• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Security: The Rise is vulnerable to the USSD remote wipe attack

USSD is the name given to those "star codes" that you punch in to your dialer to make the phone do things. There's a bug in dialers prior to 4.1, in which the dialer accepts such codes from a webpage just as though they had been put in manually, meaning it executes the dialer *#whatever# code. This can be used to essentially make your phone do a factory reset without your consent.

This app will intercept the attempt without interfering with normal phone operations:
https://play.google.com/store/apps/details?id=net.thauvin.erik.android.noussd&hl=en

From this XDA post:
http://forum.xda-developers.com/showthread.php?t=1908482

The other thing you can do is install an alternative dialer, retaining the original, so every dial attempt requires interaction. The NoUSSD solution is better because it doesn't get in the way like that.

Once we get JB, if we ever get JB, this problem won't apply.
 
  • Like
Reactions: AndyOpie150

BEST TECH IN 2023

We've been tracking upcoming products and ranking the best tech since 2007. Thanks for trusting our opinion: we get rewarded through affiliate links that earn us a commission and we invite you to learn more about us.

Smartphones