<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/css" media="screen" href="http://s2.wp.com/wp-content/themes/vip/newyorkobserver/stylesheets/rss.css"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Betabeat &#187; vulnerabilities</title>
	<atom:link href="http://betabeat.com/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://betabeat.com</link>
	<description>Just another WordPress.com site</description>
	<lastBuildDate>Thu, 23 May 2013 21:03:21 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='betabeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Betabeat &#187; vulnerabilities</title>
		<link>http://betabeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://betabeat.com/osd.xml" title="Betabeat" />
	<atom:link rel='hub' href='http://betabeat.com/?pushpress=hub'/>
		<item>
				
		<title>Samsung&#8217;s Galaxy 3 is Vulnerable to Remote Wiping by Hackers [VIDEO]</title>

		<comments>http://betabeat.com/2012/09/samsungs-galaxy-3-is-vulnerable-to-remote-wiping-by-hackers-video/#comments</comments>
		<pubDate>Tue, 25 Sep 2012 15:43:37 -0400</pubDate>
					<link>http://betabeat.com/2012/09/samsungs-galaxy-3-is-vulnerable-to-remote-wiping-by-hackers-video/</link>
			<dc:creator>Steve Huff</dc:creator>
				
		<guid isPermaLink="false">http://betabeat.com/?p=63866</guid>
		<description><![CDATA[<p><div id="attachment_63872" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png"><img class="size-medium wp-image-63872" title="samsungwipe" src="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png?w=300" alt="" width="300" height="205" /></a><p class="wp-caption-text">Ravi Borgaonkar demonstrating Galaxy handset flaws. (Screengrab)</p></div></p>
<p>During a recent security conference in South America, a Berlin-based researcher revealed that Samsung has a major problem with its iPhone challengers, the Galaxy 3 and Galaxy S2 smartphones.</p>
<p>Both can easily be remotely wiped by code embedded in a web page.</p>
<p>Ravi Borgaonkar found that the Galaxy's "service loading" feature, its method of communicating with application servers, can be exploited with just one line of code tucked away in a web page's HTML. If the attack is successful, the malicious code reverts the phones to their factory settings. Worse still, once the attack begins, the phone's user can't do a thing about it.</p>
<p>That's bad enough. <a href="http://www.digitalspy.com/tech/news/a408192/samsung-galaxy-3-vulnerable-to-remote-wipe-hack.html">There's also this</a>:<!--more--></p>
<blockquote><p>Alongside web pages, the code can also be embedded in malicious text messages, or triggered by a QR code or NFC tag.</p></blockquote>
<p>Security researchers are pressing Samsung to patch the problem because as DigitalSpy <a href="http://www.digitalspy.com/tech/news/a408192/samsung-galaxy-3-vulnerable-to-remote-wipe-hack.html" target="_blank">reports</a>, experts say this is a "major security vulnerability."</p>
<p>Mr. Borgaonkar, who reportedly wondered aloud what Samsung's engineers were smoking when they created the vulnerable system, demonstrates how it works in the video below.</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/Q2-0B04HPhs?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>Viewers may need headphones to hear Mr. Borgaonkar clearly, but the shocked audience reaction at 2:10, when he uses a link from a tweet to demonstrate how quickly a malicious web page can reset the phone, is unmistakable.</p>
]]></description>
		<content:encoded><![CDATA[<p><div id="attachment_63872" class="wp-caption alignleft" style="width: 310px"><a href="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png"><img class="size-medium wp-image-63872" title="samsungwipe" src="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png?w=300" alt="" width="300" height="205" /></a><p class="wp-caption-text">Ravi Borgaonkar demonstrating Galaxy handset flaws. (Screengrab)</p></div></p>
<p>During a recent security conference in South America, a Berlin-based researcher revealed that Samsung has a major problem with its iPhone challengers, the Galaxy 3 and Galaxy S2 smartphones.</p>
<p>Both can easily be remotely wiped by code embedded in a web page.</p>
<p>Ravi Borgaonkar found that the Galaxy's "service loading" feature, its method of communicating with application servers, can be exploited with just one line of code tucked away in a web page's HTML. If the attack is successful, the malicious code reverts the phones to their factory settings. Worse still, once the attack begins, the phone's user can't do a thing about it.</p>
<p>That's bad enough. <a href="http://www.digitalspy.com/tech/news/a408192/samsung-galaxy-3-vulnerable-to-remote-wipe-hack.html">There's also this</a>:<!--more--></p>
<blockquote><p>Alongside web pages, the code can also be embedded in malicious text messages, or triggered by a QR code or NFC tag.</p></blockquote>
<p>Security researchers are pressing Samsung to patch the problem because as DigitalSpy <a href="http://www.digitalspy.com/tech/news/a408192/samsung-galaxy-3-vulnerable-to-remote-wipe-hack.html" target="_blank">reports</a>, experts say this is a "major security vulnerability."</p>
<p>Mr. Borgaonkar, who reportedly wondered aloud what Samsung's engineers were smoking when they created the vulnerable system, demonstrates how it works in the video below.</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/Q2-0B04HPhs?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p>Viewers may need headphones to hear Mr. Borgaonkar clearly, but the shocked audience reaction at 2:10, when he uses a link from a tweet to demonstrate how quickly a malicious web page can reset the phone, is unmistakable.</p>
]]></content:encoded>
		<wfw:commentRss>http://betabeat.com/2012/09/samsungs-galaxy-3-is-vulnerable-to-remote-wiping-by-hackers-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:thumbnail url="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png?w=150" />
		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png?w=150" medium="image">
			<media:title type="html">samsungwipe</media:title>
		</media:content>

		<media:content url="http://1.gravatar.com/avatar/12d391316d94afeef01bd9a987c847fe?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">shuffobserver</media:title>
		</media:content>

		<media:content url="http://nyobetabeat.files.wordpress.com/2012/09/samsungwipe.png?w=300" medium="image">
			<media:title type="html">samsungwipe</media:title>
		</media:content>
	</item>
	</channel>
</rss>
