[+] Wayc0de's Blog[+]

Tampilkan postingan dengan label Ponsel. Tampilkan semua postingan
Tampilkan postingan dengan label Ponsel. Tampilkan semua postingan

12/11/11

Apple's iOS 5.0.1 is out - should you upgrade?

Apple's latest iOS update is out.

The new version bumps iOS5 up to 5.0.1, and is Apple's first OTA update.

OTA stands for "over-the-air", and means that you can download and apply the update directly from your iDevice.
You no longer need to download the entire firmware file to your computer - including yet another copy of everything which hasn't changed in iOS - and push it to your device.
(OTA updating isn't yet mandatory. If you prefer to keep full copies of each iOS firmware distro, you can still use the download-and-install-with-iTunes method.)

According to Apple, the highlights of the 5.0.1 update are that it:
* fixes bugs affecting battery life,
* adds Multitasking Gestures for the original iPad,
* resolves bugs with Documents in the Cloud, and
* improves voice recognition for Australian users using dictation.

Strewth! That last one's a bonzer boost for blokes and sheilas everywhere! Gives an Aussie something worth lifting a tinnie to after the Baggy Green got such a big hiding from the South Africans in the cricket!

Importantly, 5.0.1 also fixes a number of security flaws, including a remote code execution (RCE) vulnerability involving font handling, found by Erling Ellingsen of Facebook. RCE means that a cybercriminal might be able to trick your device into running software without asking you, even if you're just browsing the internet.

Interestingly, Charlie Miller's recent and controversial App Store hole has also been patched. Miller showed how to write an innocent-looking App which, once approved by Apple, could fetch and run unapproved software.

Miller was unceremoniously banned from the Apple Developer scene for at least a year; there's no word from Apple, however, on whether he'll be readmitted now the hole is fixed.

Jailbreakers will be pleased to note that devices suitable for running a jailbroken iOS5 - a list which sadly still excludes the iPhone 4GS and the iPad 2 - can happily run a jailbroken iOS5.0.1.

If you are a jailbreaker, however, note that there is not yet any way to go back to iOS5.0 once you've moved on to 5.0.1.
That means that you'll never be able to use Charlie Miller's code-signing vulnerability for jailbreaking purposes in the future, for example if an iPad 2 jailbreak appears which relies on it.

And that leaves us with one question: should you update?
Some reports suggest that 5.0.1 brings with it a raft of new problems, and that the update might not, after all, fix your battery issues.

But these complaints are still anecdotal and unscientific, so if you trust Apple and you're not into jailbreaking, I'd suggest updating to 5.0.1 as soon as you conveniently can.

Ellingsen's and Miller's vulnerabilities may not have made it to Apple's highlights list, but each of these bugs on its own can be considered sufficiently important to warrant a prompt update.
Read More...

Free Android antivirus software is 'useless,' says testing firm

The malware scanners from minor players typically catch less than 10 percent of malicious software

Free Android antivirus software is 'useless,' says testing firm
Consumers and workers who install free Android antivirus scanners from relatively unknown developers are mostly wasting their time, an independent testing firm has found. "During our tests, we found out that the majority of free products are -- to make it short -- useless," says Andreas Marx, CEO of AV-Test. Of all the major mobile platforms, Android is at most risk for malware.

The German firm tested seven free antivirus applications for the Android platform and found that the best program detected only one-third of resident malware, and all others detected less than 6 percent. The best performer, Zoner Antivirus Free, detected 8 of 10 malicious programs during installation, while the other applications detected at most 1 of the 10 malicious programs, according to the firm's analysis (PDF).

The company tested Zrgiu's Antivirus Free, BluePoint Antivirus Free, GuardX Antivirus, Kinetoo Malware Scan, LabMSF Antivirus beta, Privateer Lite, and Zoner AntiVirus Free. Four of the free antivirus program did not detect any of the 172 resident malicious programs used as a test base; another detected only 2. The programs also had little success in detecting malware during installation, with three of the programs detecting no malware and three others detecting a single program. Zoner Antivirus Free was the only standout of the bunch, detecting 32 percent of resident malware and 80 percent of malware during installation.

The firm compared the results to antivirus offerings from established security firms F-Secure and Kaspersky, which detected more than 50 percent of resident malware and blocked all 10 malware samples during installation.

The company plans to widen the testing for its next report to include antivirus programs from commercial vendors as well.

 

Read More...

10/11/11

Adobe says goodbye to Flash for mobile platforms

Adobe product management team has sent a briefing to Adobe's partners describing the future direction of the development for multi-platform mobile application development tools.

From the security point of view, the biggest and the most welcome news is the announcement of the end of the development of Adobe Flash player for mobile platforms, except for critical security and bug fixes.

Unfortunately, even if the death of Flash for mobile platforms is imminent, Flash for desktop platforms is still very much alive. Adobe Flash vulnerabilities, together with Java virtual machine and Adobe Reader vulnerabilities, have been the most common causes for drive-by download malware infections.

It is yet uncertain what is the future of Flash on desktop, but let us hope that the widespread acceptance of HTML5 will drive Adobe in the right direction of killing Flash players on all remaining platforms.

The move comes after a pressure by iPhone and iPad users which have been frustrated by not being able to access websites built in Flash since Apple announced its decision to exclude Flash support from iOS based devices.
Was Steve Jobs right about Flash after all?
Read More...

30/10/11

Android Malware Spreads Through QR Code

Last week, there was quite a buzz in the mobile-malware researchers community about a new Android malware. It came to light not because of its sophistication or complexity but due to the simple method that it uses to spread.

Most Android malware we have witnessed are repackaged malicious apps made available in black markets or third-party markets. This latest Android malware follows the same repacking path as its precursors. The only difference with this malware is that it uses quick response (QR) code to distribute the malicious link. We have already discussed in a recent blog that QR code can be used by attackers to spread malicious files.

