Showing posts with label Android. Show all posts
Showing posts with label Android. Show all posts

Friday, 30 October 2015

Google Would Work On Android Version For Desktops


Google is currently developing an Android version for desktop computers, so let sources opposite the Wall Street Journal and The Verge know. Next year, Google would be working with several manufacturers to produce desktop computers running Android.

It would ultimately be the intention of Chrome OS and Android to combine one operating system as supporting and developing two different operating systems is costly and confusing for manufacturers can be. The emphasis on Android does not mean that Chrome OS will soon disappear, the Chrome-based operating system that is used in many cheaper laptops called Chromebooks.

Manufacturers who produce Chromebooks will be able to still use Chrome but also have a choice of Android, says Re / code.Google CEO Hiroshi Lockheimer, senior vice president of Android, Chrome Cast and Chrome OS, leave via Twitter that Chromebooks still much in demand, and Google is Chrome OS remains committed.

Wednesday, 21 October 2015

Google Requires Full Disk Encryption In Android 6.0


Manufacturers smartphones and tablets with Android 6.0 supply should ensure that full disk encryption is enabled by default, according to documents (pdf) which Android Police post. Initially, Google "encryption by default" is already available in Android 5.0 Lollipop.

Later, the Internet giant decided right there to see it from. Now Google has announced that for implementations that support full disk encryption and where cryptographic calculations using the Advanced Encryption Standard (AES) over 50 mebibyte per second come standard full disk encryption is enabled. Devices with an older version than Android 6.0 were launched outside of the new obligation, unless they full disk encryption already supported. That was only the Nexus Nexus 6 and 9.

However, Google does not oblige users to turn on the screen lock. For these users, there will be a default for the disk encryption are used. When the user eventually chooses to disable the screen lock the device does not need to be re-encrypted, which could take a long time.

Sunday, 20 September 2015

Expert: Lock Screen Phone Will Never Be Watertight


This week it was announced that a leak in Android 5.x makes it possible to bypass the lock screen, but as a developer of the Plasma Phone this kind of problem will always be present and screen lock can not provide watertight protection against a physical attacker.

The Android vulnerability has been patched by Google, but the update has not yet appeared for all the different models and manufacturers. Unlike a screen lock on the desktop may apply for a different phone lines. So the phone should still be able to accept incoming calls, even if the screen is locked. In addition, there must be interaction with notifications, for example, an alarm clock, are possible. Also, it should be possible to make emergency calls on a locked phone.

"These exceptions conflict with the requirements of our lock on the desktop. That is, blocking input devices, so an attacker can not communicate with the active session," said developer Martin Grasslin. The requirements set that it must still be possible at a locked phone to communicate with a running session and also be input devices, such as the keyboard, not blocked.

Grasslin has in recent months been thinking a lot about how these requirements can be combined without compromising on safety and has not found a solution yet. "The only thing I see is that if we applications such as the phone app, let's bypass the lock screen, we actually add a hole on the architecture and if there is a hole to penetrate you thereby. There will always be a way to bypass security, "he noted.

Target lock screen

According Grasslin must be also looked at the intention of the lock screen. On the desktop computer is simple, namely that getting someone with a mouse or keyboard can not access the active, locked session. For a phone this is different, especially if an attacker has physical access. "If someone has enough time, it is unlikely that the attacker can be kept outside and the screen lock is probably not the weakest link in the chain."

It is therefore not possible to blocking input devices, but that people can not see the contents of the phone during an unguarded moment. In this case the now unveiled Android leak not really matter, as it takes some time to execute. "The screen lock prevents access by ignorant people and also by people who only have the same access to it. It's only a problem in situations where it would not matter much, because if you have the device already physically in your possession," said Grasslin.

Wednesday, 16 September 2015

Android Vulnerability Allows Attacker Bypass The Screen Lock




Researchers at the University of Texas have discovered a vulnerability in Android 5.x could allow an attacker with physical access to bypass the lock screen of the device, even if the encryption is enabled. By first turn on the camera app and then typing a large number of characters in the password field allows an attacker to crash the lock screen, so that the home screen is displayed.

