Showing posts with label Google Play Store. Show all posts
Showing posts with label Google Play Store. Show all posts

Tuesday, 6 October 2015

Malicious Game: Retro Tetris In Google Play Could Rooting Android Devices



Researchers in Google Play two games have been discovered rooting Android devices. The first game Brain Test and was previously by researchers at Check Point noted. These malicious app was removed on September 24 by Google from the Google Play Store.

The second app which anti-virus company Trend Micro warns's Retro Tetris. This malicious application uses four vulnerabilities in 2013, 2014 and 2015 to rooting Android devices. Devices from Android 2.3 Gingerbread would this risk.What does the malicious app after obtaining root access is not listed. According to Trend Micro's Retro Tetris downloaded between 500 and 1,000 times, especially in China. After being informed Google has removed the app this weekend.



RetroTetris Hashes:


Brain Test:

Wednesday, 16 September 2015

Research: Security Popular Travel Apps Seriously Flawed



The security of the most popular travel apps for both Android and iOS seriously flawed, according to research from Bluebox. Travel apps have changed a lot over the years and now offer a variety of options, such as booking flights and hotels. Now these apps get advanced options this provides new security risks and increases the attack surface.

For the study looked Bluebox the ten most popular travel apps for both Android and iOS. Only one of the ten Android apps pale 'data at rest' to encrypt the device, while none of the iOS apps did. It also showed that using two of the ten Android apps and one of the ten iOS apps Certificate Pinning. Certificate Pinning ensures that an app checks the certificate of the server so that it communicates with the appropriate server. This is to prevent man-in-the-middle attacks.

According to the researchers is to integrate a best practice to Certificate Pinning in the app, but it appears that the developers of travel apps to do this. Even in the three-apps that may apply the technique it appears that it is only used for a portion of the network connection, so that the rest of compounds is unprotected. The survey shows that most travel apps with code from other developers have been made and not 'in-house developed. This increases the attack surface.

The researchers conclude that the security of mobile apps is still in its infancy and travel apps, in particular, to tighten up security. Consumers who receive these apps are advised to only download apps from Google Play or the Apple App Store, use the latest version of operating system and application, be careful about using public Wi-Fi networks and untrusted certificate authorities switch.

Wednesday, 9 September 2015

Adblock Plus: New Browser Blocks Ads On iOS And Android



The makers of the popular browser extension Adblock Plus have today a self-developed browser for iOS and Android launched ad-blocking. This is the first time a AdBlocker on iOS devices available and the developers make their comeback in Google Play.

Several years ago Google Adblock Plus namely decided to remove it from the Google Play store. The expansion, which is available for various browsers, has been downloaded more than 400 million times and has tens of millions of active users.According to the developers, this indicates that Internet users want to block ads. In order to ensure that ads also on mobile devices can be blocked was developed Adblock Browser.

According to the developers saves Adblock Browser data and battery consumption. Studies show that ads 20% of the battery can charge. In addition, advertisements also consume data and therefore cost users money, according to the developers.Another reason for blocking ads is to protect privacy and prevent malware. Adblock Browser not only blocks infected ads, the browser has an option to block malware domains. "Adblock Browser protects your privacy because it has additional features that block trackers", so the announcement says.

Finally his ads on mobile devices very troublesome, according to the developers. Adblock Browser is based on the Kitt browser of a software company called Salsita. A test version of the browser for Android was available from May and was downloaded by 300,000 people.

Sunday, 30 August 2015

Researchers Found 30 000 Infected Apps On Google Play


Researchers at Indiana University have developed a scanner that allows them to rapidly scan hundreds of thousands of Android apps, which ultimately resulted in 30 000 infected apps on the official Google Play store. MassVet (pdf) as the scanner is called, can determine within seconds whether an app is benign or malignant, without knowing how the malware looks or behaves.

Instead of analyzing the app MassVet compares it with apps that already exist in the relevant store. Most Android malware is in fact repackaged apps. When cybercriminals repacking apps add malicious components increasing. Therefore differs repackaged app of the original. The malicious components in applications can also be found who seem to have nothing to do with each other.

