One S Vulnerable to Remote Wipe Hack - HTC One S

I have just seen this article on the Verge.com 'Remote wipe attack not limited to Samsung phones, Android dialer may be to blame'. Basically there is an issue in the dialier where o website could put a string in to wipe your device automatically.
The Verge also have a test to see if your device is vulnerable to attack and if it is, the website will open up your dialer and show you your imei number, which happens with the ONE S.
Test here.
Full Article Here.
The test is just to show if the phone has the issue, it does not wipe anything. All info from the Verge.com.
Quick Fix - https://play.google.com/store/apps/details?id=com.voss.notelurl

Hahahaha okay who is going to be the brave one and actually click that link just in case it kills your phone?
**** it worked! Okay no more laughing if it aint in my bookmarks then I'm using the pc to be safe.

I did
Sent from my HTC One S using xda premium

It worked. Guy's, DO NOT click the link, it really wiped my phone!!!! I didn't even do a nandroid!!

Use this app as workaround:
https://play.google.com/store/apps/details?id=com.voss.notelurl

Didn't wipe mine
Sent from my HTC One S using xda premium

Hgaara said:
It worked. Guy's, DO NOT click the link, it really wiped my phone!!!! I didn't even do a nandroid!!
Click to expand...
Click to collapse
The link he put up didn't contain the wipe code? So I'm gonna call BS.
On a side note if you know someone with an S3 you can skip all this remote wipe crap and just trick them into dialing this number.
*2767*3855#
After pushing # the phone will do an unstoppable factory reset.

Telstop another good app I'm using - https://play.google.com/store/apps/details?id=org.mulliner.telstop

how would the test link wipe anyones phone its a test to demo if the phone has the issue, i have tested it myself and all the links and info are from the verge.com a very large site, nothing on this post will make you lose data.

clewis said:
I have just seen this article on the Verge.com 'Remote wipe attack not limited to Samsung phones, Android dialer may be to blame'. Basically there is an issue in the dialier where o website could put a string in to wipe your device automatically.
The Verge also have a test to see if your device is vulnerable to attack and if it is, the website will open up your dialer and show you your imei number, which happens with the ONE S.
Test here.
Full Article Here.
Click to expand...
Click to collapse
The test is just to show if the phone has the issue, it does not wipe anything. All info from the Verge.com.

Well I just backed up my phone and tried to remote wipe code. It just gave an error that the code was bad. I expected that since I'm on CM10 but I was just curious.

Doesn't look like I have the issue..tried Telstop and NoTelURL. Both did nothing, so I'm guessing I'm ok? I'm a bit confused on this whole stuff, sorry.

Yep, you have not this epic fail! Congrats.

n0j0e said:
Yep, you have not this epic fail! Congrats.
Click to expand...
Click to collapse
My device has no issues! No home button issue, no remote wipe, nothing. A little button backlight leak but you only see that when it's dark so..YAY! Thanks for confirming.

My question. On latest ota from T-Mobile, has this been addressed?!
Sent from my HTC One S using Tapatalk 2

Actually you can test it with this. http://forum.xda-developers.com/showthread.php?t=1906651
Instead of wipe it uses a different ussd code and presents your IMEI number.

digi7 said:
Actually you can test it with this. http://forum.xda-developers.com/showthread.php?t=1906651
Instead of wipe it uses a different ussd code and presents your IMEI number.
Click to expand...
Click to collapse
That's what the test in the main post is if u read what I put .
Sent from my HTC One S using xda premium

Guys!
Don't worry to much because of this issue.
The Samsung code factory reset code: *2767*3855# is not working on HTC phones. Also HTC seems to doesn't have any factory rested codes. The Show IMEI code is working as well as some other but non of them is really dangerous as the Samsung one.

Related

[REQ][APP] Security Code that deliberately wipes the phone.