It is then possible to start any application or access can be enabled via ADB, in order to gain full access to the device. To carry out the attack, an attacker must have physical access and the user must have enabled a password. In the case of a PIN code or lock pattern, the attack would not work. Google was on June 25 informed by the researchers. On September 9 released Android 5.1.1 build LMY48M where the problem is corrected.

This update was last week among Nexus devices from Google itself rolled, but it is unknown when users of other Android devices will receive the update. Google develops updates for Android and can roll under its own Nexus devices. In other cases, users are dependent on their manufacturer or network provider before they get the update. A process that can sometimes take weeks or months.

Tuesday, 15 September 2015

Google Patches Nine Vulnerabilities In Android Patch Round


Last month, Google announced that a monthly patch cycle went input, which it first updates for Stage Fright leak were released. During the round patch of September, the Internet giant nine vulnerabilities fixed, two of which are labeled as critical.

Through Critical vulnerabilities an attacker could execute code remotely on the device, for example by sending an MMS message. One of these critical vulnerabilities had already actively attacked before the update was available. The other critical vulnerability relates to one of the Stage Fright leaks last month not fully been patched. The updates are only for Nexus devices and are over-the-air (OTA) are offered.

Friday, 14 August 2015

Google Update Does Not Protect Against Stage Fright Leak


The update that Google has released the Critical Stage Fright flaw in Android does not work, say researchers from security firm Exodus Intelligence . However, Google will continue to roll out the faulty update, so let them know on their own blog. Through Stage Fright an attacker could install malicious apps on Android phones by just sending an MMS message.

On July 31, Jordan Gruskovnjak researcher claimed that there was a serious problem with the proposed patch of Google.Since the update itself had not yet been rolled out, the investigator could not confirm his suspicions. Last week, Google released the update finally out so Gruskovnjak could test whether the Stage Fright leak was indeed completely solved or not.Eventually he managed to create an MP4 file which the update could circumvent and to crash the device. The researcher warned Google on 7 August, but received no response.

Then Exodus Intelligence decided to publish details about the issue. The company states that they are probably not the only ones who have discovered that the update does not solve the problem entirely. In addition, would Stage Fright Detector app from Zimperium, the company that discovered the vulnerability, incorrectly indicate that users are safe, even if that is not the case. Meanwhile work Exodus Intelligence and Zimperium together to improve the detection of the app. However, Google still has not responded.

Tuesday, 11 August 2015

New Android Apps Leak Allows Device Completely Take Over




A new vulnerability in Android gives attackers the opportunity to participate fully devices via a malicious app or install malware. The app need in this case not have to have special privileges, as there via the leak system rights can be obtained.

Once the app elevated privileges acquired, it is possible random apps that are already installed on the device can be replaced by infected versions, in order to steal passwords and other data, or SELinux policy of the device can be adjusted. The vulnerability is present in Android 4.3 to 5.1, as well as the M Preview 1, which represents more than 55% of Android devices.After being informed of the problem, Google in Android 4.4, 5.0, 5.1 and M patched and Google Play Services. This week researchers from IBM give a presentation about the leak ( pdf ).

Saturday, 1 August 2015

Seriously Android Leak Also To Attack On Apps And Websites


This week it was announced that there was a very serious leak is present in Android which allows an attacker installed on millions of Android phones malware by only sending a single MMS message. Stage Fright, such as the vulnerability is known, however, is also to attack in other ways, according to the Japanese anti-virus company Trend Micro .

Security Zimperium Stage Fright made known this week. Trend Micro says that it has also found the same vulnerability independently of Zimperium and on May 19 of this year has been reported to Google. This implies that at least two parties have discovered a critical vulnerability of this magnitude and this then Google decided to report.

