Showing posts with label Android Smartphone. Show all posts
Showing posts with label Android Smartphone. Show all posts

Wednesday, 18 November 2015

Gmail App Allows Spoofing


The Gmail app for Android installed already standard on many smart phones, enables users to send spoof emails. Google acknowledges the findings, but still taking no steps to remedy it.

Security Researcher Yan Zhu discovered that it is possible in the Gmail app to send emails from a fake sender address. The trick is very simple and will only work with the Gmail app for Android.


If the display name is changed in the settings, the app itself removes the real address from which the message is sent. For the receiver it is therefore difficult to check the sender via the headers. For demonstration Zhu sent a mail from the account security@google.com.

Although not found bug is serious, it can easily be abused. Spoofing is a technique widely used by cyber criminals to lure potential victims to a particular site.

Yan Zhu its findings in late October when Google reported, writes Motherboard, but who denies that this is a vulnerability.

Thursday, 12 November 2015

F-Secure Reveals WiFi Router For Internet Of Things


The Finnish anti-virus firm F-Secure today announced a new device unveiled it as a kind of Wi-Fi router 'for the Internet of Things can be seen and monitors all traffic for malware, adware, phishing, tracking and other threats. Sense, such as the device is called, must be connected to an already existing router.Sense then create a secure network where traffic from all devices in the home is long.

This involves the movement of laptops, smartphones, game consoles and IoT devices. The traffic is then monitored for any threats. Thus devices can also be protected where it is not possible to install security software. It may also block undesired Sense tracking. What exactly is understood to mean here is still unclear.

In addition Sense also comes with a Sense app, which devices such as laptops, smartphones and tablets can be installed.The app must ensure that the devices are also protected if they leave the house. It is also possible to manage the safety of all connected devices via the app. Possibly the router will also be enhanced with new features, such as protection for Internet banking and a VPN to surf anonymously.

Sense supports Windows 7 and newer, and newer Android 4.0 and iOS 8.4.1 and newer. In addition to Wi-Fi (IEEE 802.11a / b / g / n / ac) are also three Gigabit LAN ports offer gigabit and WAN port. The hardware should appear in the spring of next year and the rate for the first 5,000 preorders 99 euros. The normal amount is 199 euros. In addition, after the first year, 8 per month to pay for the subscription.

Friday, 6 November 2015

BlackBerry Comes With Monthly Android Updates


Smartphone manufacturer BlackBerry is echoing include Google and Samsung also monthly Android updates will roll out, as it has announced. In the case of very serious Android leaks from the patch cycle will be rejected and the updates are immediately dispersed.

BlackBerry receives, like other manufacturers, each month a list of Google with recently discovered vulnerabilities in the Android platform. A month later, Google announced these vulnerabilities. According to David Kleidermacher BlackBerry is therefore important that the updates previously been patched. The smartphone manufacturer will therefore be rolling out monthly updates. The updates are currently only for the BlackBerry Priv, the privacy of the telephone company.

In the case of very serious vulnerabilities, for example, which are remote exploits, BlackBerry can intervene earlier.Depending on the severity of the vulnerability, the complexity of the update and time in relation to the monthly patch cycle, BlackBerry will roll out a "hotfix". In that case, the update for the problem is rolled out directly among users. Before rolling out the BlackBerry hotfixes working together with partners, but if necessary, the smartphone manufacturer may choose to distribute the update directly without the intervention of third parties.

Thursday, 22 October 2015

Survey: 75% Second-Hand Hard Drives Contain Data


Used hard disks and smartphones through Amazon, eBay and Gazelle offered often turns personal data to be outdone, such as photos, videos, e-mails, call details and SMS and instant messaging, according to research from the Blancco Technology Group and Kroll Ontrack.

After more investigation showed that 57 percent of mobile devices and 75 percent of the discs actually an attempt was made to remove the material, but these attempts were not successful. The research also shows that simply deleting files on a hard drive users mistakenly feel safe. With four of the remaining data disks were the data via the delete button or by moving the deleted files to the Recycle Bin.

It quickly or completely format an old hard drive are commonly used but unreliable methods, the researchers said.Analysis showed that 61 percent of the disks where data remains were found the command "quick format" was used.