A QR code is a type of matrix barcode to store information. These codes are increasingly found on product labels, billboards, and business cards. Why are QR codes so popular? The amount of data they hold. QR codes can carry 7,089 numeric characters or 4,296 alphanumeric characters and can store up to 2KB of data.

All one needs is a smart phone with a camera and QR reader application to scan these codes. The codes can direct users to websites or online videos, and send text messages and emails.


 

QR code points to McAfee.com

If you scan the QR code above with any QR code reader using your smart phone, it will redirect you to our site http://www.mcafee.com Attackers use these codes to redirect users to URLs that ask users to download malicious applications.


Malicious QR code

Analyzing the payload

Once users download a malicious application onto their mobile devices, they need to install it. This malicious app is the Trojanized Jimm application, which is a mobile ICQ client. The payload is nothing new, as we have already seen these behaviors in the past with other Android malware such as Android/FakePlayer.A and Android/HippoSMS.A. The latter sends SMS’s to premium numbers.



 


This malicious application requires the following user permissions:


User permission request by the application

Once installed, the malware sends an SMS to a premium number that charges users. The application has the following icon:


The application icon

We have also seen the JAR version of this application; it targets the J2ME mobile phones and sends SMS’s to premium numbers. When I installed the malicious .jar package in a test environment, it displayed the following message:

 

Installing the malicious application

It prompted me to select a country and then displayed the next message:


Finally the malware tries to send messages to premium numbers from the infected mobile. Because I was executing this application in a controlled environment, it told me I didn’t have a sufficient balance in my account to send the message. ;) But I did confirm that it tried to send messages, as seen below:


In the recent blog about QR codes by my colleague Jimmy Shah, he suggested how to stay away from such attacks. Our advice has not changed: Use a mobile QR code-/barcode-scanning app that previews URLs, and avoid scanning suspicious codes.

McAfee products detect these malware in our latest DATs as Android/SMS.gen and J2ME/Jifake.a.
Read More...

26/10/11

Exploit-powered Android Trojan uses update attack

A new DroidKungFu variant poses as a legit application update

A new variant of the DroidKungFu Android Trojan is posing as a legitimate application update in order to infect handsets, according to security researchers from Finnish antivirus vendor F-Secure.

Distributing Android malware as updates is a relatively new tactic that was first seen in July. The primary method of infecting handsets continues to be the bundling of Trojans with legitimate applications; however, the resulting apps are easy to spot because of the extensive permissions they request at installation time.

[ Find out how to block the viruses, worms, and other malware that threaten your business, with hands-on advice from InfoWorld's expert contributors in InfoWorld's "Malware Deep Dive" PDF guide. ]

According to security researchers, the new update-based attacks can have a higher success rate than "Trojanizing" apps because users don't tend to question the legitimacy of updates for already-installed software.

Furthermore, when used by threats like DroidKungFu, update attacks can be hard to detect without specialized antimalware tools. That's because these Trojans use Android exploits to gain root access and then deploy their malicious components unhindered.

The new DroidKungFu variant is distributed with the help of a non-malicious application currently available from third-party app stores in China. However, the threat is global because apps infected with earlier versions of the Trojan have been detected on the official Android Market in the past.

"Once installed, the application would inform the user that an update is available; when the user installs this update, the updated application would then contain extra functionalities, similar to that found in DroidKungFu malware," the F-Secure researchers warn.

The update only asks for access to SMS/MMS messages and location, but also contains a root exploit for Android 2.2 "Froyo" that unlocks all system files and functions. Even though this particular DroidKungFu variant doesn't target devices running Android 2.3 "Gingerbread," there are other Trojans that infect this version of the operating system and could adopt the same attack technique in the future.

In addition, there is reason to believe that the malware's authors are also testing other infection methodologies. Last week, security researchers from mobile antivirus vendor Lookout detected another DroidKungFu variant that doesn't use root exploits at all.

Instead, the new Trojan, which Lookout calls LeNa, uses social engineering to trick users into giving the installer super-user access on devices where users have knowingly executed a root exploit. Once deployed, the malware attaches itself to a native system process.

"This is the first time an Android Trojan has relied fully on a native ELF binary as opposed to a typical VM-based Android application," the researchers explained. The malware is distributed by rogue VPN applications, some of which were found on the official Android Market.
Read More...

Howto Use Droidsheep - Tutorial [video]

 

Description: This official tutorial for DroidSheep for Android shows how to use DroidSheep to capture sessions in your local network.

DroidSheep runs on your Android device and listens to the networks traffic. If it captures a cookie, it shows a list with the cookies and the user can simply use the victims account without knowing his user credentials.

Download droidsheep: http://www.insecurestuff.in/2011/09/droidsheep.html


Read More...

5 SECONDS to bypass an iPad 2 password [video]

Video The password protection of an iPad 2 running iOS 5 can be circumvented in less than five seconds with just three simple steps.

Bypassing the unlock screen on iPad 2 can be accomplished by first pressing the power button until the power-off screen is displayed. Users then need only to close and reopen the fondleslab's 'smart cover' before, finally, pressing the cancel button to unlock the device.

After dodging the password protection, you can access the foreground application running at the time the device was locked, potentially exposing corporate email in the process. You can't use the home button, so access is limited to foreground applications. As enterprise IT blog BringYourOwnIT.com notes, one obvious workaround would be to instruct users to close any foreground application before locking their iPad.

Below is a video posted by BringYourOwnIT.com illustrating the easy unlock process.


The security weakness comes days after it emerged that locked iPhone 4S could be accessed using Siri, the voice-activated personal assistant built into the device.
There's an easy way for security-conscious users to disable Siri when their phone is locked but this option isn't applied by default, net security firm Sophos Read More...

19/10/11

Pentesting Iphone Applications

 

Description: This presentation mainly focuses on methodology, techniques and the tools that will help security testers while assessing the security of iPhone applications.
Read More...

