Showing posts with label Android Apps. Show all posts
Showing posts with label Android Apps. Show all posts

Sunday, 1 November 2015

Fraudulent Android App Appears As A Word Document


Researchers regularly rogue Android apps by posing as porn app or Flash Player, but now there's also discovered a malicious app that will let the user into believing that it is a Microsoft Word document. For example, the icon of the app resembles that of Word.

The file allows users think that matters 'data'. If the file is opened, the app asks for administrator privileges. After installation, the malware seeks to SMS messages and other information like IMEI number, SIM card number, device ID, contact information and other matters and sends it to the attacker. The malware can also send text messages and dial phone numbers specified by the attacker. The app is aimed at Chinese users and is distributed outside of Google Play.

According to security firm Zscaler, discovered that the app is not surprising that PC-based malware techniques appear in the mobile domain, since mobile devices are now ubiquitous. For Windows, there is still active malware via common icons and file names occurs as a document and try to entice users to open.

Wednesday, 16 September 2015

Research: Security Popular Travel Apps Seriously Flawed



The security of the most popular travel apps for both Android and iOS seriously flawed, according to research from Bluebox. Travel apps have changed a lot over the years and now offer a variety of options, such as booking flights and hotels. Now these apps get advanced options this provides new security risks and increases the attack surface.

For the study looked Bluebox the ten most popular travel apps for both Android and iOS. Only one of the ten Android apps pale 'data at rest' to encrypt the device, while none of the iOS apps did. It also showed that using two of the ten Android apps and one of the ten iOS apps Certificate Pinning. Certificate Pinning ensures that an app checks the certificate of the server so that it communicates with the appropriate server. This is to prevent man-in-the-middle attacks.

According to the researchers is to integrate a best practice to Certificate Pinning in the app, but it appears that the developers of travel apps to do this. Even in the three-apps that may apply the technique it appears that it is only used for a portion of the network connection, so that the rest of compounds is unprotected. The survey shows that most travel apps with code from other developers have been made and not 'in-house developed. This increases the attack surface.

The researchers conclude that the security of mobile apps is still in its infancy and travel apps, in particular, to tighten up security. Consumers who receive these apps are advised to only download apps from Google Play or the Apple App Store, use the latest version of operating system and application, be careful about using public Wi-Fi networks and untrusted certificate authorities switch.

Saturday, 30 May 2015

Android Phone App Lets Look Unnoticed Porn


Google Play researchers again several malicious Android apps encountered after installing the device unnoticed kinds of porn sites and make visits to these sites to open multiple links and advertisements. In late April discovered anti-virus company Avast called "Dubsmash 2 app" on Google Play that was downloaded between 100,000 and 500,000 times before Google removed these.

Once the app actively trying to hide from the user and then visited several pornography sites in the background. Presumably the creator got paid for clicks that generated the app. Clicks that advertisers think they are carried out by people. Although Google removed the app there are recent days several variants of the app on Google Play appeared as late as anti-virus company ESET know.

Apps that should keep Google actually, say the researchers from the company. In a period of several days, several variants of the Trojan Dubsmash 2 uploaded and removed by Google. Yet one variant in two days would have been downloaded about 5,000 times. A total of nine discovered called Dubsmash 2 apps which were in reality "porn clickers". Once active every minute is charged a porn site, followed by a random click pattern.

"Although click fraud causes no direct harm to victims, such as to steal passwords, generates a lot of traffic and thereby generating additional costs for victims who have a data limit, so they remain at the end of the month with a high phone bill" , the researchers note. Which argue that Google Play has some weaknesses, given that the same malicious app could be placed several times on the app store before they intervened.

Wednesday, 25 March 2015

Half Of Android Users Would Be Vulnerable To Attack APK


Android Users who install apps outside of Google Play and an old Android version use are vulnerable to a new attack. It was estimated to be half of all Android users, warns security company Palo Alto Networks.The actual number is probably much lower.

