Showing posts with label smart phones. Show all posts
Showing posts with label smart phones. Show all posts

Monday, October 22, 2018

iPhone and cryptomining Malware infection!! - Nearly 400% rise in iPhone attacks has been recorded in only the last two weeks of September



Surprised , why? - After all smartphones are also computers (and probably, a good attack surface)

Cybercriminals are using the Coinhive mining malware for attacking iPhones.

According to Check Point’s latest Global Threat Index, the company is being targeted more frequently in cryptomining malware attacks.

The inclusion of Safari browser raises concerns that this may not be an iPhone related phenomenon only and could very well be a mining script. The report also mentions Coinhive, which further intensifies these concerns.

These attacks definitely serve as a reminder to all that mobile devices are quite vulnerable to attack but are often ignored by organizations as probable attack surface. It is therefore imperative that mobile devices are comprehensively protected with a reliable threat prevention solution.

https://www.hackread.com/hackers-hit-iphones-with-cryptomining-malware/

Monday, July 9, 2018

Some Android apps share image and video data with other parties in unexpected ways, without user knowledge or consent


Example: GoPuff records the screen and sends a video of the interaction to a domain owned by the third-party analytics company, Appsee, as soon as the app starts.

Another app used the camera-taking abilities of a mobile beta-testing platform found on Google Play, TestFairy, to record users interactions through screenshots.

“Screen recording, if adopted at scale and/or in apps that handle sensitive data, could expose substantial amounts of users’ PII, especially when the full burden of securing private information is placed on developers,” the researchers said. “Further, we argue that the recording of interactions with an app (without user knowledge) is itself a privacy violation akin to recording audio or video of the user.”

https://threatpost.com/android-app-are-sharing-screenshots-video-recordings-to-third-parties-report-finds/133686/

Monday, October 24, 2016

Do you have an android phone - You might be vulnerable to Drammer.(deterministic Rowhammer)



It is a DRAM related vulnerability
and 
There is a  partial fix for the flaw (CVE-2016-6728)


From the article:

The name Drammer is short for deterministic Rowhammer

The vulnerability, dubbed Drammer, could give an attacker root access to millions of Android handsets including Nexus, Samsung, LG and Motorola.

The attack method employs an existing PC-based hack known as Rowhammer, a technique that targets rows of cells of memory in DRAM devices to induce cells to flip from one state to another.

“Drammer is the first Android root exploit that relies on no software vulnerability and is an instance of the Flip Feng Shui exploitation technique,” 

The Android Security team said it would issue a partial fix for the flaw (CVE-2016-6728) with its November security bulletin. However researchers point out, Google’s patch will make it much harder for an attacker to launch a Drammer attack, it does not eradicate it. “We hope to see a more sophisticated fix soon,” according to researchers.

For more details:
https://threatpost.com/rowhammer-vulnerability-comes-to-android/121480/

Thursday, October 1, 2015

StageFright 2.0 - Affects 1 Billion Android devices?



Previously we only had to worry about the number of vulnerabiltities
Now, we have to be concerned about the number of hosts that are affected and the level of expertise and awareness of the users.


From the article:

Stagefright is an over-privileged application with system access on some devices, which enables privileges similar to apps with root access. Stagefright is used to process a number of common media formats, and it’s implemented in native C++ code, making it simpler to exploit.


“That process, you would think, would be sandboxed and locked down as much as it could because it’s processing dangerous, risky code, but it actually has access to the Internet,” Drake said. “Android has a group enforcement where it allows [Stagefright] to connect to the Internet. This service is on all Android devices. I’d rather not have a service that’s doing risky processing have Internet access.


For More Info:

Friday, September 18, 2015

Great gift for your spouse or your boss - A Spy watch that can guess what they type.



Sometime in future we may have a Malware that will do that for free


From the article:

Using the watch's built-in motion sensors, more specifically data from the accelerometer and gyroscope, researchers were able to create a 3D map of the user's hand movements while typing on a keyboard.

The researchers then created two algorithms, one for detecting what keys were being pressed, and one for guessing what word was typed.

The first algorithm recorded the places where the smartwatch's sensors would detect a dip in movement, considering this spot as a keystroke, and then created a heatmap of common spots where the user would press down.

he second algorithm took this data, and analyzing the pauses between smartwatch (left hand) keystrokes, it was able to detect how many letters were pressed with the right hand, based on the user's regular keystroke frequency.

Based on a simple dictionary lookup, the algorithm then managed to reliably reproduce what words were typed on the keyboard.