Attack Vectors

Trend Micro, however, that there are more ways to use Stage Fright. In addition to sending an MMS message, an attacker can use an app to attack the vulnerability, and the use of a website. The vulnerability is caused by the way the Android media server handles MP4 files. This allows an attacker to cause a heap overflow and then execute arbitrary code such as installing malware.



In addition to sending a malicious MP4 file from an MMS message, it is also possible to embed such a file in a Web site or by allowing an app to open, and thereby infect an Android phone with malware. Google has already rolled out an update, but many Android users for patches depend on their telecom provider or manufacturer of the device if the device is still supported.According to Trend Micro, the problem in Android version 4.0.1 to 5.1.1, which represents 94% of all Android devices.

Monday, 27 July 2015

Millions Of Android Phones Vulnerable By New Leak



Researchers have discovered a serious vulnerability in Android which makes it possible to gain access to devices simply by sending an MMS message. Then an attacker can steal information, read emails, activate the microphone and perform other tasks. The vulnerability is in Stage Fright, a media library that handles various popular media formats.

Security Zimperium discovered vulnerability in the Android part, that the self worst Android leak calls so far. An attacker only needs namely to send an MMS message to execute code on the device. It is thereby even possible to remove the message before the user gets to see it. Only the acknowledgement is all that is visible. The researchers warn that the vulnerability is very serious, because there is no interaction from the victim is required.

Estimates suggest that 950 million Android devices running risk. The problem is particularly acute among Android versions Jelly Bean, which is about 11% of all Android devices. Zimperium warned Google that has already rolled out patches for Android. In many cases, telecoms providers and manufacturers are, however, responsible for distributing updates to their users and the security company also fears that it may take a long time before everyone is protected.

Two manufacturers, however, are a positive exception. Meanwhile the Black Phone Silent Circle is patched and Mozilla Firefox is protected from the issue. At the upcoming Black Hat conference in Las Vegas will have more details about the vulnerability are announced.

Sunday, 26 July 2015

Fraudulent Mobile Ads Consume Gigabytes Of Data



Fraudulent apps for both Android, iOS and Windows Mobile posing as popular games allow devices actually charging thousands of ads a day, without users having this in the first instance. However, the applications run continuously in the background, may consume gigabytes of data, ensure that the battery previously absorbed and are able to download more than 16,000 ads per day.

Then there are simulated random clicks on the ads, which get the developers of the paid apps. Average would be the apps on a device 700 ads download per hour, which amounts to 16 800 ads per day. It consumes about 2GB of data. Globally, there are more than 12 million devices with rogue apps are infected.

According to the US Forensiq have rogue apps produced last year for $ 857 million in damages and this year will be $ 1 billion to be passed. It should be noted that Forensiq a company engaged in the fight of advertising and click fraud. Google has already removed several of the rogue apps from Google Play, but would not say how many, reports AdvertisingAge .

Saturday, 18 July 2015

Google Removes Backdoor App From Play Store


Google has removed a rogue app from Google Play posing as a news app, but in reality it was a backdoor. The app used the name 'BeNews "of the now vanished news site with the same name, to look legitimate, say researchers at the Japanese anti-virus company Trend Micro . The researchers discovered the app in the data that was stolen by the Italian Hacking Team.

The app seems to have been developed in order to circumvent the monitoring of the Play Store. To protect Android users Google checks the content of applications for malicious code. Initially, the app asks for three permissions. Via dynamic loading technology, the app can also download and execute code from the Internet. The downloaded code will not be loaded when Google carries out the checks, but only when the app is used by a victim. The app can then use an exploit to increase its rights on the device. The exploit works on Android version 2.2 to 4.4.

In the stolen data, the researchers found also the source code of the backdoor and the server that can be used to communicate with contaminated devices. Trend Micro believes Hacking Team offered the app to customers, but there is no evidence. The app on Google Play downloaded between 10 and 50 times before it was removed by Google. The developer of the app on the Play Store has placed no other apps in the App Store Google. Google Plus account by this developer also contains no further information except a link to a "testing" area of ​​the app on Google Play.