18/10/11

NoScript security tool released for Android, Maemo

The mobile version of the Firefox extension includes protection for cross-site scripting attacks and clickjacking

The developer of the widely used Firefox extension NoScript has released a version for the Android and Maemo operating systems.

NoScript is a security tool that can be used to block the execution of JavaScript, Java, Flash, and plugins by websites that are viewed as being potentially malicious. Many Web-based attacks on computers are initiated by JavaScript.

[ Learn how to manage iPads, iPhones, Androids, BlackBerrys, and other mobile devices in InfoWorld's 20-page Mobile Management Deep Dive PDF special report. | Keep up on key mobile developments and insights via Twitter and with the Mobile Edge blog and Mobilize newsletter.

NoScript's developer, Giorgio Maone, wrote on his blog on Saturday that porting the application for Firefox on Android and Maemo was not easy, as it was a full rewrite of the extension, and "there's still a lot of work ahead."

The mobile version, called NoScript 3.0a8, includes protection against cross-site scripting attacks, in which a script drawn from another website is allowed to run that shouldn't. Cross-site scripting can allow an attacker to steal information or potentially cause other malicious code to run.

It also can block "clickjacking," another kind of attack where a user is tricked into clicking on certain parts of a Web page with hidden buttons that perform malicious actions. Those hidden buttons are delivered by an invisible iframe, which is a window that brings other content into the target website.

In 2008, researchers Robert Hansen and Jeremiah Grossman discovered a clickjacking attack involving Adobe Systems' Flash application that could give remote access to a victim's Web camera and microphone.

There are around 1,000 pieces of malware circulating for mobile devices, which pales in comparison to malware built for Windows desktop operating systems. But security analysts predict that mobile phones will increasingly be attacked for the sensitive data stored on the devices.

The NoScript mobile version shares many of the same functions as the desktop one. For example, users can built an "easy blacklist," where they select untrusted sites on which JavaScript and plugins should be blocked. Another option is the "classic whitelist," where sites that are trusted are added to a list that NoScript doesn't block.

Maone wrote that NoScript does not require the browser to be restarted after updates are installed, which "means that hot fixes for new security threats can be deployed in a more effective, timely, and convenient way."
Read More...

BlackBerry outage made roads safer, police claim

Driving with BlackBerryAccording to media reports, police in the United Arab Emirates have given a surprising explanation for a dramatic fall in traffic accidents last week: drivers' BlackBerrys weren't working.

It's claimed that last week's worldwide BlackBerry outage, which frustrated business people around the world who were unable to communicate with their colleagues, had one positive result - less texting and reading of emails by people who should have been concentrating on driving instead.

Road traffic accidents in Abu Dhabi are said to have dropped by 40%, and there was a 20% reduction in Dubai in the past week.

According to The National newspaper, Lt Gen Dahi Khalfan Tamim, the chief of Dubai Police, and Brig Gen Hussein Al Harethi, the director of the Abu Dhabi Police traffic department, both linked the drop to the service disruption experienced by BlackBerry users.

"Absolutely nothing has happened in the past week in terms of killings on the road and we're really glad about that," Brig Gen Al Harethi told the newspaper. "People are slowly starting to realise the dangers of using their phone while driving. The roads became much safer when BlackBerry stopped working."

There may be another explanation for the reduction in mobile-phone related traffic accidents in the UAE, however.

Theyab AwanaAt the end of last month, popular UAE footballer Theyab Awana was killed in a high speed crash near Abu Dhabi, and it was claimed that he was sending a message on his BlackBerry when he hit a lorry.

The football star's father, Awana Ahmad Al Mosabi, made an emotional plea to people not to use smartphones while driving, and a Facebook campaign against the use of BlackBerry Messenger while driving has grown in popularity.

Of course, texting messages or reading emails while you are in charge of a motor vehicle is insane. You aren't just putting yourself at risk, you're putting other innocent travellers in peril as well.

If you need any convincing, here's a shocking video that was made to highlight the danger. Please note: the video is graphic and may be upsetting to some people.



Whether you believe the police are right that the BlackBerry outage contributed to the reduction in road traffic accidents or not, please don't text and drive.
Read More...

14/10/11

Study on Android Auto-SMS

Not long ago, Symantec Security Response posted a blog titled Animal Rights protesters use mobile means for their message, which related to the Trojan horse Android.Dogowar that targets the Android mobile OS. This Trojan may be developed by animal protection organizations, in order to “punish” the mobile users who are fond of playing dog-fighting games.


Once the phone is compromised, it will lead to some unpleasant results. For example, every time the phone is restarted, Android.Dogowar will send a registration SMS to a certain animal protection organization (US users only), and send SMS to all the people in the user’s contact list, saying “I take pleasure in hurting small animals, just thought you should know that”.


It results in adversely affecting the compromised user’s reputation as well as monetary loss as it sends out massive amounts of SMS messages without the user being aware of it.

It made me think of earlier PC threats that were invented for the purpose of showing off or playing a hoax on the recipient. Threat composers need to master good technology in order to manipulate DOS memory blocks, or encrypt or decrypt binaries in boot loader. After the Windows operating system become popular, we saw all kinds of easy-to-use development tools appear, which required less technical knowledge to develop programs. As a result, the amount of malicious programs and threats (worms, Trojans, viruses) increased quickly. In 2007, Google launched the open source mobile platform Android. While people appreciated its openness and advancement, security issues started to draw people’s attention.

One of the most common behaviors of mobile threats is to make money by sending SMS messages. Normally, the sending process is done silently, so that users won’t be conscious about it. However, some threats may ask for user permission before sending out the SMS, just like the legitimate applications. This “obfuscation trick” helps the threats pretend to be a “good” application.

This blog will illustrate a few typical Android mobile threats and legitimate mobile applications to compare their behavior when it comes to sending SMS messages.

Android.FakePlayer

Android.FakePlayer appeared in August 2010 and in retrospect this may be the first Android threat. This threat targeted Russian mobile users. The reason why it’s named FakePlayer is because it adopted the icon of Windows Media Player.