I think the subject says it all.
Example, say someone is mugging you and is trying to force disclosure of you password. Give them the kill sequence that wipes your phone.
Sent from my Nexus One using XDA App
HTCinToronto said:
I think the subject says it all.
Example, say someone is mugging you and is trying to force disclosure of you password. Give them the kill sequence that wipes your phone.
Sent from my Nexus One using XDA App
Click to expand...
Click to collapse
Try Theft Aware.
No idea how you're gonna sms your phone without... your phone though. But you're supposed to do it from a friend's phone anyways.
Send the sms and it'll wipe your phone.
chowlala said:
Try Theft Aware.
No idea how you're gonna sms your phone without... your phone though. But you're supposed to do it from a friend's phone anyways.
Send the sms and it'll wipe your phone.
Click to expand...
Click to collapse
Send it from Google Voice.
Use wavesecure or something similar. Get to a computer and track the phone down using gps. You can take remote control of your phones functions from the computer.

Strange Text messages

This is tough to explain...
At random points a friend of mine tells me that I am sending stange text messages that look like this:
"ME:<Subject: > - What game?"
According to what I see in my text history, It is being sent from my phone. Now out of the 20 or so people I have active text sessions with, she is the only one.
I've been through various ROM's and have had this problem follow. Logic tells me its her phone based on the facts but I can't prove it. I've done a Google search and that returned nothing. Searched around the XDA site and didn't turn up anything.
Has anyone experienced anything the same or similar?
Buchez said:
This is tough to explain...
At random points a friend of mine tells me that I am sending stange text messages that look like this:
"ME:<Subject: > - What game?"
According to (1.)what I see in my text history, It is being sent from my phone. Now out of the 20 or so people I have active text sessions with, she is the only one.
I've been through various ROM's and (2.) have had this problem follow.
Logic tells me its her phone based on the facts but I can't prove it. I've done a Google search and that returned nothing. Searched around the XDA site and didn't turn up anything.
Has anyone experienced anything the same or similar?
Click to expand...
Click to collapse
Now excuse me if I am not following you, but
First you say : 1
And then you say : 2
How does something you can see in your phones text log become her phones problem?
It is your phone and it is prolly an app you install since it follows you, or a friend in your midst as they follow you too.
tweaked said:
Now excuse me if I am not following you, but
First you say : 1
And then you say : 2
How does something you can see in your phones text log become her phones problem?
It is your phone and it is prolly an app you install since it follows you, or a friend in your midst as they follow you too.
Click to expand...
Click to collapse
Yea I know, But I've been running with only stock apps for the past 24 hours and it happened again last night. I'm puzzled. Out of all the people I text it just goes to her phone.
Might have to keep my eyes out for the friend in the midst
If its showing as sent from your phone in your phone, then logic would dictate that your phone is the source of this issue. When switching roms, did u do a full wipe before reflashing? Are u sure u are not restoring any apps or configurations whether if its synced with Google or titanium backup? Perhaps u have apps stored on your sdcard? Just a few things to think about.
Sent from my Inspire 4G using XDA App
Maybe your excessive drinking is the cause "drunk texting." Admit it, it's okay, we've all done it. Lol
Sorry, can't say that I have ever experienced that, maybe a friend or flatmate is joshing with you.
Sent from MY LeeDroid loaded Inspire
Lol. This is also a plausible explaination Haha.
Nochips4me said:
Maybe your excessive drinking is the cause "drunk texting." Admit it, it's okay, we've all done it. Lol
Sorry, can't say that I have ever experienced that, maybe a friend or flatmate is joshing with you.
Sent from MY LeeDroid loaded Inspire
Click to expand...
Click to collapse
Sent from my Inspire 4G using XDA App
What game?
Sorry I meant to say was it looks like you're the problem
Do you sync htc sense? I've had the same thing happen and it only happened after flashing a rom and logging into htc sense. Not sure how or why but it would re send a few texts.
Sent from my Inspire 4G using Tapatalk
cant be any worse then me talking to someone. and hearing someone else cross talk into my phone lol, but they cant hear me