Monday, 13 July 2015

Even If You Uninstall Google Photos App, It Will Keep SynchronizingYour Pics On Cloud




Nothing worse roll us not to be aware of when a device keeps going up personal information to the cloud or any other type of storage beyond our control. And something happens to Google Photos and mania still synchronize everything we took with our mobile even when we have installed on our smartphone or tablet application.


Saved cloud of Google

The story is roughly as follows. Some users have found that once removed from your mobile or tablet application Google Photos , concern still see quite how photos and videos obtained from the terminal just available in the cloud service of the Mountain View.

Is something like "remove the app from my mobile Android and Google remains committed to catch me everything I have on the phone. " Well, you must know that this is not true because Google Photos is a single viewer and organizer of everything we have in the cloud, and not the reason for that content to be there or will be updated every day.

In the oldest in the safe place that comes to my mind the account options Google brings Android series since its inception, and once inside we have active on your terminal see a lot of services that are managed from it.

How do I remove the automatic rise?

Among the options in this menu we manage Google account is that of sync contacts , calendars, and applications ... upload photos automatically. This is where you must act, telling the device to our account Google does not want to see anything in the cloud , so to disable root be cut any further rise.


Yes, but this option has traditionally been in the account menu Google , with Android M has changed its placement, leaving him to deactivate the rise in the menu of Backup .

In other versions of the OS of Google thing is more or less as usual, with specific options off camera rises to the cloud if we want, have or not the application of Photos in our terminal.So you know, if you no longer do you use the photographic manager of Mountain View , the photos and videos that might be coming to carry forth a cloud but be aware of it.

Wednesday, 8 July 2015

Fraudulent BatteryBotPro App From Google Play Removed



Google has removed a rogue app from Google Play posing as BatteryBotPro app and infected machines used for all kinds of fraud. The BatteryBotPro app is an app that displays detailed information about battery and battery consumption. The app, which 2.99 euros to be paid for, downloaded between 100,000 and 500,000 times.

Recently, criminals have downloaded the app and includes malicious modules, then place successfully on Google Play the custom app. Unlike legitimate app asks the rogue app administrator privileges to install. Once the user has authorized the app installed and will offer the same functionality as the legitimate app, says security firm Zscaler . In the background, the malicious app uses the device include committing click fraud and ads fraud.

This smartphone is used for displaying ads and generate false clicks on ads. In addition, the app also appears to gather information about the device and additional malicious apps to be installed without the user's permission has to give here. Next click and ad fraud app also aims to send text messages, which can cost the user money. After being informed, Google removed the app from Google Play. How many users have downloaded the rogue app is unknown.

Thursday, 18 June 2015

Researchers Have Malware In Apple App Stores




Researchers at Indiana University have succeeded in malware for Mac OS X and iOS to get into the App Store from Apple that allows access to sensitive data from other apps can be obtained. Examples include passwords to iCloud, your default e-mail program and Internet banking and the secret token for the note program Evernote.

It also showed that the design of the app sandbox on Mac OS X was vulnerable, so the malware could approach the private directory apps. The malware could thus have access to notes, and contacts that were stored in Evernote, as well as photos of WeChat. The researchers published their work in late May in a report ( PDF ) called "Unauthorized Cross-App Resource Access on Mac OS X and iOS." To prevent apps access to each other's information systems get fit "app isolation" to which each app is in its own sandbox.

It appears that in some cases for apps still be possible to access the "resources" of other apps, which the researchers call "unauthorized cross-app resource access" (XARA). It was known that this problem played in Android, but the researchers wanted to know whether Mac OS X and iOS are vulnerable. Two platforms, which are believed to be safer than Android, so the researchers in the report know. They discovered that the problem also affects the Apple operating system. Thus, the mechanism can be hijacked that controls access to the Keychain, so it is then possible to gain access to passwords and other credentials of apps and websites that are stored here.