      

When the threat is executed, a Russian alert quickly flashed and quit. In the meantime, the threat started silently sending SMS messages of fixed content to pre-set commercial numbers that costs users money. However, Android.FakePlayer only sends SMS messages when it executes for the first time. It won’t send any SMS messages again even users restart their phones.

Base on our analysis, we found that Android.FakePlayer took advantage of the Android’s SQLite database function to store the “sent” status. If it’s executing for the first time, the threat will use SQL to build a table, insert data, and record execution status. The following is a screenshot of the database file:

        
The database content is as follows:

           

When Android.FakePlayer is executed again, it will first query the database to see if the status is “sent”. If so, the threat will quit immediately.

Apart from using a database, some mobile threats use Android’s SharedPreferences functionality to store status, such as Android.Smstibook.

Android.Smstibook

In May 2011, Google removed a few Android games and small applications from its official sites, including iCalendar, iMatch, ShakeBanger, and ShakeBreak. These applications are actually threats called Android.Smstibook, which is designed to send SMS messages.

In contrast to a typical Android threat, which is simply a repackaged normal application that has malicious code inserted into them, aka Trojanization, Android.Smstibook was developed specifically to masquerade as a legitimate app (a Trojan horse in the classic sense) and published through the Google Market.

                  

                    

Once executed, Android.Smstibook will send SMS messages to commercial numbers, and record the status through SharedPreferences to avoid sending messages a second time. The image below shows the related SharedPreferences file in XML format:

                      

Furthermore, Android.Smstibook makes use of Android’s Receiver mechanism to filter mobile service provider’s SMS messages. This is to prevent users from receiving an SMS message informing them that they have been charged a fee for using a commercial SMS messages.

Of course, normal mobile applications also use SQLite and SharedPreferences to record status, such as Jimm_setup.

Jimm_setup

Jimm is an ICQ chat client for mobile devices. It’s very popular in Russia. Jimm_setup is the installation file.

                          

However, a report claimed that Jimm_setup was suspicious for cheating users, because it cost users 200 rubles (about US$13) to install it. After testing the program, we found that during the installation process, Jimm_setup actually clearly stated that it will send two paid SMS messages, each costing 400 rubles (about US$6.50) each.

    

The installation interface of Jimm_setup


The text translates as “After you click ‘install’ to begin the installation procedure, during which two SMS will be sent to a toll number.”.

Jimm_setup uses SharedPreferences to record if the paid SMS message has been sent to ensure that such SMS messages won’t be sent twice.

However, it’s hard for Jimm’s old users to accept the fact that they need to pay for the previously free application.

Recently, we searched for Android applications that auto-send SMS messages in order to find malware, and interestingly not all of them are malware. Here are some examples of the way applications are harnessing SMS messages and auto-sending SMS messages for 'legitimate' purposes.

Oops! I’m in my bikini. Look

This is freeware on Google Market to edit and share photos in social network sites.


When first executed, users need to register their personal information. Otherwise, they can’t enter the main menu.


While entering the main menu, the application will send SMS messages that are advertisements to the phone itself. If users press the Back button or re-execute the program, same SMS messages will be sent again. This will cause repetitious SMS messages, which will inconvenience users.


However, besides troubles, there is also convenience. For example, when you travel in Zagreb by tram but forget to buy ticket, ZET Panic might be something you need.

ZET Panic

ZET is the abbreviation of Zagreb Tram System. ZET Panic is a customized ticketing application. Once executed, it will send “Zg” to 8585, and then the tourist will receive an SMS reply, which is actually an e-ticket. But in order to enjoy the service, the tourist must be in Croatia.

                  

During our test, we found ZET Panic would alert users that it’s going to send out SMSmessages. If users don’t reply within 4.1 seconds, the SMSmessagesaresent automatically. This step might be improved by adding a “send” button so that users could control whether to send the SMS or not.

    

The text translates as “This Application makes use of Mprijevoz Ticket service: 10kn + SMS. The ticket is valid 90 minutes in all directions.” and “Cancel”.


The text translates as “Request sent” and “OK”.

Android.Nickispy —a backdoor mobile threat that appeared recently—will send the IMEI of the compromised device to a specific mobile number every time the phone is restarted.

In general, the openness of Android platform brings us both advantages and disadvantages. While we enjoy the convenience, we need to be aware of the mobile security issues. Apart from installing trustworthy mobile security software on the phone and downloading applications from official channels, users also need to be extra vigilant to avoid unnecessary problems or even monetary loss.
Once you find any applications suspicious, please uninstall it immediately.
Meanwhile, Symantec and Android service providers monitor the Android threats closely and take action fast when threats are detected.
Read More...

Bogus Netflix Application For Android Steals Passwords, Won't Let You Watch Movies

A report from Symantec claims that malware authors tricked an untold number of Netflix users into coughing up their account credentials with a Trojan horse application that doubled as a Netflix app for the Android platform.

In a blog post, Symantec researcher Irfan Asrar writes about a new piece of malware, Android.Fakenflick (not to be confused with NPR star reporter David Folkenflick, mind you), which looks identical to the legitimate Neflix application, but sends any user name and passwords entered via the Android phone to a remote server controlled by the attackers. According to Symantec, the malware was first identified on October 10 and has been linked to just a small number of infections. After accepting the user's Netflix credentials, the malware displays an message saying the Android phone is not supported by the application, which is then uninstalled.

