Showing posts with label IOS. Show all posts
Showing posts with label IOS. Show all posts

Thursday, 5 November 2015

Thousands Of iOS Apps Discovered Backdoor


Researchers have discovered thousands of apps for iOS an ad library malicious enables users to print and listen to steal sensitive information. The problem is in different versions of the saga mobi SDK. An ad library that developers add to their app in order to generate income.

Security firm FireEye now reports that some versions of the library have backdoor functionality. It is currently unclear whether that was added by the developers of mobi saga or attackers have done this. The backdoor to the ad library offers makes it possible to record audio, take screenshots, to retrieve location data, modify files and install additional apps. For this last action, however, is user interaction required.

In total FireEye discovered in the Apple App Store over 2800 apps with the potentially backdoored versions of the saga mobi SDK. In addition, the apps tried more than 900 times in order to achieve a adSage server that would have been able to activate the back by functionality. According to the security company this is especially a problem if attackers manage to hack the servers of adSage. In that case, they can activate the backdoor functionality. Apple was informed in October, but it is unclear whether the apps in question have also been removed from the App Store.

Thursday, 15 October 2015

Yahoo Mail App Allows Users With No Password To Login


Yahoo today launched a redesigned Mail app which allows users without a password to login. In addition, e-mail accounts from multiple e-mail providers are supported, as the Internet giant announced. New in the app is the addition of the "Yahoo! Account Key".

This key is according to Yahoo a simpler and safer alternative to the password. During login, users need a password to give more but simply a tap of a button. In this case, a notification with the Key Account is sent to the smartphone. The user can then via a single tap to confirm that he really wants to log in, then he is also logged as Yahoo late in a blog posting know. The new Yahoo Mail app is available for iOS and will appear later today on Google Play.

Wednesday, 7 October 2015

Apple: YiSpecter-Malware Only Works On Old iOS Versions


The YiSpecter malware that security company Palo Alto Networks warned only works on older iOS versions, and only if users themselves downloading malware from untrusted sources, says Apple. The malware is mainly active in China and Taiwan, but the number of infections is unknown.

To spread the malware uses different methods, but a user action is still required to download and install the malware. In a statement to The Loop, Apple says that the problem affects only users of older iOS versions of the malware itself from unreliable sources have downloaded. The specific problem could be resolved in iOS 8.4. This version was published on June 30 of this year.

In addition, Apple has the apps that were used to block the spread of malware. Apple recommends that iPhone owners to install the latest version of iOS apps only from trusted sources such as downloading the App Store. Also, users should be careful when they get warnings when downloading apps.

Sunday, 27 September 2015

Apple Will Protect Mac Computers From malware XcodeGhost


 In addition, also put a new variant of the Genieo-adware on the black list, let developer of Mac software Intego know.

XcodeGhost came a few days regularly in the news. Chinese developers had downloaded an infected websites through unofficial version of Xcode for OS X, Apple's tool for developing apps. The infected Xcode ensured that the developed apps became infected. Apple yesterday published a list of the 25 most downloaded apps infected. Besides XcodeGhost is now also detected a new version of the Genieo-adware. This adware creates problems for years to Mac users, according to the questions and comments on the official Apple forum.

Friday, 25 September 2015

Apple Publishes List Of Top 25 Infected Apps


Apple has as indicated previously published the list of the 25 infected apps were downloaded the most. The apps infected with malware XcodeGhost, which can send information about the device and apps. According to Apple the malware is not in a position to steal personal information.

We deliberately for a Top 25 chosen because in addition to these 25 applications, the number of affected users is very small. Users who have downloaded an infected app are advised to update the app, which addresses the issue. If the app is no longer available in the App Store, the update will appear soon. In the Top 25 apps are of WeChat, DiDi Taxi, Railroad 12 306, China Unicom, Baidu music, Himalay FM and various games. The apps have been downloaded by millions of people, mainly in China. Furthermore, Apple users will also be separate warn.

Monday, 21 September 2015

Adblock Plus For iOS Is Awaiting Approval Apple


The most famous AdBlocker on the internet can come any time, also for iOS, but is still awaiting approval from Apple. That is what the developers of Adblock Plus know. Adblock Plus was previously only available on the desktop and has been downloaded over 300 million times.