The researchers decided to test the scanner with 1.2 million apps from 33 different app markets. MassVet proved apps within 10 seconds, assess and outperformed 54 virus scanners on VirusTotal. Of the 1.2 million-controlled apps were found to be more than 127 000 malignant and 34 000 were missed by most malware scanners on VirusTotal. Some of the malware specimens were installed millions of times. It also found that 5000 malicious apps each had more than 10,000 installations.
Google Play

Also analyzed MassVet 400 000 apps on Google Play, of which 30 000 were found to be malignant. This equates to an infected rate of 7.6%. According to the researchers this different from earlier figures of Google. According to Google, was found on Android Users who only install apps from Google Play at less than 0.15% of the devices a "potentially malicious application" (PHA).

However, users of China's market places that are most likely to Android malware. In the market places of Anzhi, Yidong, yy138 and Anfen was 39%, 36%, 28% and 23% of all available apps malware. On the fifth of infected stores SlideMe comes back, 21% of the malware apps proved to be. The overview is also given to the store by Opera. This was 7.8% of the apps labeled as malicious.

Friday, 7 August 2015

Free App Checks Android Devices On Stage Fright Leak



Owners of an Android device that want to know whether they are vulnerable to severe Stage Fright leak can now download a free app that controls the device. Additionally, Samsung has an app ( .apk ) that empower users MMS messages can disable it on their device.

The Stage Fright-vulnerability was discovered by security Zimperium and Trend Micro. By only sending a MMS message an attacker could execute code on vulnerable machines. But the leak is attacking via apps websites. In reality, not about one vulnerability, but consists Stage Fright of ten different vulnerabilities, as has Zimperium let you know.

Google and several manufacturers have already announced that they will be releasing updates for Stage Fright serious flaw, which are expected to be rolled out by the end of this month. Through the free " Stage Fright detector App "by Zimperium now users can check whether they are still vulnerable. In addition, the security company also took the following video online in which the vulnerability is demonstrated.

Thursday, 23 July 2015

Dozens Of Apps On Google Play Quietly Visit Porn Sites



Researchers have discovered in recent months, dozens of apps on Google Play that Android devices unnoticed kinds of porn sites allow visits. It involves a total of 60 apps posing as popular games, such Dubmash, Clash of Clans and Subway Surfers.

The apps are in the last period downloaded at least 210,000 times. Once active try the apps to hide from the user and then visit various porn sites in the background. Presumably the author get paid for the clicks generated by the apps. Clicks that advertisers think they are performed by people. According to anti-virus company ESET, there is a cat-and-mouse game between Google and the authors of the fraudulent apps. Once Google remove an app is a new upload.

Most of the fraudulent apps have no or a few tens of downloads before they are found and removed. A single app falls on, like Subway Surfers 2, which was downloaded at least 50,000 times. According to ESET caused the click fraud apps no direct harm to users, such as steal passwords, but they generate a lot of traffic that users with data limit on cost can hunt.

Saturday, 18 July 2015

Google Removes Backdoor App From Play Store


Google has removed a rogue app from Google Play posing as a news app, but in reality it was a backdoor. The app used the name 'BeNews "of the now vanished news site with the same name, to look legitimate, say researchers at the Japanese anti-virus company Trend Micro . The researchers discovered the app in the data that was stolen by the Italian Hacking Team.

The app seems to have been developed in order to circumvent the monitoring of the Play Store. To protect Android users Google checks the content of applications for malicious code. Initially, the app asks for three permissions. Via dynamic loading technology, the app can also download and execute code from the Internet. The downloaded code will not be loaded when Google carries out the checks, but only when the app is used by a victim. The app can then use an exploit to increase its rights on the device. The exploit works on Android version 2.2 to 4.4.

In the stolen data, the researchers found also the source code of the backdoor and the server that can be used to communicate with contaminated devices. Trend Micro believes Hacking Team offered the app to customers, but there is no evidence. The app on Google Play downloaded between 10 and 50 times before it was removed by Google. The developer of the app on the Play Store has placed no other apps in the App Store Google. Google Plus account by this developer also contains no further information except a link to a "testing" area of ​​the app on Google Play.

Wednesday, 8 July 2015

Fraudulent BatteryBotPro App From Google Play Removed



Google has removed a rogue app from Google Play posing as BatteryBotPro app and infected machines used for all kinds of fraud. The BatteryBotPro app is an app that displays detailed information about battery and battery consumption. The app, which 2.99 euros to be paid for, downloaded between 100,000 and 500,000 times.