For more info:
http://news.softpedia.com/news/creepy-smartwatch-spies-what-you-type-on-a-keyboard-491604.shtml

Wednesday, September 16, 2015

Android 5 phones (other than Lollipop) - (Lock-screen) Password can be easily bypassed by typing any long string.



This is plain and simple failure in app testing.
However,  it has been fixed so go ahead and upgrade.



From the article:

 Unless they've been fully patched to version 5.1.1 including last week's security updates.

Yes, by typing in too many characters, you can kill off the security mechanism and gain full access to the device, even if its filesystem is encrypted – miscreants can exploit this to run any application, or enable and developer access to the device.


The attack only works if the gadget has a lock-screen password set, the researchers note: the attack doesn't work against pattern or PIN setups.




For more info:
http://www.theregister.co.uk/2015/09/16/google_patches_android_lockscreen_bypass_nexus/

Monday, June 29, 2015

LG Smartphones - Actually, not so smart. Man-in-the-Middle attack possible



Apparently the apps (or their programmers) are too lazy to perform integrity checks
If this does not surprise you, check how the vendor plans to resolve this issue.


From the article:

“When fetching new applications, the client looks for the ‘appUrl’ field, which holds a base64 encoded, encrypted URL. The encryption key is symmetric, it is based on the certKey field, which is part of the same message. Since there is no integrity protection applied to the messages, an attacker can intercept the update response and replace the value of appUrl with any arbitrary URL pointing to a potentially malicious APK,” the researchers said. 

The vendor plans to fix the bug only in new handsets and won’t push a fix to existing phones. As a workaround, they recommend turning off the “Auto app update” function on affected LG handsets. 



For more information:

Thursday, March 27, 2014

Remember the saying "Birdie told me" now, the birdie can steal your credentials.



This is a POC , the researchers were able to steal credentials from a Drone.


According to the article:- 

Snoopy, “a distributed tracking and profiling framework," was developed by SensePost Research Lab researchers Daniel Cuthbert and Glenn Wilkinson and was claiming victims by 2012. 

Snoopy was mounted on a quadcopter and flying over London spoofing Wi-Fi networks. The researchers were able to obtain “network names and GPS coordinates for about 150 mobile devices” in less than one hour. They also stole Amazon, PayPal and Yahoo credentials.

Snoopy, like the WiFi Pineapple, can spoof Wi-Fi networks and trick your device into connecting to it.

CNN Money added, “Devices two feet apart could both make connections with the quadcopter, each thinking it is a different, trusted Wi-Fi network. When the phones connect to the drone, Snoopy will intercept everything they send and receive,” including passwords, usernames, sites visited, credit card numbers entered, and location data. Snoopy also scoops up the MAC address, tying the traffic to a specific device. The researchers were even able to track a phone to the owner's home.


The links below has more information:-

Security,Smart-Devices and stretching Trust boundary - Are we losing control ?



We all know people are the weakest link and with smart devices it is easier to exploit.

This article discusses how Trust gets stretched and affects the security when it comes to Mobile Devices.

(Remember people  can also connect their mobile devices to  any WiFi networks increasing the risk.
Add IoT and it becomes a lot more fun)

Quote from the article:

“A process without input is a miracle, while one without output is a black hole. Either you’re missing something, or have mistaken a process for people, who are allowed to be black holes or miracles”



According to the article:- 

As a baseline, the company itself took the responsibility for trusting the OS to have provided a safe sandbox for all apps to play in, and the phone vendor to have only installed trustworthy apps as part of their customization. So our trust boundary is already extended beyond our company resources to the phone service provider, the phone manufacturer, the phone vendor, the phone OS developer and the security application company. All which we may have to just accept but should be aware of.


But our new employee has, unknown to the company, extended our trust boundary is several ways:

  • Adding Gmail account 
  • Adding games
  • Adding calendar app
  • Lastly the social media apps


I think that ultimately, none of this is all that egregious and should be a normal use case for IT distributing devices, but add this up over a 500 person company and your trust boundary grows far beyond your ability to manage it, making it effectively infinite. 



The links below has more information:-

Wednesday, March 5, 2014

Fake version of Netflix (Malware) on phones and tablets (Supposedly pre-installed) from at least four different manufacturers.



With the fake Netflix application, the organization told Marble Security the app was pre-installed when it bought the device. Marble Security then looked at devices from its other customers and found the problem was widespread. They found a fake version of Netflix on phones and tablets from at least four different manufacturers, Jevans said.

The links below has more details:

http://www.cio.com/article/749199/Pre_installed_Malware_Turns_Up_on_New_Phones