With the release of iOS nine are now supported adblockers on the iPhone and iPad. Recently appeared AdBlocker 'Peace' in the App Store and became a huge success until the developer withdrew the app. In their own words the AdBlocker was too rigorous with ad blocking. It was an all-or-nothing approach.

Crystal, another app in the App Store, is selective in its work. "Acceptable ads" are admissible. To this end the AdBlocker use the whitelist of Adblock Plus. Crystal, which is now the best-selling app on iTunes is also recommended by the developers of Adblock Plus, whose own app is expected soon in the App Store.

Wednesday, 9 September 2015

Survey: Half iPhones Vulnerable To Hackers


Half of all iPhone users running an older version of iOS, allowing appliances to miss updates to more than a hundred vulnerabilities. This places Duo Security on the basis of its own research. Half of the test apparatus takes IOS 8.4 or 8.4.1, while the other half 8.3 or IOS parent has been installed. IOS rating 8.3 released on April 8 this year, five months ago.

Many users therefore risk. Thus resolved in iOS 8.4.1 two major vulnerabilities, called Ins0mnia and Quicksand. These are only two known vulnerabilities. Additionally, iOS 8.4.1 fixed it much more vulnerabilities. Despite the impact shows that 91% of iPhone users a week after the release of the new version had not yet been installed.

The investigation of Duo Security also shows that 31% of iPhones on iOS 2.8 or above running. These users miss updates to more than 160 security vulnerabilities. It also appears that 14% were still running iOS 7 or older works. These devices miss updates to more than 230 vulnerabilities. "Compare it with desktop computers. We have a desktop for months or years to miss security updates nor to the corporate network. We have to think the same way on mobile devices," said Mike Hanley.

For 20 million iPhone users, it is not possible to update, because they use an unsupported device. It is about the iPhone, iPhone 3, iPhone 3GS and iPhone 4. The oldest mobile Apple does not yet support the iPhone 4s. If Apple this would stop supporting the number of aircraft not receive updates more to rise to 60 million. Users who want to be safe in this case no other option than to purchase a new device.

Avira Tool For Lost iPhone Logins Sent Over HTTP



A free tool from antivirus company Avira for finding stolen or lost iPhones appeared to send unencrypted passwords over HTTP. This would allow an attacker who get the network traffic could eavesdrop usernames, passwords and other sensitive information.

It discovered security researcher David Coomber. According Coomber were the passwords that the Avira Mobile Security iOS app sent well protected by the weak MD5 algorithm, but would offer no protection against an attacker could sniff network traffic. Mobile Security is an app that allows users to trace five lost or stolen iPhones. Also, users can check via the tool or their e-mail was hacked, the address book or safe and iOS is up to date. Avira was informed on July 17 and published on September 3 version 1.5.11 in which the issue is resolved.

Sunday, 26 July 2015

Fraudulent Mobile Ads Consume Gigabytes Of Data



Fraudulent apps for both Android, iOS and Windows Mobile posing as popular games allow devices actually charging thousands of ads a day, without users having this in the first instance. However, the applications run continuously in the background, may consume gigabytes of data, ensure that the battery previously absorbed and are able to download more than 16,000 ads per day.

Then there are simulated random clicks on the ads, which get the developers of the paid apps. Average would be the apps on a device 700 ads download per hour, which amounts to 16 800 ads per day. It consumes about 2GB of data. Globally, there are more than 12 million devices with rogue apps are infected.

According to the US Forensiq have rogue apps produced last year for $ 857 million in damages and this year will be $ 1 billion to be passed. It should be noted that Forensiq a company engaged in the fight of advertising and click fraud. Google has already removed several of the rogue apps from Google Play, but would not say how many, reports AdvertisingAge .

Apple Allows Users To Rogue Pop-Up Blocker In iOS 9


Apple has added a feature to iOS Safari 9 which allows users to block malicious pop-ups. IOS users for some time been the target of fraudulent pop-ups that occur as crash reports. The popups use JavaScript to ensure that they do not close on a normal way.

