About
Subscribe
  • Home
  • /
  • Security
  • /
  • Award-winning researchers at MWR Labs expose vulnerabilities in Amazon Fire Phone and Samsung Galaxy S5

Award-winning researchers at MWR Labs expose vulnerabilities in Amazon Fire Phone and Samsung Galaxy S5

Double win for global security firm MWR InfoSecurity at Mobile Pwn2Own 2014.

Johannesburg, 14 Nov 2014

At this year's Mobile Pwn2Own event, which took place during the Applied Security Conference (PacSec) in Tokyo, the research arm of global consultancy MWR InfoSecurity, MWR Labs, won two different categories by exclusively demonstrating security flaws in both the Amazon Fire Phone and Samsung Galaxy S5.

One team of researchers from MWR Labs in South Africa exposed a remote code execution on the Amazon Fire Phone, while another team from MWR Labs in the UK exploited the Samsung Galaxy S5, enabling them to steal personal details.

The Zero Day Initiative (ZDI), host of the annual event, announced MWR Labs researchers, Bernard Wagner and Kyle Riley, from South Africa, won the Mobile Application/OS category, successfully demonstrating remote code execution on the Amazon Fire Phone through a Man-in-the-Middle attack. The researchers, based at MWR's South African office, have indicated that the exploit was possible due to a set of vulnerabilities within a pre-installed package on the device. To prove they were able to execute arbitrary code remotely, the criteria stipulated the researchers should be able to retrieve files from exploited devices ? such as SMS messages and photos ? without any user interaction. The prize for this category was $50 000.

"This is a fantastic accolade for the MWR Labs team in South Africa," said Harry Grobbelaar, MD of MWR InfoSecurity in South Africa. "It is undisputable proof of the talent MWR has been cultivating in the South African market, and the quality of our professional services, helping customers with all areas of cyber security."

In addition, from the UK, Robert Miller and Jonathan Butler won the Short Distance Category after they were able to demonstrate exploitation against the Samsung Galaxy S5 over Near Field Communication (NFC). They successfully retrieved personal information from the device, securing the win and $75 000.

"MWR is proud to receive these awards," said Ian Shaw, Group MD of MWR InfoSecurity. "Our researchers from across the globe work extremely hard; and entering competitions, such as Pwn2Own, are vitally important as it keeps us at the sharp edge of the industry.

"This work forms part of a wide-ranging programme of security research at MWR on a global scale and highlights the ongoing need for mobile developers and manufacturers to prioritise security, in order to keep customers safe."

The MWR Labs research also identified additional vulnerabilities, which will first be reported to Amazon and Samsung in the coming weeks. It intends to publish advisories in due course for these vulnerabilities on its Web site (https://labs.mwrinfosecurity.com/) in accordance with MWR's disclosure policy.

Share

Mobile Pwn2Own 2014

Mobile Pwn2Own is ZDI's annual contest that rewards security researchers for highlighting security vulnerabilities on mobile platforms. With the near-ubiquity of mobile devices, vulnerabilities on these platforms are becoming increasingly coveted and are actively and vigorously hunted by criminals for exploitation. This contest helps to harden these devices by finding vulnerabilities first and sharing that research with mobile device and platform vendors.

http://h30499.www3.hp.com/t5/HP-Security-Research-Blog/Mobile-Pwn2Own-Tokyo-2014/ba-p/6599054#.VGMlMRZAdcq

MWR InfoSecurity

Established in 2003, MWR InfoSecurity is a research-led information security consultancy, with a client list consisting of Dow Jones, NASDAQ, FTSE 100 companies and Government agencies and departments. MWR consults with clients around the world, providing specialist advice and services on all areas of security, from mobile through to supercomputers.

Central to its philosophy is the desire to deliver high quality cyber security consulting services and unsurpassed levels of support to clients. MWR's focus is working with clients to develop and deliver a full security programme, tailored to meet the needs of each individual organisation.

MWR's services range across professional and managed services, technical solutions and training covering areas such as security research, incident response, web defense, phishing, mobile and payment security.

Editorial contacts