The malware is designed to look and behave exactly like the legitimate Netflix application for Android - with a similar look and feel. The application also requests the same permissions of the phone user. Asrar hypothesizes that malware authors were simply jumping on an opportunity to get hungry Netflix users to download their malware, after Netflix released an official Android application that only ran on certain Android phones. An ad hoc effort sprang up to port the app to non supported platforms. Users who downloaded Fakenflick may have thought they were getting a grayware ported version of the application. Google's Android mobile operating system has been a leading target of mobile malware writers in the last year. Researchers have uncovered Android versions of popular Windows malware like the Zeus banking Trojan. In June, researchers at North Carolina State University also rang the alarm about a new and stealthy piece of spyware dubbed "Plankton" that was lurking on the Android Marketplace. Google says it suspended a number of applications from the Marketplace in the wake of that revelation The company was already struggling with a persistent infections of Marketplace applications with the DroidDream malware. Kaspersky Lab researchers found that the number of malware signatures for the Andoid operating system tripled between the first and second quarters of 2011, from just 50 to 150. Read More...

Error 3200: Apple iOS 5 stumbles on launch

Apple has launched the much anticipated iOS 5.0 - the new version of its operating system for iPhones and iPads, complete with revolutionary new features such as the iCloud.

It should have been a great moment for the company, and something to put some cheer back in Apple fans' hearts following the death of founder Steve Jobs last week.

iOS 5

However, things aren't going as smoothly and catch-free as the notoriously detailed-orientated company would perhaps like.

Error 3200 trending on TwitterMany users are finding that their attempts to update their iOS devices to the latest and greatest version of the mobile operating system are floundering, with users faced with error messages such as

"An internal error occurred." (3200)
during the install process.
Others are seeing messages related to internal errors 3002 or Error 3004.

Whatever the number, the problem has got so big that the phrase "Error 3200" is currently trending on Twitter.

Theories are bouncing around the net that Apple is simply a victim of its own success, and its servers have not been able to cope with demand for the new version of iOS, meaning that devices are failing to properly register themselves with the mothership. If that's true, you might be wise to wait a day or two.

Error message

Unfortunately, Apple's website isn't being terribly helpful for any users searching for information about what the error may mean:

No results found

Come on Apple, surely you can do better than that?
Me? I have chosen to hold off upgrading my wife's iPhone and iPad to iOS 5.0 - just as we haven't updated our iMac at home to Mac OS X Lion yet.

Call me antediluvian if you wish, but I can't really see the attraction in being an early-adopter. Security patches are one thing, but if something is working for me just fine, I don't feel the need to install the shiny new version as soon as it rolls off the software vendor's conveyor belt.

The risk is always going to be that there are still some wrinkles to iron out. I'd much rather wait until the teething problems have been sorted out, and then consider whether the new features built into Apple's operating system are what I'm after.

This is hardly the most auspicious launch for iOS 5.0 and the much vaunted iCloud. And let's not forget, if there's an error 3200 you have to assume that there's at least another 3199 error messages waiting to show their face to some poor users at some point in the future. :) Read More...

12/10/11

New Symantec Research: The Motivations of Recent Android Malware

For years now, we in the cyber security industry have been saying an explosion of mobile malware is just around the corner. Beginning in earnest this year, we have indeed observed a marked increase in threats targeting mobile devices – particularly the Android platform. However, it’s probably not accurate to say the expected explosion has in fact occurred. The reality is that cybercriminals are still very much in the exploratory phase of figuring out how to monetize the exploitation of mobile devices. This is the topic of Symantec’s latest research. You can read the whitepaper in its entirety here.

Above all else, our analysis highlights how most current efforts to monetize mobile malware have only a low revenue-per-infection ratio. This has severely limited the return on investment achievable by attackers. It also offers detailed insight into the top current mobile malware monetization schemes observed by Symantec, including how each works and examples of the malware presently being used to carry them out. These schemes are: Premium-rate number billing scams
Spyware
Search engine poisoning
Pay-per-click scams
Pay-per-install schemes
Adware
Stealing mobile transaction authentica¬tion numbers (mTAN)

However, the research also points out that the currently struggling revenue-per-infection ratio is primed to improve. The trigger will likely be advances in mobile payment-type technology and the widespread adoption of using mobile devices for both payment and accepting payment. The key is that these applications rely on devices to transmit financial information —such as mobile banking credentials—backed by real monetary funds. We’ve learned in the PC world just how lucrative the exploitation and sale of this kind of information can be for enterprising cyber criminals.

Many vendors are now using mobile devices such as smartphones and tablets as point-of-sale devices. For example, a farmer’s market vendor or a taxi driver may now swipe your credit card through their personal smartphone rather than a dedicated point-of-sale device. Alternatively, a big box retailer may replace their existing point-of-sale devices with well known smartphones or tablets. A malicious attacker who has infected these devices, which is likely easier than infecting existing point-of-sale devices, could potentially skim every credit card transaction.

Additional potential revenue-generating schemes likely to be seen in the near future are discussed as well. These include:

Selling stolen International Mobile Equipment Identity (IMEI) numbers for use on previously blocked or counterfeit phones.
Peddling fake mobile security products—another tactic that has been highly successful in the PC realm.

The paper surmises that only if the current monetization schemes, and those likely to be seen in the near future, succeed will attack¬ers continue to invest in the creation of Android malware.

Whitepaper: Motivations of Recent Android Malware
Read More...

Report: Smartphones will become a way to attack otherwise protected devices

Compromised smartphones will infect computers when they dock in much the same way malware gets onto laptops via thumb drives

Smartphones will become an increasing menace to network security that could drop malware onto protected devices when they dock to sync or plug into USB ports to charge, security experts say in a Georgia Tech report.

Compromised smartphones will infect computers they may plug into for otherwise legitimate reasons, much the same way malware such as Stuxnet found its way onto laptops via thumb drives, according to the "Emerging Cyber Threats Report 2012" (PDF) released at the Georgia Tech Cyber Security Summit 2011" today. It was presented by the Georgia Tech Information Security Center and Georgia Tech Research Institute. [ Stay ahead of advances in mobile technology with InfoWorld's Mobile Edge blog and Mobilize newsletter. ]

ONLINE SECURITY: Father of SSL says despite attacks it has lots of life left

The report warns that "mobile phones will be a new on-ramp to planting malware on more secure devices." The document cites an anonymous industry source saying that "... someone who just needs to charge his phone can introduce malware as soon as it's plugged into a computer within that location."