In the so-called crash message is called to call a specific phone number. The number of telephone scammers then ask users amounts of between 40 and 70 euros for solving the "problem". On the Apple forum in recent months dozens of topics and responses to find the people who report to see were . Users who have to deal with the pop-up to close Safari by tapping twice on the home button and then clear the browser history, as Apple on this page explains.

In iOS 9 However, it will also be possible to block pop-ups, as discovered Mac developer Rosyna Keller in the beta version of iOS 9. The Finnish anti-virus firm F-Secure affirms that pop-ups with fraudulent JavaScript indeed simple be closed. All expected to appear iOS 9th September.

Friday, 17 July 2015

IPhone Users Target Fraudulent Crash Message



Owners of an iPhone are still the target of popups fraudulent crash reports and scammers have already moved their operations to the UK. The last few months, especially American iOS users got to see the message on their device.

Meanwhile, there are also reports that British users see the messages, so let the Daily Mail know. The pop-ups using JavaScript, so it is impossible to close the browser in the normal way. According to the report in the pop-up iOS crashed and should be contacted directly with the "support staff." The telephone number of scammers who argue that there needs to be paid to fix it. It is a sum of 43 euros to British victims must deal and 73 euro prompted to Americans.

In addition, the scammers ask for the credit card information of their victims. On the Apple forum in recent months dozens of topics and responses to find people who report to you got . Users who have to deal with the pop-up to close Safari by tapping twice on the home button and then clear the browser history, as Apple on this page explains. What kind of websites users come into contact with the pop-ups is unknown.

Thursday, 18 June 2015

Researchers Have Malware In Apple App Stores




Researchers at Indiana University have succeeded in malware for Mac OS X and iOS to get into the App Store from Apple that allows access to sensitive data from other apps can be obtained. Examples include passwords to iCloud, your default e-mail program and Internet banking and the secret token for the note program Evernote.

It also showed that the design of the app sandbox on Mac OS X was vulnerable, so the malware could approach the private directory apps. The malware could thus have access to notes, and contacts that were stored in Evernote, as well as photos of WeChat. The researchers published their work in late May in a report ( PDF ) called "Unauthorized Cross-App Resource Access on Mac OS X and iOS." To prevent apps access to each other's information systems get fit "app isolation" to which each app is in its own sandbox.

It appears that in some cases for apps still be possible to access the "resources" of other apps, which the researchers call "unauthorized cross-app resource access" (XARA). It was known that this problem played in Android, but the researchers wanted to know whether Mac OS X and iOS are vulnerable. Two platforms, which are believed to be safer than Android, so the researchers in the report know. They discovered that the problem also affects the Apple operating system. Thus, the mechanism can be hijacked that controls access to the Keychain, so it is then possible to gain access to passwords and other credentials of apps and websites that are stored here.

Impact

"The consequences of these attacks are serious, including the leak of passwords, secret tokens and all kinds of sensitive documents. Our research shows that the problem is caused by a lack of authentication at app-to-app and app-to-system interactions "the researchers said in their conclusion. They developed a scanner to analyze binaries for OS X and iOS apps to determine if the proper protection measure is contained in their code or not.

More than 88.6% of the 1612 popular Mac apps and 200 iOS apps were completely vulnerable to a XARA attack, which could steal a malicious app security information. Apple would be informed by the researchers in October 2014 and then asked to wait with the publication of the report, but the investigators would have since heard nothing more, reports The Register . The problem in Mac OS X 10.10.3 and 10.10.4 still present.

Tuesday, 9 June 2015

Leak in iOS Mail App Allows Remote Attacker HTML Charge


A researcher has revealed a leak in the iOS Mail app which allows an attacker to load external HTML e-mail messages, which it is then possible to perform very convincing phishing attacks. The vulnerability was in January this year by researcher Jan Soucek discovered.

The iOS mail client shows a particular HTML tag in email messages can not be ignored. As a result, HTML content can be loaded which replaces the contents of the original e-mail message. Sourcek reported the problem to Apple in January, but because there is still no solution has appeared Soucek decided now a proof-of-concept to publish his attack. Thus, it is possible to display a pop-up to the user through the e-mail that looks like a legitimate logon window. In reality it is a malicious pop-up completed the password sends to the attacker, according to a demonstration video below.

