the user click?
Attack: Invisible Grid Attack
1
2
3
4
Security mechanism used as side-channel!
The attacker can use these patterns to infer where the user clicked!
Attack: Invisible Grid Attack
These overlays are drawn invisible during a real attack
Design Shortcomings
Attack: a11y on steroids
Attack: a11y on steroids
1) Steal PIN
2) Inject PIN and unlock the phone!
Bonus point: phone unlock while keeping the screen is off!
Attack: Stealthy Phishing
<username>
<password>
<password>
<username>
Login
Login
JohnDoe
L33tP4ss
<username>
<password>
JohnDoe
L33tP4ss
Login
Filled�by a11y
Clicked by a11y
Welcome, John!
Great!
UI-in-the-middle
Attack
Attack: Silent God-mode App Installation
Attack: Silent God-mode App Installation
Attack: Silent God-mode App Installation
Are these attacks actually practical?
User Study
Results
Results
Results
Overall Awareness
Overall Awareness
Overall Awareness
How can we fix this?
Responsible Disclosure
Responsible Disclosure
Responsible Disclosure
Responsible Disclosure
Disclosure of “a11y on steroids” (August 22nd)
Responsible Disclosure
Responsible Disclosure
Responsible Disclosure
Few classes of vulnerabilities will generally not qualify for a reward:
Android Rewards�Qualifying Vulnerabilities
Responsible Disclosure
Responsible Disclosure
Responsible Disclosure
All attacks are still working!�(Even on Android 7.1.2, with May’s updates)
Short-term Recommendations
Securing Android UI
Takeaways
Takeaways
Takeaways