Smartphone

Another problem is also difficult to remove data from smartphones. At 57 percent of the smartphones with leftover data was tried to remove, but there were a total of 179 text messages, 252 IM and 75 great photos behind. In total 10 838 2153 e-mails and text messages and instant messages were found on the analyzed devices.

Thursday, 6 August 2015

Reservation OnePlus Weather "Hacked"



The system where people can reserve the new phone phone manufacturer OnePlus again "hacked" and once again it was Jake Cooper, disgruntled user who is also the first hack made ​​public. Shortly launch OnePlus the OnePlus 2. In order to qualify for the appliance must have potential buyers about an invitation, after which they are placed on a waiting list.

OnePlus offers people on the waiting list the opportunity to improve their position depending on how many people they invite to the waiting list. This allows Cooper dropped a spot around 9000 to a position around 70,000. He compiled a script that used disposable email addresses to invite people called for the waiting list, which improved his own position. Eventually he points this place in 1694 to reach the waiting list.

After this problem was solved Cooper discovered a new way to manipulate the waiting list. Instead of disposable email addresses, he now used the possibility of Gmail to create aliases for its own char e-mail address. Eventually he could in this way with a brand new Gmail address will be place on the waiting list in 2299. Meanwhile, also this method to manipulate the list addressed by OnePlus.

"We knew this was possible, and have monitored the list on this type of behavior. It is not common, but it is noticeable. We have already taken a number of measures to reduce it, but before invitations are sent, we will List first check for fraudulent registrations, and we continue to introduce new measures to combat it, "said OnePlus at the forum , which Cooper thanked by surname. Because of his efforts, he now gets an extra early invitation.

Tuesday, 4 August 2015

Dissatisfied User "Hacks" Booking OnePlus



Soon OnePlus phone manufacturer has launched a new phone, the OnePlus 2, but the way the device is put into the market, one user was not tasty. To qualify for an extension must have potential buyers about an invitation. Jake Cooper had first bought all the OnePlus One and decided then also in writing in time for the new model.

That earned him a spot around 9000 on. OnePlus offers people on the waiting list, however, the opportunity to improve their position depending on how many people they for the waiting list to invite. Thereby Cooper dropped to a place around 70,000.He compiled a script that used disposable email addresses to invite people called for the waiting list, which improved his own position. Eventually he points this place in 1694 to reach the waiting list. After his method was published in a blog warned Cooper OnePlus. However, the phone manufacturer has not responded to his tweet.

Friday, 31 July 2015

Hacker Makes Tool To Unlock GM Cars Remotely



The well-known hacker Samy Kamkar has a tool designed to cars from manufacturer General Motors (GM) are located remotely open and start. GM offers car owners a service called OnStar with which the car can be found via a smartphone app, opened and started.

Kamkar developed for 100 dollars a small device, the OwnStar that a car or truck should be placed and the communication of the smartphone to the app to intercept. The problem with the app is that SSL be used to exchange encrypted data, but the certificate does not correctly check to ensure that there is communication with the real OnStar servers.

The Ownstar consists of a Raspberry Pi and three radios and can occur as a friendly network. Once the user's GM Remote Link app launch and the smartphone within range of the device is a man-in-the-middle attack is carried out in order to steal the user's credentials. Then these data are from a 2G GSM connection is sent to the attacker. With the login information, an attacker then follow the car, open the doors, start the engine or to sound the horn or alarm.

Starting on distance is not possible, this is still requires a human operator. GM is now working on an update to address the problem, as a spokesperson of the automaker opposite Wired know. During the upcoming Def Con conference in Las Vegas will Kamkar provide more information about his attack. The following video shows already see a short demonstration.

Saturday, 4 July 2015

Virus For Android Smart TVs Launched



An increasing number of television sets to have "intelligent" capabilities, which often means that they are connected via a mini-computer with the internet. There are several operating systems to drive the smart televisions, including Android TV Google.

The Russian anti-virus company Doctor Web already had a virus for Android smartphones, but now has a product specifically for smart televisions, media players and consoles launched that run on the operating system. "With the advent of the Internet of Things (IoT) era are not only computers and smartphones that run the risk of becoming infected, so they need anti-virus protection," said the virus fighter.