Recently, criminals have downloaded the app and includes malicious modules, then place successfully on Google Play the custom app. Unlike legitimate app asks the rogue app administrator privileges to install. Once the user has authorized the app installed and will offer the same functionality as the legitimate app, says security firm Zscaler . In the background, the malicious app uses the device include committing click fraud and ads fraud.

This smartphone is used for displaying ads and generate false clicks on ads. In addition, the app also appears to gather information about the device and additional malicious apps to be installed without the user's permission has to give here. Next click and ad fraud app also aims to send text messages, which can cost the user money. After being informed, Google removed the app from Google Play. How many users have downloaded the rogue app is unknown.

Monday, 29 June 2015

VU Researchers Reveal Vulnerability In Android


Researchers at the Free University in Amsterdam have revealed a vulnerability in Android which an attacker can install using the stolen credentials to a Google Account in several steps malicious apps on devices.

The problem is caused by one Google account used for different devices. An attacker who successfully infect the computer of an Android user knows and manages to steal the password of the Google Account can then install apps on all Android devices associated with that account, so the researchers had this weekend at the Volkskrant know. The devices showed the researchers used only during the installation process notifications in the notification bar, as downloading and installing the app.

"But once this was done, there was nothing more to see until the notification screen is explicitly opened. It is also true that the icon of the app does not always end up on the main screen, but sometimes only at the 'all apps' list, for example, if your main screen already filled, or - if the app is published correctly -. We did not make use of the latter, "said university researcher Victor van der Veen . Together with researcher and professor Radhesh Krishnan system and network Herbert Bos discovered and he researched the issue.

Play Store

Van der Veen says that can be installed through the attack vector only apps from the Play Store. According to the researcher then has two options attacker. Or placing a simple app on Google Play, which will be opened after installing a new rogue app.These users, however, would have to set themselves apps from external sources can be installed. Something that is disabled by default. The second option is to install an app on Google Play containing all malicious code. "Meanwhile we have several 'bad' applications received in the Play Store without being detected as malicious by Google," Van der Veen.

Through the malicious app, an attacker can then perform a variety of actions on the device, such as the interception of text messages or turn on the camera. The researchers warned Google late last year, but the Internet giant would want to do anything about the problem. Van der Veen advises users who want to protect themselves against possible attacks to watch.So should be immediately removed unsolicited downloaded apps and the option "Install from external sources" are disabled.Also users should change their passwords regularly. "Especially when there are suspicious or strange signals. And protect your PC, because the criminals come for the first time," the researcher noted.

Friday, 22 May 2015

Dozens Minecraft Apps On Google Play Prove Scareware


On Google Play, researchers from the Slovak anti-virus company ESET found dozens of apps that occur as cheats for the popular computer game Minecraft, but in reality scareware. It involves a total of 33 applications that were placed on Google Play over a period of nine months and have been downloaded between 660,000 and 2,800,000 times.

The apps do not do what they promise and show after starting only banners claiming that the Android device with a "dangerous virus" infected. Then offered to remove the virus, for which there should be a "virus" via SMS enabled. However, it is an SMS user subscription costs 4.80 euro per week. ESET recommends that Android users to still only download apps from official app stores, to check what permissions the app asks and be read reviews from users.

NSA Wanted To Infect Android Users On Google App Store


The US National Security Agency has set up a project in the past which attempted to infect users of the Google Play Store and Samsung App Store with spyware, according to documents from whistleblower Edward Snowden of late 2011 and early 2012 date.

According to the documents sought the NSA and British, Canadian, New Zealand and Australian intelligence agencies to find ways to attack smartphone users. Through the previously disclosed XKEYSCORE system smartphone traffic was identified.Through another project that had looked into development of the connection from the user to the aforementioned app stores was to hijack so that could then be controlled via a man-in-the-middle attack malignant "implants" to the smartphone .


In this way the intelligence services could monitor the target then. In addition to using the app stores as a springboard for the spread of spyware intelligence also sought ways to hijack them and spread misinformation among targets. Also wanted the intelligence to access the app store servers so that they could gather information about users, so notify the intercept and CBC News .