Other problems include the differences between laptop browsers and those used on smartphones. The latter display address bars fleetingly, leaving little time to observe the safety status of sites being visited, the report says. "If a user does click on a malicious link on a mobile browser," the report says, "it becomes easier to obfuscate the attack since the Web address bar is not visible."

Finding information about SSL certificates a site may be using may be difficult if the information is available through the browser at all, the researchers say.

Touch screens on smartphones may make users more susceptible to clicking on links that seem legitimate but mask malicious sites beneath them, which could lead to drive-by downloads of malware.

Patches and updates for smartphones are woefully infrequent, the report says. "While computers can be manually configured not to trust compromised certificates or can receive a software patch in a matter of days, it can take months to remediate the same threat on mobile devices -- leaving mobile users vulnerable in the meantime."

Meanwhile, the authors say that bot masters will find more ways to make money off their zombie machines beyond using them as spam or DDoS engines. For example, a downloader controlled by a bot master could infect machines with reconnaissance malware that profiles the user of the machine for marketing purposes. The information can be sold and resold until a legitimate business buys the information as part of a lead-generation effort, the report says.

Or alternatively, the zombies could be queried for personal technical details as a way to design a long-term stealthy attack to compromise data. Botnet operators will work more to create bot armies that they lease to others for whatever purpose they have in mind. "Infrastructure and information sharing will also occur more regularly between botnet operators and other malicious actors," the report says.
Read More...

Apple slaps another security band-aid on iTunes

Summary: Apple patches 79 gaping security holes in the iTunes for Windows software.


Apple has shipped iTunes 10.5 to fix mountains of security problems that expose Windows users to dangerous hacker attacks.

The security patch, available for Windows 7, Windows Vista and Windows XP SP2, fixes a total of 79 documented vulnerabilities.  The most serious of these flaws could allow remote code execution attacks via booby-trapped image or movie files.

The bulk of the vulnerabilities affect the open-source WebKit rendering engine that powers the iTunes Store and iTunes LP.

Details on the vulnerabilities can be found in this Apple security advisory.
iTunes 10.5 is being distributed via the Windows software update utility.
 Alternatively, it can be downloaded directly from the iTunes web page.
Read More...

06/10/11

Android malware downloads instructions from blog

Researchers from Trend Micro say the communication mechanism is a first for mobile malware

Researchers from Trend Micro have spotted a piece of malicious software for Android that receives instructions from an encrypted blog, a new method of communication for mobile malware, according to the company.

The malware, which can steal information from an Android phone and send it to a remote server, purports to be an e-book application. It has been found on a third-party Chinese language application store.

[ Also on InfoWorld: Android's big security flaw, and why only Google can fix it. | Master your security with InfoWorld's interactive Security iGuide. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

Trend Micro calls the malware "Androidos_Anserver.a." If the application is installed, it asks for a variety of permissions. If those are granted, it can then make calls, read log files, write and receive SMSes and access the Internet and network settings, among other functions.

The malware uses the blog to figure out which command-and-control servers it should check in to. The command-and-control server then feeds the malware an XML file, which contains a URL where the malware can update itself. It can also connect with the blog to check for new updates. Trend Micro found that 18 variants of the malware have been posted to the blog between July 23 to Sept. 26.
"This is a blog site with encrypted content, which based on our research, is the first time Android malware implemented this kind of technique to communicate," wrote Karl Dominguez, a Trend Micro threat response engineer, on a company blog.

Malware writers have been known to abuse blogging platforms before. Dominguez noted that a botnet discovered earlier this year obtained instructions posted to Twitter.

Some of the newer versions of the malware on the blog "had the capability to display notifications that attempt to trick users into approving the download of an update," Dominguez wrote.

Security experts generally recommend that users should be cautious when downloading Android applications from third-party application stores due to the number of rogue applications that have been found. Users should also keep an eye on what permissions an application asks for and only allow the fewest permissions lest the application has nefarious functions.

 

Read More...

05/10/11

Android Malware Uses Blog Posts as C&C

Newer and more complicated Android malware variants are expected to emerge, along with the rising number of malicious Android apps. A new backdoor that we were able to analyze proves just that. Malware targeting the Android platform are continuously improving in performance as well as using new techniques to thwart analysis and to avoid detection.

This Android malware, which Trend Micro detects as ANDROIDS_ANSERVER.A, arrives as an e-book reader app and can be downloaded from a third-party Chinese app store. It asks for the following permissions upon installation:


Based on the permissions requested alone, it is easy to see that this particular malware has a lot of capabilities. Once granted, the permissions can be used to execute the following:
  • Access network settings
  • Access the Internet
  • Control the vibrate alert
  • Disable key locks
  • Make a call
  • Read low-level log files
  • Read and write contact details
  • Restart apps
  • Wake the device
  • Write, read, receive, and send SMS
For more information on how cybercriminals utilize permissions in conducting malicious routines, check out our e-book, “When Android Apps Want More Than They Need.”

From our analysis, we found that this malware has two hardcoded C&C servers to which it connects in order to receive commands and to deliver payloads. The first server is just like the usual remote site to which the malware posts information to and gets commands from. The second C&C server, however, caught our attention more. This is a blog site with encrypted content, which based on our research, is the first time Android malware implemented this kind of technique to communicate.

Below is a diagram of how ANDROIDOS_ANSERVERBOT.A uses the blog site as a C&C server:

Click for larger view
Further analysis of the blog content revealed six encrypted posts containing backup C&C server URLs:



In addition, 18 binaries have been uploaded to the blog from July 23 to just last September 26. It should also be noted that one of the updates is named _test, which suggests that this malware is still being further developed.



Decrypting the posts and analyzing the binaries, we found out that the files are just different versions of one file. Comparing them, one difference we found is that the newer versions had the capability to display notifications that attempt to trick users into approving the download of an update.