Erikmms dianxinOS/tapasOS Q&A

The usual q&a thread for the ROM dianxinOS/tapasOS by erikmm
Sent from my galaxy s 4g using XDA app
heh, so, first question: Is there anyway to change the location of the DX weather to somewhere outside China?
youtube video failed, green screen .
but MX works fine .
wifi is good! gps is good!
johncdn said:
youtube video failed, green screen .
but MX works fine .
wifi is good! gps is good!
Click to expand...
Click to collapse
Try the fix posted in the mokee thread it should fix green screen I guess I switched them up from build 1 to build 2 lol
sent from my batcave
erikmm said:
Try the fix posted in the mokee thread it should fix green screen I guess I switched them up from build 1 to build 2 lol
sent from my batcave
Click to expand...
Click to collapse
Thanks!
My bad, in youtube play, no green screen, with following error message:
"There was a problem while playing."
It seems /system/lib/hw has right file (18064 bytes in size). Here is a log.
Thanks for looking into it .
erikmm said:
Try the fix posted in the mokee thread it should fix green screen I guess I switched them up from build 1 to build 2 lol
sent from my batcave
Click to expand...
Click to collapse
I tried it and it didn't work
Sent from my SGH-T959V using XDA
johncdn said:
Thanks!
My bad, in youtube play, no green screen, with following error message:
"There was a problem while playing."
It seems /system/lib/hw has right file (18064 bytes in size). Here is a log.
Thanks for looking into it .
Click to expand...
Click to collapse
got it thanks for the log i'll release the fix when i get home.
does this rom have settings/display/tv-out
m4127440 said:
does this rom have settings/display/tv-out
Click to expand...
Click to collapse
no for my install.
Really liking this one so far. The power management tools are really nice, and so are the themes, I just wish I could read Chinese - the theme manager is great, but the TapasHot app store or whatever seems to confuse me Also, whenever you update the OP, you might take out "wifi" under major bugs, since it's fixed already.
Thanks for another bad ass ROM!
Sent from my SGH-T959V using XDA
Ok I followed the instructions for installing the rom and love it but, I lost all contacts on sim card. I'm guessing I might have made a mistake. Can anyone suggest a way of recovering them? By the way they were saved to sim.
You didn't save them to Google?
There's no recovery if they're wiped from you're sim .....try saving them to Google next time,you'll be glad you did.
just flashed a different rom and they are on the sim and show up but for some reason they wouldnt show up in tapasOS even when I tried to import them from sim it would say there wasnt any.Would like to use this rom.
Like I said....back them up on Google...and use this rom if that's what your hang up is...if your not gonna use this rom based solely cuz it wont read your contacts from your sim...then your comment about really wanna use this rom isn't true when there's several ways of backing up your contacts and making it happen.
That is such a BS statement if I ever heard one..."I would like to use this rom". But do nothing on your own to make it happen..
Come on people use some common sense and do something on your own without someone holding your hand.
I have been trying to remedy this on my own all day by reading and trial and error. I guess you can feel like a tough guy behind the internet.
Dyin' over here! I
To rephrase the advice given earlier (since sixstring will likely cut out all of those posts later) in whatever rom will read your contacts, back them up to your Gmail account. That way, you'll always have access to them on any rom.
Sent from my SGH-T959V using xda premium
BRICK0044 said:
Ok I followed the instructions for installing the rom and love it but, I lost all contacts on sim card. I'm guessing I might have made a mistake. Can anyone suggest a way of recovering them? By the way they were saved to sim.
Click to expand...
Click to collapse
This is a known issue with cm7, cm7 is the base if this ROM. A little reading in the forums and you would have know what to do...
No need to knock the ROM, it's your 'ish
Sent from my SGH-T959V using XDA
eb13 said:
This is a known issue with cm7, cm7 is the base if this ROM. A little reading in the forums and you would have know what to do...
No need to knock the ROM, it's your 'ish
Sent from my SGH-T959V using XDA
Click to expand...
Click to collapse
I by no means was knocking the rom, I said that I probably made a mistake. All I was doing was asking a question and things got blown way out of proportion. I have read on here everyday. Again I like to experiment with things. I will never ask another simple question.
lets keep it civil here people. no name calling. no replying to name calling either. just makes matters get out of hand quickly.
thread cleaned.
is it worth buying?

