Showing posts with label smartphone security. Show all posts
Showing posts with label smartphone security. Show all posts

Monday, August 20, 2012

Apple responds to iPhone SMS security vulnerability

The company says the threat of text message spoofing is a limitation of SMS. Oh, really?


undefined
More ways for texts to get yucky.
(Credit: CNET)
 
CNET - Yesterday I reported on revelations that iPhones may be particularly vulnerable to an SMS spoofing attack. Basically, because of the way iOS handles text headers, a nasty person could manipulate the "reply-to" number to appear to be someone they're not, like a financial institution.

Ever received a text from your bank on your iPhone? You may want to take a closer look and make sure it's the real deal.

A hacker who goes by the handle "pod2g" says a security flaw has made receiving texts on an iPhone insecure since the inception of iOS, and that the vulnerability still remains in the latest beta of iOS 6.
undefined

The issue lies in the header of a SMS message, which includes both the originating number of the message and a reply-to number. According to pod2G, the iPhone only displays the reply-to number and loses track of the originating number, which creates a few possible problems:
- pirates could send a message that seems to come from the bank of the receiver asking for some private information, or inviting them to go to a dedicated Web site. [phishing]

- one could send a spoofed message to your device and use it as a false evidence.

- anything you can imagine that could be utilized to manipulate people, letting them trust somebody or some organization texted them.    More

Yesterday I reported on revelations that iPhones may be particularly vulnerable to an SMS spoofing attack. Basically, because of the way iOS handles text headers, a nasty person could manipulate the "reply-to" number to appear to be someone they're not, like a financial institution.

More

Tuesday, December 13, 2011

Google pulls 22 more malicious Android apps from Market



 

‘RuFraud’ sent texts to premium numbers, posed as popular games like ‘Angry Birds,’ ‘Need for Speed’

 

Computerworld – Google has removed nearly two dozen malware-infected apps from its official Android Market in the last several days, a security company said Sunday.
So far this year, Google has yanked more than 100 malicious Android apps from its download distribution channel.

San Francisco-based Lookout Security said that it and other vendors had notified Google of several recent waves of malicious apps — 22 apps altogether — that reached the Android Market. Google has yanked those programs from the e-mart, said Lookout.

Lookout spotted nine malware-infected apps last week, and another 13 over the weekend.
The company dubbed the malware bundled with the fake apps “RuFraud,” and said that the code sent spurious text messages to premium numbers, racking up revenues for the criminals.

While North American users were not affected — RuFraud was written not to target the U.S., for instance — people in France, Germany, Italy, Poland, Russia, the U.K. and several other eastern European and central Asian countries were.

As in previous malicious app campaigns, the RuFraud apps borrowed elements of legitimate apps, but did not simply snatch complete apps, then re-package them with malicious code, said Lookout.              More

Wednesday, August 10, 2011

How to Spot an Android Trojan




PCMag.Com – Malware that targets Android phones is on the rise. According to a recent report from mobile security specialists at Lookout, Android users are more than twice as likely to encounter nefarious software today than they were six months ago. When did downloading apps become a contact sport?

The open nature of the platform and the ease with which developers can upload apps in Google’s official Android Market are partially to blame. The same accessibility that makes Android attractive to phone manufacturers and developers has attracted the attention of mischief-makers and malware creators out to make a quick buck.

Fortunately, mobile devices have some inherent protections that don’t exist on traditional PCs. For any malware to infect your phone, you need to take some kind of action for it to happen—usually downloading and installing an app. That’s the good news. The bad news is that there are hundreds of thousands of Android apps, spread over several app stores. No cell phone is an island—you’ve got to download something at some point.

If you’re an Android user, there are a number of precautions you can take to better protect yourself (first thing: use a lock code on your phone). Downloading from only “trusted” sources is always good advice, but how do you know who to trust? Lots of great apps come from little developers and small businesses that most people wouldn’t recognize. How can you tell the difference between them and the bad guys?

There are a number of warning signs to help you spot evildoing Android apps, and we’ve compiled them below. But the main ingredient in protecting yourself is always vigilance. Read before you download—and after. Don’t blindly click on things (like permissions agreements) with wild abandon. All the rules below are essentially extensions of the golden rule of all security: stay on guard.


1. Look Up the Developer
When DroidDream, the first trojan to appear in the official Android Market, was discovered, th apps that contained the malware were from developers with names like Kingmall2010 and we20090202. Likewise, they hadn’t even replaced the default Android icon on the apps’ description pages. If there’s no real logo, and you haven’t heard of the developer, at least Google the developer’s name to see if it’s legit.


2. Be Wary of Knock-Off Games
Games are trap of choice among many malware creators. Casual gaming on phones has been skyrocketing in recent years—no surprise when many apps cost just a buck or two. If it’s free, even better, right? Wrong. Some trojans disguise themselves as free versions of paid games, just with malware. Late last year a trojan dubbed “Gemini,” which recruited infected phones into a botnet, was found in various pirated versions of Android games, including President vs. Aliens and Baseball Superstars. If you think you’re getting something for free that you would otherwise have to pay for, consider that you may be paying in another way: with your security.       More