Another addition to later versions is the capability to terminate four security-related apps:
  • com.qihoo360.mobilesafe
  • com.tencent.qqpimsecure
  • com.ijinshan.mguard
  • com.lbe.security
The use of blog platforms in malware activities is not unheard of. In fact, early this year, a botnet was found using Twitter for issuing commands to infected systems. If anything, this recent adaptation of mobile malware is another sign of continued development and proliferation. Read More...

02/10/11

Mobile devices are fast-growing target of malware

IBM's X-Force security research team says mobile application markets are a haven for malware, and expects double the mobile exploits this year

Look for double the mobile exploits this year vs. 2010 and particularly watch out for mobile applications that are really malware, says IBM's X-Force security research team.

Those are two warnings from the "X-Force 2011 Mid-Year Trend and Risk Report," which says that mobile application markets are a haven for malware.

[ Stay ahead of advances in mobile technology with InfoWorld's Mobile Edge blog and Mobilize newsletter. ]

Exploits of mobile operating systems will go from 18 in 2009 to about 35 by the end of 2011, the report says, as the number of vulnerabilities will go from about 65 to more than 180 over the same period.

MOBILE THREAT 
"The first half of 2011 saw an increased level of malware activity targeting the latest generation of smart devices, as attackers are finally warming to the opportunities these devices represent," the new report says.

The report uses Android devices as an example, and notes that since the operating system is open, many developers write applications to it. Some of these apps are malicious, so users should be careful which ones they choose and where they get them from. "One of the most popular and effective ways to distribute Android malware is through application markets. Besides Google's own official market, there are many unofficial third-party markets," the report says.

Another problem with mobile devices, particularly phones, is that users are at the mercy of their phone manufacturer to patch known operating system vulnerabilities. Known vulnerabilities may go unpatched, not because patches don't exist, but because they aren't provided by individual phone makers. "Many mobile phone vendors don't push out security updates for their devices," the report says.

Network defenders face a growing threat from weaknesses in software. These weaknesses are assessed via Common Vulnerability Scoring System (CVSS), with those scoring 10 out of 10 deemed critical. The percentage of critical vulnerabilities has jumped in the first halfof 2011 vs all of 2010 from 1 percent to 3 percent.

That's still a small percentage, but it is triple last year. And the actual number of critical vulnerabilities so far this year is already larger than last, the report says. "Almost every one of these critical vulnerabilities is a serious remote code execution issue impacting an important enterprise class software product," the according to the report.

Vulnerabilities are getting more concentrated among fewer vendors, the study finds. In 2009, the 10 software companies with the most reported vulnerabilities accounted for a quarter of all the vulnerabilities reported. This year so far, that number has jumped to a third (34 percent). IBM X-Force didn't name the top 10. "The bottom line is that enterprise IT staff are spending just as much, if not more time installing patches this year as they have in the past," the report says.The report does point out some bright spots:

* Web application vulnerabilities dropped from 49 percent of all disclosures to 37 percent, the first decline in five years.* Vulnerabilities ranked high and critical are at a four-year low.* Spam and traditional phishing are declining. Read More...

The next frontier in fearing the iPad

Some in IT keep looking for another reason to say no to the world of consumerized IT; mobile DLP is their latest attempt to regain control

In 2010, scaredy-cat IT and security folks wrung their hands over users bringing in their own smartphones and tablets. In early 2011, they wrung their hands over how to control the applications on those devices. Now they're wringing their hands over data leakage from those devices, prompting security vendors to offer mobile DLP (data loss prevention) tools. Zenprise is the first, but you can bet more will follow. (Have you heard of any iPad- or iPhone-related data breaches? I didn't think so.)

I have to give these folks credit: They're persistent in finding ways to say no to modern technology and the realities of today's "consumerized IT," or at least to look for new ways to bind it up in hopes maybe it'll strangle to death. (Good luck with that.) Of course, it's the iPad that seems to stoke these folks' fears the most -- ironically, because it can connect to business systems and actually work with much business data, so people want and use it.

[ Apple has much to learn about securing Mac OS X -- and Microsoft could teach it how. Luckily, iOS security is much, much better. | Compare the security and management capabilities of iOS, Android, WebOS, Windows Phone 7, and more in InfoWorld's Mobile Management Deep Dive PDF report. ]

Mobile Management Deep Dive
Let's be clear: There is data to protect, and I don't believe "anything goes" is the the right policy. And there is some technology worth considering to do so, as I describe later. But I see another agenda behind much of these claims over security concerns. I notice, for example, that companies citing fears over sensitive data emailed to an iPad or of users having unapproved apps on an Android tablet don't have the same concern over data emailed to computers or over the fact that they happily let employees work after hours from home computers full of personal apps. There's a double standard that reeks of a hidden agenda to block the shift to employee-driven technology or to assert new levels of self-justified control in a perverse land grab for relevance or job security.

A good test of whether a security policy is legitimate is if it is applied equally to all endpoints. These days, many endpoints are in use, and we will not go back to the day of employees all working at a corporate office on corporate PCs unconnected to the Internet and locked out from the rest of the world. It's 2011, not 1981. A second good test is whether its cost (in money, lost flexibility, lost opportunity, and time) is worth whatever is being secured.

The fact is, the iPad and all the other mobile devices that have enjoyed so much uptake by individuals and enlightened businesses bring tremendous benefit. More work can be done in more places, improving customer satisfaction and the company's bottom line. Employees can use the tools and devices that fit their personal style, reflecting and honoring what they bring to the table -- they are not robots, after all. And they can use a mix of personal and business tools, which helps the business because now they work more and across additional hours of the day. Additionally, this compensates the employee by letting them reclaim some of that time for their personal lives.


