Slashdot Mirror


Epic's First Fortnite Installer Allowed Hackers To Covertly Download and Install Anything on Users' Android Phones, Google Researchers Say (androidcentral.com)

Epic decided to ditch Google Play Store for its sleeper hit Fortnite. By doing so, while Epic may have saved some money that it would have had to split with Google, it also ran into an issue that it could have avoided had it not parted ways with Google. AndroidCentral reports: Google has just publicly disclosed that it discovered an extremely serious vulnerability in Epic's first Fortnite installer for Android that allowed any app on your phone to download and install anything in the background, including apps with full permissions granted, without the user's knowledge. Google's security team first disclosed the vulnerability privately to Epic Games on August 15, and has since released the information publicly following confirmation from Epic that the vulnerability was patched.

[...] When you go to download "Fortnite" you don't actually download the whole game, you download the Fortnite Installer first. The Fortnite Installer is a simple app that you download and install, which then subsequently downloads the full Fortnite game directly from Epic. The problem, as Google's security team discovered, was that the Fortnite Installer was very easily exploitable to hijack the request to download Fortnite from Epic and instead download anything when you tap the button to download the game. It's what's known as a "man-in-the-disk" attack.

39 comments

  1. That's just Epic's stupid way of doing things by Anonymous Coward · · Score: 2, Insightful

    They have an installer for everything, or a "launcher" which is an repackaged web browser that downloads things for you or lets you access their web store for content.

    Epic could let you just download directly from your browser but then the walled garden Apple wanna-be aspirations would be gone.

    1. Re: That's just Epic's stupid way of doing things by Anonymous Coward · · Score: 0

      There's an idea, they make tablets just to play Fortnite and nothing else.

  2. Walled gardens by Anonymous Coward · · Score: 0

    So glad its not walled

  3. download and install anything in the background? by Anonymous Coward · · Score: 0

    I swear, it's like our surveillance devices (phones) are deliberately being compromised. I know it sounds like tinfoil hat territory, but in this day and age it should be rare and unusual news when this kind of thing happens, not a daily occurrence.

  4. Doesn't CaptainDork play Fortnite a lot? by Anonymous Coward · · Score: 0

    I wonder what he has to say.

  5. not just fortnight. by nimbius · · Score: 4, Informative

    When you go to download "Fortnite" you don't actually download the whole game, you download the Fortnite Installer first.

    so this is actually a common method for a lot of applications in the play store as well. its the lazy app developers "curl|sudo /bin/bash" approach to installation. The difference being many of these other apps paid their play store fe--er, i mean those applications are protected by Google.

    --
    Good people go to bed earlier.
    1. Re: not just fortnight. by Anonymous Coward · · Score: 0

      Yeah it is stupid to make sure the apps are safe. It should be a free service. College for all, free medical care, diners that stay open for nostalgia while losing cash, you know the old smash and grab politics of the left. Wave the flag get your head beat in because fascism or whatever they hate today. But it has to be free see.

    2. Re: not just fortnight. by Anonymous Coward · · Score: 0

      You seriously need to grow up and read a book.
      And stop listening to Fox News

    3. Re: not just fortnight. by blahplusplus · · Score: 0

      Yeah it is stupid to make sure the apps are safe. It should be a free service. College for all, free medical care, diners that stay open for nostalgia while losing cash, you know the old smash and grab politics of the left. Wave the flag get your head beat in because fascism or whatever they hate today. But it has to be free see.

      Gee it's shit like this that makes me think the world has gone downright insane, there is no real left wing movement in america. There is one party, the party of big business with it's two wings republicans and democrats.

      Indeed america is filled with raging communists given the bottom 80% of society holds a meager 5% of the total financial wealth of the economy.

      https://whorulesamerica.ucsc.e...

      If numbers and science were anything to go by, if you are working class or poor and aren't left wing and american, you are pretty damn uninformed. But that's america for ya.

      George carlin said it best about american citizens:

      https://www.youtube.com/watch?...