It would be particularly Android devices that are connected to the Internet and allow users to install software from unofficial marketplaces or USB drives that run according to Doctor Web risk. In case the Android TV device supports a remote control, the remote control can also be used to control the virus.

Thursday, 28 May 2015

Android Ransomware Not Give Paying User Penalty


Last week, more than 15,000 e-mails are sent with Android ransomware that occurs when a security update for Adobe Flash Player. The messages contain little text, except that the enclosed APK file, "Check Updates.apk" is an update to Flash Player.

In reality, it is ransomware that locks the device and a warning from the FBI shows. According to the warning, the user would have viewed pornographic websites. To unlock the device must be an amount of $ 500 to be paid. If the user attempts to unlock the device, the amount is increased to $ 1,500, reports the Romanian antivirus company BitDefender .

According to the Spanish security company S21sec ransomware makers find new ways to spread their creations. Currently used mainly social engineering, but new capabilities are added continuously, according to the IT security officer. Users also are advised to install APK files from untrusted sources and email filtering with MOT attachments.

Friday, 22 May 2015

Dozens Minecraft Apps On Google Play Prove Scareware


On Google Play, researchers from the Slovak anti-virus company ESET found dozens of apps that occur as cheats for the popular computer game Minecraft, but in reality scareware. It involves a total of 33 applications that were placed on Google Play over a period of nine months and have been downloaded between 660,000 and 2,800,000 times.

The apps do not do what they promise and show after starting only banners claiming that the Android device with a "dangerous virus" infected. Then offered to remove the virus, for which there should be a "virus" via SMS enabled. However, it is an SMS user subscription costs 4.80 euro per week. ESET recommends that Android users to still only download apps from official app stores, to check what permissions the app asks and be read reviews from users.

Saturday, 9 May 2015

Man Acquitted Of Possession Of Child Pornography For Malware


A 37-year-old American was acquitted of possession of child pornography because malware was on his smartphone, so has an assistant prosecutor of Franklin County announced. The man was arrested for an extensive whiskey theft which he has now also known.

More than five years would have the American whiskey from a distillery stolen and resold. While investigating the man was also examined its smartphone, which child pornography was found, as did News Graphic end know of April. Further research showed that there was no foul play, said the assistant prosecutor. "The images were caused by malware or ransomware who had downloaded files automatically," so let him know .

The American finally made ​​a "plea deal" with the prosecutor. That agreement also states that the child was the result of malware, reports Kentucky.com . For whatever malware it is not disclosed, but both last year and early this year discovered several researchers ransomware variants which indeed showed child pornography on Android smartphones and mainly had a large number of devices in the US infected.

Thursday, 19 March 2015

9 Year Old Demonstrates Attack On Android Smartphone


A 9 year old boy last week during a security conference demonstrated how Android smartphones can be attacked by a malicious app. Reuben Paul gave during the B-Sides conference in Texas not only a demonstration, he also provided the keynote .

The boy showed how he through a malicious app, which looked like a game, was given access to the smartphone. Then he could turn on the camera and steal the address book, call history and messages. "Also, I located where they were," said Paul opposite My Fox Chicago . "If a child can do it, it's a piece of cake for a normal hacker." Through the demonstration Paul wanted to warn the public to be careful when downloading apps.

Tuesday, 17 March 2015

Kaspersky launches free anti-theft app for Android


The Russian anti-virus firm Kaspersky Lab has a free Android app launched that allows users to track their phone in case of theft or loss, or can remote wipe. The app is called Phound and offers several options. A device can be so if it is lost or stolen will be blocked. For this, the user must first log on to a special website.


Via GPS, GSM or Wi-Fi networks, it is then possible to find the position of the device. To search for the device to simplify users can also take pictures with the front camera, or display a message on the screen of the device. If the phone or tablet at home or lose the office, it can be detected by the alarm function. The device produces a loud noise and thus goes through until the owner enters a code.

The app also offers the possibility to remotely delete all personal information from the device and the SD card, including contacts, messages and photos. If necessary, it may also be performed a hard reset of the device. The police warns regular owners of smartphones, laptops and tablets to install anti-theft software, as these programs in the event of theft can help in the investigation .