Showing posts with label App Store. Show all posts
Showing posts with label App Store. Show all posts

Thursday, 5 November 2015

New XcodeGhost-Malware For iOS Developers Discovered


Researchers have identified a new variant of the XcodeGhost malware discovered trying to infect iOS developers so they put infected apps in the official Apple App Store. There are more than 200 companies worldwide, which infected iOS users roam.

XcodeGhost is spread via infected versions of Xcode, Apple's official tool for developing iOS applications. Because of its size, the program is 4GB in size, some developers in China choose not Xcode via Apple's website, but can be downloaded via unofficial download sites. The Xcode on these websites provide the XcodeGhost malware. The apps that developers were thus also became infected.

After the discovery of the infected apps in the App Store, Apple decided to remove and arranged so that Chinese iOS developers can program easier downloading. Although the hit iOS developers new clean apps have provided, there are still users who continue to use the affected versions. These include to the popular chat app WeChat.

It also notes that users with infected iOS apps also walk around within companies. Security firm FireEye discovered 210 enterprises which infected apps were trying to communicate to the outside. However, most companies are located in Germany and the United States.

New version

There is also a new version of XcodeGhost discovered in unofficial versions of Xcode 7. This is the Xcode iOS version 9. In this version added new features to iOS infect 9 and bypass static detection by Apple. Also, there is one app is discovered which had become infected via the new XcodeGhost malware and ended up in the Apple App Store. It is a Chinese shopping app that also was offered in the US store. Apple has the app been removed.

Sunday, 27 September 2015

Apple Will Protect Mac Computers From malware XcodeGhost


 In addition, also put a new variant of the Genieo-adware on the black list, let developer of Mac software Intego know.

XcodeGhost came a few days regularly in the news. Chinese developers had downloaded an infected websites through unofficial version of Xcode for OS X, Apple's tool for developing apps. The infected Xcode ensured that the developed apps became infected. Apple yesterday published a list of the 25 most downloaded apps infected. Besides XcodeGhost is now also detected a new version of the Genieo-adware. This adware creates problems for years to Mac users, according to the questions and comments on the official Apple forum.

Friday, 25 September 2015

Apple Publishes List Of Top 25 Infected Apps


Apple has as indicated previously published the list of the 25 infected apps were downloaded the most. The apps infected with malware XcodeGhost, which can send information about the device and apps. According to Apple the malware is not in a position to steal personal information.

We deliberately for a Top 25 chosen because in addition to these 25 applications, the number of affected users is very small. Users who have downloaded an infected app are advised to update the app, which addresses the issue. If the app is no longer available in the App Store, the update will appear soon. In the Top 25 apps are of WeChat, DiDi Taxi, Railroad 12 306, China Unicom, Baidu music, Himalay FM and various games. The apps have been downloaded by millions of people, mainly in China. Furthermore, Apple users will also be separate warn.

Friday, 11 September 2015

Experts Praise New Security In iOS 9


Several security experts are very positive about the new security features that Apple added to iOS nine. The new version of the mobile operating system must next Wednesday sixteenth september appear.Besides new security features is also underway.

According to David Richardson of mobile security firm Lookout is the new way apps "sideloaded" can be a major security gains. Apple offers companies and developers the ability to install via "enterprise / ad-hoc provisioning" apps. For this, Apple will give special certificates from which applications can be signed. Attackers have used this method in the past to malicious apps iOS devices install.

To install an app like this, the user must not only indicate that he wants to install the app, but also that he trusts the app developer. A simple process that consists of the two touching buttons. With iOS nine has changed this. Users receive a warning after you install the app on an untrusted developer originated. To use the app, then they should themselves go to settings and there indicate they trust the developer. "Complexity in this case is excellent," said Richardson. Users can namely not so fast 'click' and install the wrong app.

Anti-virus company ESET is particularly enthusiastic about the new two-factor authentication process and the obligation to use a stronger pass code. Users must now specify namely a pass code of six characters. Two-factor authentication is now added directly to the operating system. As a result, according to the ESET much more difficult for attackers to gain access to the Apple ID of users.

Saturday, 18 July 2015

Google Removes Backdoor App From Play Store


Google has removed a rogue app from Google Play posing as a news app, but in reality it was a backdoor. The app used the name 'BeNews "of the now vanished news site with the same name, to look legitimate, say researchers at the Japanese anti-virus company Trend Micro . The researchers discovered the app in the data that was stolen by the Italian Hacking Team.

The app seems to have been developed in order to circumvent the monitoring of the Play Store. To protect Android users Google checks the content of applications for malicious code. Initially, the app asks for three permissions. Via dynamic loading technology, the app can also download and execute code from the Internet. The downloaded code will not be loaded when Google carries out the checks, but only when the app is used by a victim. The app can then use an exploit to increase its rights on the device. The exploit works on Android version 2.2 to 4.4.

In the stolen data, the researchers found also the source code of the backdoor and the server that can be used to communicate with contaminated devices. Trend Micro believes Hacking Team offered the app to customers, but there is no evidence. The app on Google Play downloaded between 10 and 50 times before it was removed by Google. The developer of the app on the Play Store has placed no other apps in the App Store Google. Google Plus account by this developer also contains no further information except a link to a "testing" area of ​​the app on Google Play.

Wednesday, 4 March 2015

IOS App Scans Password And Security Of WiFi Routers


Anti-virus company Avast at the Mobile World Congress in Barcelona announced an app for iPhones and iPads that checks the security of Wi-Fi networks. The free app searches for Wi-Fi networks in the area and then determine whether they are safe. Thus, among other things, to see whether the Wi-Fi router that the wifi connection offers used weak passwords, the WiFi network is encrypted and whether vulnerabilities are present in the router that attackers can exploit.

In the case of unprotected Wi-Fi networks put the SecureMe app a secure VPN connection. Make in case users with an open Wi-Fi network connection, this VPN connection will be switched automatically. The app is free, but whether this also applies to the VPN part is unclear. Avast will first organize a beta test of the app before it appears in the App Store.

Wednesday, 2 April 2014

Tinder plagued by spam bots


A number of users of dating app Tinder reports that they are matched a fake profile of an attractive woman.In reality the automated bots that users want to download. Mobile game "Castle Clash"
The bots display a link to the game via the URL "Tinderverified.com", making it seem like Tinder is the owner of the URL, or is involved in any case in one way or another to the action. This is not the case.
A Reddit user realized what was happening and posted a screenshot. This post now has a handful of responses from others who say they have experienced the same. Also on Twitter More and more reports from people who claim they are matched with a fake profile.
The bot first sends innocent messages like "hey" and "how are you?" then they tell the unsuspecting user that they have such a fun game on their phone, "Castle Clash, have you heard of?" The bot then informs the URL, no matter what was the response of the user.
It is still unclear who exactly is behind the fake accounts, even though the app developer IGG.com course obvious. The company offers dozens of games on the App Store and Google Play. However, it is also possible that the developer himself the victim of an aggressive promotional network as previously happened with the on-demand ride service Uber .
Tinder shows himself to be aware of the problem and said the necessary steps to remove the spam.

Symantec Detailed Report