Second OnePlus Factory App Discovered. This One Dumps Photos, WiFi & GPS Logs

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
A security researcher has found a second factory app that was included on OnePlus devices delivered to customers, and this one can be abused to dump the user's photos and videos, but also GPS, WiFi, Bluetooth, and various other logs.

Discovered by a mobile security researcher who goes online by the pseudonym of Elliot Alderson —the name of the main character in the Mr. Robot TV series— this app's name is OnePlusLogKit and is an application that comes preinstalled on OnePlus devices, also running with system privileges.
The same security researcher found a similar OnePlus factory app yesterday. That app, named EngineerMode, allowed a user or malicious threat actor to root devices.

Debug app provides easy access to a bunch of OnePlus logs
According to a series of tweets and screenshots of the app's source code the researcher published online today, this second app has the ability to enable logging of various phone services, logs which it saves on the phone's SD card.
This is a big security issue, Alderson told Bleeping Computer in a private conversation. An attacker can enable the logging behavior in three ways and then steal the collected logs as they pile up.

OnePlusLogKit logging can be enabled by entering *#800# via the phone's dial pad. This brings up the app's interface where various logging features can be turned on or off.

An attacker with physical access to the device can enable the logging and collect the logs at a later date. In addition, attackers could use social engineering and trick users into enabling the logging themselves and later sending over the log files.

Last but not least, an attacker can use malware to enable logging and data collection programmatically.

"You don't need to be root here," the researcher said. "The log files are stored in the SD card. So if an app has the permission to read the SD card, it can access the logs."

No good reason why this app is on customer devices
....
 

upnorth

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
Quote : " "They suck, this is sure," Baptiste says of OnePlus's security, "but we can find this kind of thing in every firmware." "

Source : OnePlus Phones Have an Unfortunate Backdoor Built In

No official statement on OnePlusLogKit yet but on EngineerMode. Quote :

" Friends,

Yesterday, we received a lot of questions regarding an apk found in several devices, including our own, named EngineerMode, and we would like to explain what it is. EngineerMode is a diagnostic tool mainly used for factory production line functionality testing and after sales support.

We’ve seen several statements by community developers that are worried because this apk grants root privileges. While, it can enable adb root which provides privileges for adb commands, it will not let 3rd-party apps access full root privileges. Additionally, adb root is only accessible if USB debugging, which is off by default, is turned on, and any sort of root access would still require physical access to your device.

While we don't see this as a major security issue, we understand that users may still have concerns and therefore we will remove the adb root function from EngineerMode in an upcoming OTA.

Thanks, "

Source : What is EngineerMode?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top