X-Ray author here, happy to answer any questions folks have!
Why haven't you published this to the Google Play store?
It's a weird distinction that they allow AV-like apps, but not vulnerability assessment apps.
11–15 of 15 posts
X-Ray author here, happy to answer any questions folks have!
Why haven't you published this to the Google Play store?
It's a weird distinction that they allow AV-like apps, but not vulnerability assessment apps.
Just ran it on my Nexus S with 4.1 and everything is patched. Currious to see how the HTC / Samsung's that are not Nexus devices fare.
We posted about some of the security improvements in Jelly Bean 4.1 last week:
https://blog.duosecurity.com/2012/07/exploit-mitigations-in-...
Galaxy Nexus running CM9 RC1 is vulnerable to Mempodroid :(
CM9 RC1 is supposed to be running 4.0.4, right? Shouldn't that have been patched already? Though it also appears they have some bigger issues, like everything you type going out to the debug logs, passwords included. You should report this on their issue tracker: http://code.google.com/p/cyanogenmod/issues/list
The vulnerability is looking checking to see if the mem_write() function is functional (where the vulnerability was present), which was removed/disabled by upstream AOSP.