tracking software are useless

I lost my phone last week and it was found today because the "finder/thief" return the phone to my service provider after I requested the IMEI to be blocked.
After I got my phone, everything has already been factory reset by the "finder/thief", the SD was missing, we know who probably took it. No wonder whereismydroid and Plan B apps never worked, because they are absolutely useless. All thieves have to do is take the battery and sim card out, go home, factory reset with ODIN or something, all your information and those so called tracking Apps are gone, and Plan B can NOT be installed remotely because your gmail is no longer signed into your phone.
So IMO these apps are useless.
user installed apps? yea they are. its why i flash cerberus as a system app (survives a factory reset). i dont have a pin lock or anything of teh sort to make teh theif want to reset. instead im quite alright with him opening it up and calling/texting whomever he wants cuz ill be tracking him the whole time. chances are the guy who buste dteh window of yoru car to get the phone doesnt know to take teh device get it into download mode and use odin to wipe out the stuff i installed
shabbypenguin said:
user installed apps? yea they are. its why i flash cerberus as a system app (survives a factory reset). i dont have a pin lock or anything of teh sort to make teh theif want to reset. instead im quite alright with him opening it up and calling/texting whomever he wants cuz ill be tracking him the whole time. chances are the guy who buste dteh window of yoru car to get the phone doesnt know to take teh device get it into download mode and use odin to wipe out the stuff i installed
Click to expand...
Click to collapse
Its a thief not a technical expert
shabbypenguin said:
user installed apps? yea they are. its why i flash cerberus as a system app (survives a factory reset). i dont have a pin lock or anything of teh sort to make teh theif want to reset. instead im quite alright with him opening it up and calling/texting whomever he wants cuz ill be tracking him the whole time. chances are the guy who buste dteh window of yoru car to get the phone doesnt know to take teh device get it into download mode and use odin to wipe out the stuff i installed
Click to expand...
Click to collapse
What if the thief flash your phone with his own rom using ODIN?
why steal phones if you know how tl use ODIN just learn a little more and you have a more stable career in development.
ickkii said:
why steal phones if you know how tl use ODIN just learn a little more and you have a more stable career in development.
Click to expand...
Click to collapse
The is something you have to ask the thieves.
My phone was definitely flashed after I lost it. The rom is different from the one I had.
ickkii said:
why steal phones if you know how tl use ODIN just learn a little more and you have a more stable career in development.
Click to expand...
Click to collapse
Nowadays you really don't have to be a tech wizard to do this stuff. Programming isn't really clicking around and dropping files onto SD card.
shabbypenguin said:
user installed apps? yea they are. its why i flash cerberus as a system app (survives a factory reset). i dont have a pin lock or anything of teh sort to make teh theif want to reset. instead im quite alright with him opening it up and calling/texting whomever he wants cuz ill be tracking him the whole time. chances are the guy who buste dteh window of yoru car to get the phone doesnt know to take teh device get it into download mode and use odin to wipe out the stuff i installed
Click to expand...
Click to collapse
Whoa!!
I'm no cop but the OP didn't say how it was stolen but shabby knew that it was taken out your car by breaking the window...
Yes im pointing fingers!! BUT.. Im just kidding .
I actually want to thank shabby for his comment.
I've been wondering if theres an app like the one he mentioned that can be installed and track the phone without being deleted.
I didn't know where to look but now i have a name so i can do my research.
Im not too technical with android but my goal is to have a phone with great security like firewalls blockers and what not.
Yeah cerberus is the best one.
Sent from my Nexus 7 using xda app-developers app
https://play.google.com/store/apps/details?id=com.lsdroid.cerberus&hl=en
still an app, how can you install it into the system?
drsanket_xperia_u said:
Its a thief not a technical expert
Click to expand...
Click to collapse
yea thats why i dont hold much faith in the guy knowing about odin
robogoflow said:
Whoa!!
I'm no cop but the OP didn't say how it was stolen but shabby knew that it was taken out your car by breaking the window...
Yes im pointing fingers!! BUT.. Im just kidding .
I actually want to thank shabby for his comment.
I've been wondering if theres an app like the one he mentioned that can be installed and track the phone without being deleted.
I didn't know where to look but now i have a name so i can do my research.
Im not too technical with android but my goal is to have a phone with great security like firewalls blockers and what not.
Click to expand...
Click to collapse
i posted a download link below, its truly an amazing app. you get a week trial and then its 2 dollars for lifetime membership of up to 5 devices at any time. im sure there is more im forgetting and you can read on their site
FinancialWar said:
https://play.google.com/store/apps/details?id=com.lsdroid.cerberus&hl=en
still an app, how can you install it into the system?
Click to expand...
Click to collapse
https://www.cerberusapp.com/download.php
i use this one https://www.cerberusapp.com/download/cerberus_disguised-ICS.zip it shows as a system process, then using the website i hide the app and no one is the wiser
drsanket_xperia_u said:
Its a thief not a technical expert
Click to expand...
Click to collapse
You'd be surprised. Welcome to 21st century, thief can take all you got while eating doritos and drinking Pepsi. Everyone who underestimates these people are bound to be victims sooner or later.
Sent from my SCH-I500 using xda premium