UC Browser


The documents also show that the intelligence services had discovered vulnerabilities in UC Browser, an immensely popular browser in Asia, and particularly China and India. Worldwide, 500 million people would use the program. The browser was found to leak all kinds of information over the phone. Information used by the intelligence services too. Canadian CitizenLab UC Browser has studied because the documents in April and discovered numerous vulnerabilities, which have now been remedied through an update. Google declined to comment on the findings and Samsung has given no substantive response.

Full Document Report

Thursday, 21 May 2015

Adblock Plus Launches Its Own Browser For Android


The makers Adblock Plus , the popular browser extension on the Internet, launched its own browser for Android that ad blocking is central. Through Adblock Plus can block Internet ads. According to the developers, the add-on downloaded over 300 million times. If we look at the statistics of active daily users would look about 20 million Firefox users and over 10 million users use Chrome extension.

In the past, Adblock Plus created an extension for Android users, but Google has removed from the Google Play Store, because the add-on products or services other influences. By not being available in app stores is very difficult to reach mobile users, thereby fail not of existence. Additionally Adblock Plus for Android could only block ads on HTTP. In recent months, developers have therefore been working on its own mobile browser that integrates ad blocking.

Today is the first beta version of the browser released. The browser is open source and based on Firefox. The reason is that the Adblock Plus developers Mozilla as a project and as a company really admire. "Firefox for Android is a great mobile browser," so they claim. Most users would not know it, but the browser supports numerous extensions, including Adblock Plus. "Unlike Firefox on the desktop, we are very limited when it comes to integrating Adblock Plus in the user interface of Firefox for Android."

By developing its own browser have to integrate the developers more freedom to adblocking as basic feature that is both understandable and easy to configure. The developers say that they have big plans for the future. So we look to combine the Adblock browser and desktop browser users in a meaningful way. So far the mobile browser now gets all the attention and Internet recalled that test. According to the website of the Adblock Browser comes soon a version for iOS.

Thursday, 12 February 2015

Google Play Leak Makes Possible Automatic Install Apps


A vulnerability in the Google Play Store allows attackers to install apps from automatically from the store on the devices of Android users. The problem is caused by the Google Play support domain no X-Frame-Options (XFO).

A malicious user could then through Cross-Site Scripting (XSS) in a particular part of the Google Play web application, or via Universal XSS (UXSS) remotely install any app from Google Play and start. According to Todd Beardsley security company Rapid7 are many versions of Android 4.3 (Jelly Bean) and previously supplied with browsers that are vulnerable to UXSS.

In addition, there is the possibility that users themselves have installed a vulnerable browsers. Users who want to protect themselves against the problem have therefore advised to use a browser which does not occur frequently UXSS vulnerabilities, such as Google Chrome, Mozilla Firefox or Dolphin Browser. Another solution is not to be logged into a Google account while surfing.

The problem was reported to Google on December 12 last year. However, no mention is made of the vulnerability is fixed.Rapid7 did create a module for Metasploit to demonstrate the vulnerability. Metasploit is a framework for testing the safety of the systems. The now published module combines two vulnerabilities to execute arbitrary code on Android Devices.

First create the module using a UXSS leak in the default Android browser, as well as various other browsers on Android 4.3 and above. In addition, maintains the Google Play web interface no X-Frame-Options and is therefore vulnerable to script injection. The end result is the remote execution of code from Google Play's feature to remotely install apps. An attacker can therefore install and start anywhere in the Play store.

Monday, 7 April 2014

Popular Virus Shield App apparent scam

Security conscious Android users were disappointed this week when it emerged that their Virus Shield anti-virus app was nothing more than a simple image on the screen of their mobile phone or device.
According maker Deviant Solutions Virus Shield prevents malicious apps end up on the mobile device of the user. In addition, the apps, settings, files, and media in real time would scan the app and would protect the private information of the owner. All this, with minimal impact on battery and without showing ads.



Google Play Store
The app received a whopping 4.7 stars in the official Google Play Store, cost $ 3.99 and was within a week of the best-selling paid app in the Store.



Scam
Unfortunately, the promise proved too good to be true. When the Android Police glanced at the source code, it was found that the only functionality of the app consisted of a picture of a shield with a cross and a shield with a check mark where the user could switch by tapping on the screen. between This would produce the so-called security should be off. Or in Deviant Solutions, however, proved "failed" to have an effective anti-virus application after the on-off button to hang up.
Virus Shield has been removed from the Google Play Store.