Menu
Android app developers should update to Dropbox's latest SDK

Android app developers should update to Dropbox's latest SDK

A vulnerability could allow your Dropbox files to be uploaded to someone else's account

Android apps that use Dropbox for storage and are built using an older version of its SDK are vulnerable to an attack that can steal data, although Dropbox has released a fix, according to IBM security researchers.

IBM's application security research team said Wednesday they had found a way to link their own Dropbox account to an Android app on another person's phone that connects to the storage service. After a successful attack, any data uploaded by the app is delivered to the attacker's Dropbox account.

Dropbox publishes an SDK (software development kit) for linking its service to an app. The flaw, nicknamed "DroppedIn," affected Dropbox SDK versions 1.5.4 through 1.6.1 and was fixed in version 1.62, IBM said in a blog post.

The attack, while serious, isn't easy to carry out. It also won't work if a person has Dropbox's own mobile app installed on their phone, and it won't give an attacker access to the full content of a Dropbox account.

Dropbox said the issue doesn't appear to have been exploited by hackers to access data, and that most of the popular apps using its SDK have been patched.

An attacker must first obtain an access token for a Dropbox-enabled app, which can be done by downloading the app and authorizing it for their own Dropbox account.

The attacker must then lure someone to a website or web page with malicious code. The code grabs from the victim's phone a large cryptographic number, known as a "nonce," that's used as part of the authentication process to link an account. With the access code and the nonce, the attacker can link their own Dropbox account to the victim's Android app.

One way users can tell if they've been attacked is by logging into Dropbox using a PC and checking if there are files that should have been saved by a mobile app using Dropbox that aren't there, IBM wrote. It said there aren't many Android apps that use Dropbox's SDK, but a couple of popular ones do, including Microsoft's Office Mobile and AgileBits' 1Password.

As some affected Android apps may not be updated quickly, the best way to defend against the attack is to download the mobile version of Dropbox, which "makes exploitation impossible," IBM wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags IBMdropboxExploits / vulnerabilities

Featured

Slideshows

EDGE 2018: Kiwis kick back with Super Rugby before NZ session

EDGE 2018: Kiwis kick back with Super Rugby before NZ session

New Zealanders kick-started EDGE 2018 with a bout of Super Rugby before a dedicated New Zealand session, in front of more than 50 partners, vendors and distributors on Hamilton Island.​

EDGE 2018: Kiwis kick back with Super Rugby before NZ session
EDGE 2018: Kiwis assess key customer priorities through NZ research

EDGE 2018: Kiwis assess key customer priorities through NZ research

EDGE 2018 kicked off with a dedicated New Zealand track, highlighting the key customer priorities across the local market, in association with Dell EMC. Delivered through EDGE Research - leveraging Kiwi data through Tech Research Asia - more than 50 partners, vendors and distributors combined during an interactive session to assess the changing spending patterns of the end-user and the subsequent impact to the channel.

EDGE 2018: Kiwis assess key customer priorities through NZ research
Show Comments