Sunday, 7 June 2015

Dropbox Prohibits 85,000 Words As Passwords



To prevent users from weak or easily guessed passwords choose Dropbox uses an extensive list of forbidden words. This was discovered by researcher Jerod Brennen by the Dropbox app to extract through the program 7-Zip. Both APK files on Android and iOS IPA files are really just zip files, in all but name. In the app, he found a file called pw.html, from what appeared to be 52 lines of JavaScript.

The script aims to prevent Dropbox users choose weak passwords when creating an account via the mobile app. The script uses a line with 85 100 banned words that should not be chosen as a password. These are words like password, computer and qwerty up of figures as 123456, 696969 and 111111 to combinations as abc123, passw0rd and 1234qwer. Also notable is the large number of obscene words that should not be selected. According Brennen that the online list has put, security professionals can add the word to their own lists and tools.

Wednesday, 3 June 2015

Bug In Skype Chat Fixed


The bug in the chat function of Skype's already solved: Skype has released a software update.
In the chat you came into trouble if you typed the following characters and sent: http: // :. Then crashed chat program. Even if you got sent to the characters: Skype quit and each time the program rebooted, the chat service crashes again.


The bug affected only people who use a Skype version for Windows, Android or iOS. The problem did not occur with the Mac version and those using the touchscreen version for Windows 8, reports VentureBeat .

On skype.com/download can now download the latest version of the program.

iMessage crash

A painful situation for Skype, says tech editor Nando Kasteleijn. "Especially because typing http: // :. prevents faster than the strange series that marks late crash iMessage So if you want to send a link to someone, you better direct copy and paste the entire URL. "

SkypeSupport We need a new version of Skype asap. Crashing Bug Affecting phone and desktop clients.- Rafael Rivera (WithinRafael) June 2, 2015

Last week it was announced that a message with a series of strange characters include your iMessage, WhatsApp and Twitter Account may crash. "It is striking that several platforms prove to crash relatively quick succession after entering certain characters," said Nando.

Skype has thus solved the problem and that's a lot faster than Apple.

Monday, 25 May 2015

Stallman: Windows And Mac OS Are Malware


Much of the software in circulation today is malware. It are programs that treat their users bad, says Richard Stallman, which is Windows, Mac OS and iOS gives specific examples. Stallman is the creator of the GNU operating system.

He uses the definition of malware not only for viruses and Trojans, but for programs that users are treated badly. Stallman Something that has become commonplace, writes in a column for The Guardian. "There are so many cases of proprietary malware reported that we should consider any closed program as suspicious and dangerous." Some of these programs closed spy on users, while others are made ​​to chain users through DRM solutions. Other programs impose censorship on weather and some software is specially designed to sabotage users, Stallman continues.

As an example he mentions malware operating systems like Windows, Mac OS and iOS. This is software that users chains, spies and censors. An Internet that closed out all kinds of software solutions exist is not to be trusted. Stallman calls therefore users to take action. So should software and Web services that spy on users or follow avoided.

It should be collectively invested in free solutions that users do not follow the web. Thirdly legislation must come through democratic ways which prohibits several "malware practices." It is also necessary that there be a democracy, says Stallman.Something which according to him is not the case with trade agreements such as TTP and TTIP those companies actually offer the ability to suppress democracy.

Thursday, 21 May 2015

Adblock Plus Launches Its Own Browser For Android


The makers Adblock Plus , the popular browser extension on the Internet, launched its own browser for Android that ad blocking is central. Through Adblock Plus can block Internet ads. According to the developers, the add-on downloaded over 300 million times. If we look at the statistics of active daily users would look about 20 million Firefox users and over 10 million users use Chrome extension.

In the past, Adblock Plus created an extension for Android users, but Google has removed from the Google Play Store, because the add-on products or services other influences. By not being available in app stores is very difficult to reach mobile users, thereby fail not of existence. Additionally Adblock Plus for Android could only block ads on HTTP. In recent months, developers have therefore been working on its own mobile browser that integrates ad blocking.