Impact

"The consequences of these attacks are serious, including the leak of passwords, secret tokens and all kinds of sensitive documents. Our research shows that the problem is caused by a lack of authentication at app-to-app and app-to-system interactions "the researchers said in their conclusion. They developed a scanner to analyze binaries for OS X and iOS apps to determine if the proper protection measure is contained in their code or not.

More than 88.6% of the 1612 popular Mac apps and 200 iOS apps were completely vulnerable to a XARA attack, which could steal a malicious app security information. Apple would be informed by the researchers in October 2014 and then asked to wait with the publication of the report, but the investigators would have since heard nothing more, reports The Register . The problem in Mac OS X 10.10.3 and 10.10.4 still present.

Sunday, 7 June 2015

Dropbox Prohibits 85,000 Words As Passwords



To prevent users from weak or easily guessed passwords choose Dropbox uses an extensive list of forbidden words. This was discovered by researcher Jerod Brennen by the Dropbox app to extract through the program 7-Zip. Both APK files on Android and iOS IPA files are really just zip files, in all but name. In the app, he found a file called pw.html, from what appeared to be 52 lines of JavaScript.

The script aims to prevent Dropbox users choose weak passwords when creating an account via the mobile app. The script uses a line with 85 100 banned words that should not be chosen as a password. These are words like password, computer and qwerty up of figures as 123456, 696969 and 111111 to combinations as abc123, passw0rd and 1234qwer. Also notable is the large number of obscene words that should not be selected. According Brennen that the online list has put, security professionals can add the word to their own lists and tools.

Wednesday, 3 June 2015

Bug In Skype Chat Fixed


The bug in the chat function of Skype's already solved: Skype has released a software update.
In the chat you came into trouble if you typed the following characters and sent: http: // :. Then crashed chat program. Even if you got sent to the characters: Skype quit and each time the program rebooted, the chat service crashes again.


The bug affected only people who use a Skype version for Windows, Android or iOS. The problem did not occur with the Mac version and those using the touchscreen version for Windows 8, reports VentureBeat .

On skype.com/download can now download the latest version of the program.

iMessage crash

A painful situation for Skype, says tech editor Nando Kasteleijn. "Especially because typing http: // :. prevents faster than the strange series that marks late crash iMessage So if you want to send a link to someone, you better direct copy and paste the entire URL. "

SkypeSupport We need a new version of Skype asap. Crashing Bug Affecting phone and desktop clients.- Rafael Rivera (WithinRafael) June 2, 2015

Last week it was announced that a message with a series of strange characters include your iMessage, WhatsApp and Twitter Account may crash. "It is striking that several platforms prove to crash relatively quick succession after entering certain characters," said Nando.

Skype has thus solved the problem and that's a lot faster than Apple.

Friday, 22 May 2015

NSA Wanted To Infect Android Users On Google App Store


The US National Security Agency has set up a project in the past which attempted to infect users of the Google Play Store and Samsung App Store with spyware, according to documents from whistleblower Edward Snowden of late 2011 and early 2012 date.

According to the documents sought the NSA and British, Canadian, New Zealand and Australian intelligence agencies to find ways to attack smartphone users. Through the previously disclosed XKEYSCORE system smartphone traffic was identified.Through another project that had looked into development of the connection from the user to the aforementioned app stores was to hijack so that could then be controlled via a man-in-the-middle attack malignant "implants" to the smartphone .


In this way the intelligence services could monitor the target then. In addition to using the app stores as a springboard for the spread of spyware intelligence also sought ways to hijack them and spread misinformation among targets. Also wanted the intelligence to access the app store servers so that they could gather information about users, so notify the intercept and CBC News .