    4. Re:not just fortnight. by Anonymous Coward · · Score: 0

      Explain how on Android one app can install apk of different app with full permissions without even notifying user.
      Sounds like shitty security.

    5. Re: not just fortnight. by Anonymous Coward · · Score: 0

      When you complain that other people are wealthier than you, you are just being a jealous ass.
      If you have enough to eat, if you have a home, clothes... then whining that someone else has more food, or better clothes, is just pathetic.

      I don't give a fuck that I'm in the bottom 80% of the US wealth distribution. Who cares that Musk and Brin can buy thousands of hookers and tons of blow? Are you really so small-minded that the thought of someone else having more than you makes you so angry?

      If you are starving, if you are homeless - THEN you can complain. But petty envy just proves how shallow and pitiful an existence you are.

    6. Re: not just fortnight. by Anonymous Coward · · Score: 0

      If you think that wealth inequality and collusion of capital and politics is about jealousy over clothes, you might as well excuse yourself from future discussion.

    7. Re: not just fortnight. by Anonymous Coward · · Score: 0

      The bottom 80% of society in the US is far better off than most of the world.

      The fact that the top percentages in the US owns a lot of wealth, is because the US has been incredibly successful at creating wealth.

      Leftists are near-universally psychopaths. Any well-known political gathering of leftists scores towards the top of the medical scale of psychopathy: http://www.minddisorders.com/Flu-Inv/Hare-Psychopathy-Checklist.html

      glib and superficial charm
      grandiose (exaggeratedly high) estimation of self
      need for stimulation
      pathological lying
      cunning and manipulativeness
      lack of remorse or guilt
      shallow affect (superficial emotional responsiveness)
      callousness and lack of empathy
      parasitic lifestyle
      poor behavioral controls
      sexual promiscuity
      early behavior problems
      lack of realistic long-term goals
      impulsivity
      irresponsibility
      failure to accept responsibility for own actions
      many short-term marital relationships

      Check Hollywood up against this.

      And the effect is that when leftists get enough power to put their plans into action without a real opposition, society becomes some dystopian horror movie.

      You could also check this against Trump.....

    8. Re: not just fortnight. by Maritz · · Score: 1

      Do you argue against real points, or just this embarrassing straw man shit? I mean, I'm cringing for you, it's that fucking pathetic. Find some shame from somewhere, people might start liking you more.

      --
      I do not want your cheap brainburning drugs. They are useless for work. And I am a working man today.
  6. it's like a boot disk... by MJhasHIV · · Score: 1

    or something

  7. Just another Epic stupid way of doing things? by Anonymous Coward · · Score: 0

    Wanna see a stupid way of doing things? https://www.cnbc.com/2018/08/24/trump-paid-michael-cohen-more-than-what-he-stated-in-financial-disclosure.html

    Another? https://www.washingtonpost.com/opinions/tax-crimes-brought-down-al-capone-what-about-trump/2018/08/23/996cea04-a710-11e8-8fac-12e98c13528d_story.html

  8. Google-focused much? by Anonymous Coward · · Score: 0

    So a big-time publisher decides to avoid the 30 percent Troll (google) tax for their app.. and suddenly Google is there to the rescue to immediately identify an issue that hundreds of publishers already know and have dealt with in the past. This article is directly supporting the bottom line of the walled-garden methodology. The wall-owner is hell-bent on letting world+dog on why their wall is the best wall and if you don't like the wall.. and won't pay for the wall... you are somehow complacent in a lack of good judgment.

    Peace out.

    1. Re:Google-focused much? by Anonymous Coward · · Score: 0

      Pretty sure this issue has nothing to do with avoiding play store. Read advisory https://issuetracker.google.com/issues/112630336
      It's the official play store app that doe this second stage download. A lot of large apps do it.

  9. can I say... by shentino · · Score: 1

    Epic Fail?

  10. So generic installer, lets apps install software by Anonymous Coward · · Score: 0

    So a generic installer for a game allows other apps to install additional software.