Through the vulnerability could allow an attacker to break into the installation of a seemingly safe APK file and replace it with an app of choice, without the user noticing. The security issue is caused by an error in the system service "Package Installer" of Android, allowing attackers unnoticed can get unlimited access rights. During installation let Android Apps see what permissions they need in order to work properly. A Messages app, for example, require access to SMS messages, but not to the GPS location.

The vulnerability gives attackers the ability to deceive users by a false, smaller set to allow access rights to see. In reality, the user, if he chooses to install the app, just give access to all services and data on the device, including personal information and passwords. The problem is present in Android 2.3, 4.0.3-4.0.4, 4.1.x, and 4.2.x and some distributions of 4.3. According to Palo Alto Networks uses about half of Android users one of these versions.

The actual number of users that are at risk is likely to be much lower. The security issue because only occurs at Android apps that are downloaded from third parties and unofficial marketplaces. It does not apply to apps downloaded from Google Play. These files are downloaded namely in a safe environment that can not be modified by an attacker. Owners of Android devices vulnerable therefore be advised to only download apps from Google Play.

Tuesday, 17 March 2015

Kaspersky launches free anti-theft app for Android


The Russian anti-virus firm Kaspersky Lab has a free Android app launched that allows users to track their phone in case of theft or loss, or can remote wipe. The app is called Phound and offers several options. A device can be so if it is lost or stolen will be blocked. For this, the user must first log on to a special website.


Via GPS, GSM or Wi-Fi networks, it is then possible to find the position of the device. To search for the device to simplify users can also take pictures with the front camera, or display a message on the screen of the device. If the phone or tablet at home or lose the office, it can be detected by the alarm function. The device produces a loud noise and thus goes through until the owner enters a code.

The app also offers the possibility to remotely delete all personal information from the device and the SD card, including contacts, messages and photos. If necessary, it may also be performed a hard reset of the device. The police warns regular owners of smartphones, laptops and tablets to install anti-theft software, as these programs in the event of theft can help in the investigation .

Wednesday, 4 February 2015

Durka Malicious App: Apps On Google Play Store Infect Millions With Adware


Researchers have found several apps on Google Play that occur as games, but found to contain a million times and downloaded in reality adware. Some of the apps, including the card game Durka, activate the existing adware only after 30 days.

The adware ensures that when users unlock their device, they get a warning that their device is infected or outdated or full porn state. Then you will be asked to take action. If users are being redirected to come dubious apps and app stores herein secretly send text messages or collect all sorts of personal information. In some cases, users refer to security apps on Google Play.

Anti-virus company Avast thinks the adware distributors get paid for generating traffic to the apps and app stores. "Most people will not find out the cause of the problem and will have to deal with every time ads as they unlock their device," says analyst Filip Chytry. He thinks that most people end up trusting the solution offered, which can lead to more unwanted apps or costs. Besides Durka also involves an IQ test app and an app on the history of Russia. The apps are downloaded together between 5 million and 10 million times.

Hashes:

BDFBF9DE49E71331FFDFD04839B2B0810802F8C8BB9BE93B5A7E370958762836 

Tuesday, 27 January 2015

Research: Weak Encryption In Popular Android Apps


Many of the popular free Android apps in the Google Play store use weak encryption to protect sensitive information. Which claims that the US security firm FireEye 9339 apps with more than 1 million downloads analyzed . Of these, 8261 were found to use a cryptographic functionality of the Android platform. 8261 of these apps again proved 5147 apps (62%) contain one or more cryptographic vulnerabilities.

It involves, for example using static keys for encryption. These keys can be removed from the app and then to decrypt the data. This was 21% of the apps the case. Furthermore, 58% had to use a weak encryption algorithm that the apps are vulnerable to certain attacks. For a handful of apps was also developed an attack. One of these apps accepted all dished SSL certificates, allowing attackers to perform a man-in-the-middle attack.

According to the researchers cryptographic vulnerabilities are a serious threat because they enhance the effectiveness of other attacks. Through the misuse of SSL could intercept an attacker instance sensitive information. "This problem is compounded by root exploits in which an attacker rooting a device can determine which apps are installed to send random data for offline decryption" concludes researcher Adrian Mettler.