UC Browser


The documents also show that the intelligence services had discovered vulnerabilities in UC Browser, an immensely popular browser in Asia, and particularly China and India. Worldwide, 500 million people would use the program. The browser was found to leak all kinds of information over the phone. Information used by the intelligence services too. Canadian CitizenLab UC Browser has studied because the documents in April and discovered numerous vulnerabilities, which have now been remedied through an update. Google declined to comment on the findings and Samsung has given no substantive response.

Full Document Report

Monday, 27 April 2015

Malicious Word Document Hidden In A PDF File


Frequently happens that attackers use DOC and PDF files to infect internet users with malware, but recently a researcher found a PDF file called "Sales Invoice" that contained a malicious Word document.When opening the PDF file is via Javascript tried to open an embedded Word document. Standard warns Adobe Reader to open these embedded files.

If users ignore the warning and still choose to open the DOC file in Microsoft Word, then get them whether they want to run the macro in the document. In recent months, regular Word documents with macros used , which once carried download malware. Also in this case, it is after the execution of the macro malware downloaded. It is a variant of the Dridex banking Trojan, a Trojan horse that steals money from online bank accounts.

According to researcher Steve Basford the malicious Office documents at the time only against Windows users. "Apple and Android software to open these attachments and might even run the macros embedded in the annex," he tells his own blog.Belgian researcher and ISC handler Didier Stevens made ​​this demonstration video in which he analyzes the PDF file.

Monday, 23 March 2015

Encrypted SMS With Android App SMSSecure


Announced a new app for Android should make it possible again to send encrypted text messages, now another popular Android app that made ​​this possible is stopped. Recently showed Open Whisper Systems , the developer of Secure Text, know that the support of encrypted SMS / MMS is stopped.

According to the developer will be encrypted SMS / MMS never easy to use as encrypted text messages, because users in encrypted SMS manual should exchange the encryption keys before it can be communicated. "We believe that people should not even know what a" key "is, so this obstacle always felt wrong," said the developers.

Also mentions Open WhisperSysms SMS and MMS a "security disaster", because metadata is continuously leaked. SMS messages pass through the servers of telecom companies. The developers do not want the state-run telecom companies like Saudi Arabia, Iran or China can access the metadata Text Secure users. Finally, the support of SMS / MMS make it more difficult for the developers in order to improve the app.

SMSSecure

On GitHub is a new app called appeared SMSSecure , a fork of Text Secure. It is a spin-off based on the source code of Text Secure and focuses on encrypted SMS messages. To go with the app to work there needs to be an unencrypted backup Text Secure, which can then be imported by SMSSecure. SMSSecure developed by the Frenchman Bastien Le Querrec.

Monday, 9 March 2015

Malware Infected Xiaomi Smartphone Appears Counterfeiting


Last week there was a fuss about Chinese smartphone manufacturer Xiaomi standard that malware would be delivered, but now it is confirmed that it is a counterfeit device. Bluebox security company published last Thursday a blog posting about malware that was found on the Xiaomi Mi 4 LTE smartphone. The company had bought the unit in China.

When scanning of the apps on the smartphone was found one suspect app, allowing users of information risk could walk.Initially the Chinese smartphone manufacturer would not have responded to the findings of Bluebox. After publication of the research did however a response, which the company claimed that there was possibly purchased a manipulated device.

Bluebox had purchased over the phone namely a physical supplier, while Xiaomi China does not sell equipment through "third-party" parties. The aircraft would only online and through the shops of telecom providers are offered. Then again Bluebox responded with criticism, because it was apparently possible for stores or anyone in the distribution chain to adjust the devices.

Counterfeit
After an extensive testing on the basis of all kinds of pictures is now been established that it is a counterfeit Mi 4. The unit was so well imitated that it initially also managed to circumvent a special app Xiaomi for detecting counterfeit devices. The latest version of the app can now detect the counterfeit version.

According Bluebox let the incident shows how important it is for companies to take researchers reports seriously and work together. Further notes the security of the supply chain, where it happens that consumers compromised smartphones can purchase. Finally, the tools to identify counterfeit goods must be improved.