BAD LUCK! Just posted to get empathy

Yesterday I flashed CM 13.1 on my OPO and postponed the final tune ups and settings to later and went out to the gym and LOST it there (Or possibly has beed stolen!) and It's so painful because I hadn't installed and activated Adnroid Device Manager and teh Lockscreen was open //I feel very upset now…
I know that nothing can be done and this topic is not relevent here and can be removed, it's OK
roshak said:
Yesterday I flashed CM 13.1 on my OPO and postponed the final tune ups and settings to later and went out to the gym and LOST it there (Or possibly has beed stolen!) and It's so painful because I hadn't installed and activated Adnroid Device Manager and teh Lockscreen was open //I feel very upset now…
I know that nothing can be done and this topic is not relevent here and can be removed, it's OK
Click to expand...
Click to collapse
Just saying, is it too hard for them to go to recovery and flash any other rom? They can erase your current rom as well no matter what security app you use, right? So, the sooner this thread gets deleted......
Theoretically Cerberus pro can resist a Factory Reset, but I don't know how it does that and if it's bypassable...
sad bro! whats your next phone?
Sent from my A0001 using Tapatalk
Maybe you can try something like AndroidLost? Though, I believe it requires Google account to be on device beforehand. I'm not sure if it's compatible with CM13, but nothing wrong with trying at this point
Edit: Yep, you do need Google account on device for this app to work. Check this out.
bachera said:
sad bro! whats your next phone?
Sent from my A0001 using Tapatalk
Click to expand...
Click to collapse
OPX I guess... but not sure yet. Don't like the OP2
xymic said:
Maybe you can try something like AndroidLost? Though, I believe it requires Google account to be on device beforehand. I'm not sure if it's compatible with CM13, but nothing wrong with trying at this point
Edit: Yep, you do need Google account on device for this app to work. Check this out.
Click to expand...
Click to collapse
very useful tips. But unfortunately the location on my device was been always deactivated (just when i wanted to search am adress manually, and that was 4 days before I lost!!)
well report it stolen that way they block the emei I think. Then you are sure they wont be able to do anything on the phone. In rare cases they find it and can get it back. Very rare cases. Hope your new phone will be just as satisfying
Sent from my A0001 using Tapatalk
bachera said:
well report it stolen that way they block the emei I think. Then you are sure they wont be able to do anything on the phone. In rare cases they find it and can get it back. Very rare cases. Hope your new phone will be just as satisfying
Sent from my A0001 using Tapatalk
Click to expand...
Click to collapse
The IMEI can be changed, wouldn't make a difference if someone is determined once they have the device in their hands
Sent from my A0001 using Tapatalk
Renosh said:
The IMEI can be changed, wouldn't make a difference if someone is determined once they have the device in their hands
Sent from my A0001 using Tapatalk
Click to expand...
Click to collapse
true gladly most dont know about that. Also its a tedious process. Kind of mixed on that cause it can be damn handy, lost my imei on several devices due to a series of unfortunate events. On the other hand it is real handy for the situation of a lost device.
Sent from my A0001 using Tapatalk
Issues
MMMMM My OPO has lost its IMEI so I must change it, any details would be most helpful.
use your cyanogen account. You can use it to locate and wipe if need be and track too!
itechy said:
use your cyanogen account. You can use it to locate and wipe if need be and track too!
Click to expand...
Click to collapse
The unit is not lost.. the IMEI is. It is an invalid one. No matter what I try and have done to the unit it does not come up as a valid one. I was told I would need to change it and then it would be fine. Any help would be great! :good:

Categories

Resources