Today is the first beta version of the browser released. The browser is open source and based on Firefox. The reason is that the Adblock Plus developers Mozilla as a project and as a company really admire. "Firefox for Android is a great mobile browser," so they claim. Most users would not know it, but the browser supports numerous extensions, including Adblock Plus. "Unlike Firefox on the desktop, we are very limited when it comes to integrating Adblock Plus in the user interface of Firefox for Android."

By developing its own browser have to integrate the developers more freedom to adblocking as basic feature that is both understandable and easy to configure. The developers say that they have big plans for the future. So we look to combine the Adblock browser and desktop browser users in a meaningful way. So far the mobile browser now gets all the attention and Internet recalled that test. According to the website of the Adblock Browser comes soon a version for iOS.

Friday, 24 April 2015

IOS Leak Late iPhones And iPads Crashing Within Wifi Range



A vulnerability in iOS allows attackers to iPhones and iPads to let wifi range crashing, allowing the devices in the worst case continue rebooting endlessly. The vulnerability was discovered by researchers at Skycure . For a demonstration of a network attack, the researchers bought a new router and set up in a certain way.

After the researchers had made connection with the router turned the iOS app on their device suddenly crashing. Not much later were other people in the neighborhood to do with crashes. It was found in all cases to iOS users. Further investigation revealed that the problem is caused by specially prepared SSL certificates. Attackers can use this set of apps that crash a SSL connection.

According to the researchers, almost all apps in the Apple App Store use SSL for their communications. An attacker has a lot of opportunities to strike. Not only is it possible to have used apps crash, the vulnerability also affects iOS itself. In certain cases it is possible to restart devices to engage endless, making them unusable, according to the researchers.

"Even if the victims realize that the attack comes from the Wi-Fi network, they can not turn off the WiFi interface." Since the problem is not completely solved by Apple users get the advice to not connect to Wi-Fi networks and suspicious anyway to update to iOS 8.3, as there are some of the problems found "possible" have been corrected.

Wednesday, 22 April 2015

1500 iOS Apps Vulnerable To MITM Attacks


Some 1,500 applications for the iPhone and iPad contain a vulnerability that could allow an attacker who is between a user and the Internet is encrypted SSL traffic from the app to intercept and decrypt. The leak is present in the AFNetworking library that use these applications and ensures that SSL certificates are not checked properly.

AFNetworking the library is a popular library for app developers and adds networking capabilities to the app. The vulnerability was patched on March 26 this year, but research from SourceDNA shows that are only 1500 apps use a vulnerable version of the library. Researchers from Minded Security warned late March already the problem and say that they were able to intercept all the vulnerable SSL traffic during a test through a proxy like Burp Suite .

According SourceDNA the problem by now patched, but app developers do not know much of the problem and continue to give vulnerable updates to their apps. The company put this website online that allows users to see if there have been installed on their phone apps that are vulnerable.

Wednesday, 18 March 2015

IP Box Can Lock Screen iPhones Brute forcing


Researchers have discovered a device that makes it possible to brute forcing the lock screen of iPhones and iPads. IP Box, as the device is called, would be used by telephone repairmen to bypass the screen lock of iOS. "This obviously has major implications for the safety and of course was something that we wanted to investigate and validate" said researchers MDSec .

They did eventually get to 200 pounds one of the devices. The IP Box appears to simulate via the USB connection to enter the PIN and also tries all possible pin combinations. According to the researchers, this has been known, but the device also works if the option is enabled to delete the data after 10 attempts.

"Our initial analysis indicates that the IP Box to circumvent the restrictions by making direct with the power of the iPhone connection and aggressively to break the flow after each unsuccessful PIN, but before the attempt is synchronized in the Flash memory." Entering a PIN would therefore take about 40 seconds. A four-digit PIN can therefore be outdated in some 111 hours.

The attack has been tested on iOS 8.1. An attack on iOS 8.2 will follow. The research would show that it is possible to have a leak was discovered last year, but this has yet to be confirmed. The researchers made ​​the following video on YouTube in which the device and the attack will be demonstrated.