    If an app is using the Fortnight/Epic installer, your phone has already been compromised--pretty much a non-issue

  11. Re:googles own damn fault. by Anonymous Coward · · Score: 0

    Maybe Google should offer a reverse progressive "store tax", but then the smaller developers would freak out about it. Cost plus 20% would be reasonable, but then Google would reveal its costs to the competitors. 30% of the app price should really be too much for any publicly listed company that wants to generate revenue and profit. Something must be done.

  12. Re: not just fortnight, KILL ACTUAL NAZI SCUM by Anonymous Coward · · Score: 0

    That's just what these RIDICULOUS NAZI FAGGOTS want you to think, their whole thing is being faggots online to demoralize "the left" lol. You're looking at it wrong, it's fucking hilarious.

    When Trump hangs they'll know too.

  13. Re:Android sucks by Anonymous Coward · · Score: 0

    If you buy a cheap piece of crap you get a cheap piece of crap.
    If you get a decent device running android its way better than the 5 years behind IOS devices

  14. private Galaxy Apps API by iTrawl · · Score: 1

    Leave it to Samsung to write code that allows apps to install without asking you to confirm permissions.

    --
    "Everybody's naked underneath" -- The Doctor
  15. Full permissions by Anonymous Coward · · Score: 0

    including apps with full permissions granted

    No doubt that 90% or more of those have no real need for those full permissions. Thanks Google, for allowing, even encouraging such behaviour.

  16. Re:So generic installer, lets apps install softwar by rjr162 · · Score: 1

    Exactly this and my thoughts.

    What this says to me is there's no checks on an application calling files belonging to another within Android.

    Granted security apps would need this ability, but by default android should block this and only grant by given permission, and in that case it doesn't seem like the Play Store would have helped as there's other Android apps I've downloaded from the Play Store that do similar things (including with purchasing optional add-ons etc)

  17. Not the only one by Anonymous Coward · · Score: 0

    Maybe not so much now given someone appears to have lit a fire under Gaben's ass to take security seriously but Steam and many games on it do the same thing. I stopped reporting things like this to Valve because they don't respond nor really give a damn.

    The entire Steam installer could be hijacked because not only did they not use SSL for many things, but in places where they did, it wasn't verified. Google really shouldn't be throwing stones anyway when they themselves live in glass homes (no pun intended).

  18. Malware? by Anonymous Coward · · Score: 0

    After downloading and running that installer on my Redmi 5A (it failed due to my phone not being in the list of supported devices), I rebooted it and got a weird message that the encrypted partition was corrupted (yes, I do use device encryption).

    I had to factory-reset it (as the message suggested), but it's probably compromised now.
    Dammit.

    1. Re: Malware? by Anonymous Coward · · Score: 0

      No, you're shitty Chinese phone probably just corrupted the filesystem on its own when the download used up a bunch of space on the partition.

    2. Re:Malware? by Anonymous Coward · · Score: 0

      So you ran something that wasnt supported, and it didnt work. I'm shocked !

    3. Re: Malware? by Anonymous Coward · · Score: 0

      Well, Xiaomi is much better than the other garbage.
      Also, I love "you're" grammar.

    4. Re: Malware? by Anonymous Coward · · Score: 0

      P.S. it was not even downloading anything - have you read my comment at all?

  19. Android is open! Android is free! by AmazingRuss · · Score: 1

    Android is broken... but you can fix it yourself with the source code!

  20. Makes me wonder... by Travelsonic · · Score: 1

    How many of these other applications that use similar installers have such vulnerabilities (irrespective of program, or the platform they run on)? This is a trend I'm seeing a lot, "installers" that download the program, rather than just installing them.

    --
    If you believe in privacy, and believe you have "nothing to hide" at the same time, you're a goddammed idiot
  21. Color me obvious by shanen · · Score: 1

    If I ever got a mod point I'd probably give that one a funny, though there's an element of insight, too. Other aspects of the problems are too obvious for comment.

    Instead, I'll just ask again for solution approaches. Obviously signed code from reliable sources is one, but I'd prefer to see the Google stop abusing everyone and start using some of the information in our favor. In the Android app case, that would involve sharing the financial information to help the potential victims recognize the probably crooks.

    --
    Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.