Proposing one problem, but addressing another

Back to this third wave of fear over data on iPads: This week, Zenprise announced an iPad app and related server software that lets iPad users access SharePoint files on their tablets, with the permissions and restrictions honored on the iPad. That's great -- Microsoft's approach to SharePoint has been to restrict it to Windows PCs and Windows Phone 7 smartphones, which only encourages employees to copy the files to cloud storage, email them, and otherwise work outside of SharePoint when they're using an iPad, Android tablet, Mac, or a home PC. This tool addresses some of the security risk created by Microsoft's lock-in strategy for SharePoint. (Zenprise plans a version for Android next year. It started with iPads because they are so widely used in business.)

But Zenprise's pitch didn't start so constructively. It first took the fearmongering route, using an example of the increasingly common practice of boards of directors using iPads to work with the sensitive documents in board meetings rather than going with paper copies. In this regard, corporate boards aren't alone: I learned during a work trip earlier this year that several counties in Florida now give their boards of supervisors iPads to review legislative and regulatory proposals, as they are easier to set up and use than computers.

The Zenprise pitch was that a DLP tool would keep such sensitive documents secure -- except it wouldn't. If the data were emailed, as I was informed, once the data left the organization to its legitimate, DLP-approved recipients, those files could be abused as desired on an iPad, a computer, or any other device with email access. Plus, in Zenprise's case, its DLP is limited to files accessed directly from SharePoint, so it wouldn't address an emailed document. For any documents accessed directly from SharePoint that the user had permission to edit locally, that local copy is not managed by SharePoint or the Zenprise app (it's now in another app, for editing), so it's now free for abuse. The tool does not address the example problem.

The other scary scenario in the pitch was the notion that IT set the data security policies. That's a mistake. Document access policies are a legal and business decision, not one that IT should make. IT should provide the tools to implement the policies and to monitor their compliance, but if IT has to decide what to protect -- or even if someone has to go to IT to protect a document, rather than do it directly -- something is seriously wrong with your technology management.

I don't mean to pick on Zenprise. The folks there try to balance the demands of their customers (for a security vendor, that means the most paranoid ones) with the realities of the users who ultimately deploy their customers' tools. But when a nuanced vendor like Zenprise goes down the fearmongering path, you can only imagine what the more old-school firms will say when they decide to join in.

A better approach to securing corporate data on the iPad

What's changed in business in the last decade (it started with working at home, not with iPads) is that information has to flow to be useful, because different people who may not even be in your organization need to create, refine, and act on it. That means it goes through multiple endpoints and a variety of tools. The old-fashioned approach was to standardize everything on a common platform and toolset, with the common security layer across it all -- the classic model for IT control. But that doesn't work when the world is heterogeneous and by definition not standardized. That's what it is today in most places, and traditional IT control doesn't fit that new world.

Within a SharePoint context, letting iPad users participate within the same rules as Windows users is a good thing. But at the end of the day, it's a partial solution attacking the wrong problem. And let's be honest, Zenprise is not offering a DLP tool but a mobile SharePoint client. That's a good thing for many companies in the here and now that use SharePoint, but it only works in the SharePoint context. If anything, the "consumerization of IT" phenomenon should teach IT that point solutions are insufficient in a heterogeneous context.

So, if you were to use the Zenprise SharePoint client, you couldn't stop there. You might also want to deploy a remote access tool that has the iPad user work with the data virtually so that sensitive information never leaves the managed server -- not just SharePoint servers -- in the first place. That approach of course requires expensive, management-heavy, and bandwidth-intensive desktop virtualization.

Of course, there's a simpler twist on that approach: Using services like Accellion and Box.net that let you set up access-managed shared folders, where documents are restricted to a managed workspace on the mobile device. The problem with these services is that they restrict the users to basic reading and commenting; an employee who wants to work on a proposal or presentation is either prevented from doing so or moves the files to another app, breaking the management control over that file. But that could change: both companies, as well as GoodReader and six others are looking to implement MobileIron's content management API in their apps; not yet in beta, this technology would let IT set policies for content via an MDM tool that the apps would enforce.

A better approach for many companies than all of these would be to extend traditional DLP to mobile devices. DLP works by funneling data traffic to a server that analyzes the content and applies its rules to it (usually just flagging suspect transmissions, but sometimes acting on them, such as to block the transmission).

That way, you're handling all apps and communications, regardless of the
endpoint device, through a universal filter at the data center, where this effort should happen anyhow. In fact, the endpoint device isn't involved, so you don't need to worry about if an app or OS gives you the visibility you need; all you need to do at the endpoint is ensure that its communication is routed through the DLP server. I suspect we'll see DLP tools get extended just that way to handle the new generation of mobile devices -- I sure hope so.

But over the longer term, DLP itself suffers from being an island. It can handle data sent over communications channels, but there are other means to get data from devices, such as local file copying. Ultimately, what we need is digital rights management that works across apps and platforms -- a universal standard that carries the DLP rules with the data itself. Until it exists (if it ever does, considering how proprietary the tech industry has become again, though MobileIron's effort could be a jumpstart), IT is stuck with old approaches that don't fit the new world in which IT still has to provide security.

No easy answers for legitimate IT security needs

Even IT and security leaders who aren't looking to enrich security vendors by asking for more tools that won't really work have a problem: How to secure all the data (and just the data) that needs to be protected while supporting the shift to employee-provided technology and its accompanying flexibility. However, there's no good answer -- yet.

Flexibility and control are a hard combination to get. But users will accept that goal and work with you on it. Remember, not all problems are solved with technology; people are good tools, too. You can start by not trying to recapture mainframe-era IT control, but instead figuring out what data really needs to be protected. From there, you can manage, monitor, and log access to the data so that it's available to those you trust. If it leaks, you might also know who's broken that trust.

If you try to use security to block the flexibility that consumerized IT is really all about, you'll drive your users underground (which increases your security risk), waste lots of money on tools that don't work as you want, and get in the way of your business's ability to work well, setting a path to failure and, ultimately, oblivion. Read More...