ads

dimanche 13 septembre 2015

[Q]Can an app keep onto its root access after reboot?



Hey guys! I'm new to this community so first of all I want to say hello to you all! Sadly my arrival is mostly based on a possible-problem for me.
So here's the situation:

1- Bad Guy runs an app on Good Guy's phone that asks for root access, this app is malicious and can be used to steal almost everything (like theftspy that was developed by a dev from xda)
2-Bad Guy grants it the access and sets SuperSU to "grant on demand" for this specific app. Then deletes all the logs of all this and removes this app from APPS tab of SuperSU.
3- Good Guy is completely unaware of all these.
4-A few weeks later Good Guy learns that this Bad Guy could have been installed an app on his phone that can steal sensitive information. He performs an Avast Mobile Security scan that returns clean and later performs a complete wipe of his phone and loads a new ROM.

So I'm the Good Guy here :p I confronted Mr. Bad Guy about it who ultimately denied that, but I got some strong suspicions that he might be lying. Data in the phone was private (mostly business) so even the probability of this being stolen is scary.

Without any further ado my question is: Can this malicious app keep onto its root access after a reboot (can any app do that)? Because if it can not, then even if it starts itself after boot, it'll have to grant root access again which would leave logs and would be seen on SuperSU this time, which neither was there so would mean I am safe. Also is Avast's scan result reliable on this basis?

Thanks to everyone who took their time to read, any help is so much appreciated.



Aucun commentaire:

Enregistrer un commentaire