• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

More Malicious Android Apps

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
If you are an Android phone owner, keep your eyes peeled for malicious apps that can ruin your day by running up your bill. Symantec has the lowdown:

We have detected a few applications carrying Android.Pjapps code. One of these applications is Steamy Window. Similar to other compromised Android applications, it is difficult to differentiate the legitimate version from the malicious one once it is installed. However, during installation it is possible to identify the malicious version by the excessive permissions it requests.
 
Guess this answers my question on whether or not I need a Android anti-virus....
 
Just de-select the option to install applications from unknown sources. If you absolutely must install an app from an unknown source, temporarily enable the option and then disable it again afterwards.

I wonder if the security companies are deliberately using scare tactics in an attempt to create a market for anti-virus software for handheld devices, much like they already have done for Windows. Now that Microsoft has the audacity to provide anti-virus/malware tools for free with their own OS, I guess the anti-virus companies are looking for new markets.

With Windows, the strategy backfired when malware programmers started using the same strategy, making their malware look like fake antivirus/security suites. I would hate to see the same thing happening to Android.
 
good to know this information before hand, since I plan on purchasing a Motorola Bravo (Android O/S) for the wife this week. (birthday)
 
These can't install themselves. You have to install them.

Protips:
Buy only "with Google" devices so you have access to Google Market, and all the awesomesauce that comes with Google Apps.

Don't install software not obtained from the Google Market. While it's possible for something to sneak in, chances are it won't last.

If you need to install software not found on Google Market, you should be smart enough to avoid any problems.

I have little sympathy for most people who get infected like this. You're being a dumbass installing pirated software, or not paying attention to the screens presented to you. It's a bigger issue in markets where you can't get "with Google" devices (or simply where the cheaper non approved devices are prevalent like China).

I don't want people to rely on bloatware anti virus and anti malware kits for their phones. I want people to either get smarter or die trying, it's better for the human race. :D
 
A little common sense and reading what permissions an app requires goes a long way.

Google Navigation - requires GPS.
Sudoku - SHOULD NOT REQUIRE GPS.

Handcent SMS - requires being able to access your SMS messages.
A live wallpaper - Why does a live wallpaper need to see your texts?
 
Symantec discovered this when 18 of its top employees, entire CEO team, marketing team, distribution team, etc etc all had their company andriod phone infected.

Just kidding, but, this sounds like a pre-emptive get the Symantec anti-virus for your iPhone...
 
A little common sense and reading what permissions an app requires goes a long way.

Google Navigation - requires GPS.
Sudoku - SHOULD NOT REQUIRE GPS.

Handcent SMS - requires being able to access your SMS messages.
A live wallpaper - Why does a live wallpaper need to see your texts?

Yep... me and you must be the limited amount of people who actually read that part, most people just agree and don't read what the app wants to use on your phone.

I must say though, that I have avoided at least 25% of potential apps because they ask for really scary stuff (like for instance a game that "requests all contact data" or a simple calculator that "requires full internet access".

No thanks, pass on the fishyness.... I am glad android has this safety feature before you download an app.
 
it really is just common smarts.

I admit I don't always check what permissions an app wants if I get it from google market, but 3rd party stuff I check everything for permissions that seem fishy.

I also use droidwall in whitelist mode, so all apps are denied any sort of data access until I specifically checkmark it as being allowed.

Combine that with TrafficStats so I can see if anything is out of the ordinary for data usage (all advertising is blocked, so most apps shouldn't have any data usage showing at all).

Makes for one very happy phone :)
 
Yeah, this truly does seem to come down to common sense, just like most cases of malware outbreaks on PCs.

"What do you mean, I don't get a free prize for being the 1,000,000th visitor?!?" :D
 
For a bunch of smart computer geeks/dorks/users (like most of us), it seems that almost all of you *still* don't get "it".

What is common sense to us, is NOT common sense to the girl down the street "txting" her friends, yo. It also doesn't apply to our 65 year old parents that have allergic reactions to all things Internet related, who consequently believe Internet Explorer or Safari are "the internet".
Most people don't run bandwidth monitors on their phones, or disabled functions only to enable them "when necessary".

We aren't the intended target of these malware makers. Our parents are. Those kids on the corner txting each other (while standing next to each other), are. The uninformed and those that "just don't care" are their intended targets...because they're realistic targets. Coyotes don't attack Wolves. Coyotes attack small animals, easy prey, etc. In this context, we are the wolves...and the others I spoke of are the easy prey...therefore they go after them.

The problem is, the industry doesn't base things like their futures on us...it bases them on the common demographic...IE, the OTHER 99% of their customer base.

Kinda like when a mechanic can "hear" what's wrong with your car...and says, when it squeaks like that, X is going bad -- ya know...it's common sense. No, it's not. It common sense in that industry, but to the rest of us, it's a fucking squeak coming from somewhere under the hood.
 
Protip: It's a good idea to read what permissions an app requires before installing it.

A little common sense and reading what permissions an app requires goes a long way.

Google Navigation - requires GPS.
Sudoku - SHOULD NOT REQUIRE GPS.

Handcent SMS - requires being able to access your SMS messages.
A live wallpaper - Why does a live wallpaper need to see your texts?

If only the common person understood this. The security in Android is very good. It's up to the user to be stupid. :( :eek: :mad:

For a bunch of smart computer geeks/dorks/users (like most of us), it seems that almost all of you *still* don't get "it".

What is common sense to us, is NOT common sense to the girl down the street "txting" her friends, yo. It also doesn't apply to our 65 year old parents that have allergic reactions to all things Internet related, who consequently believe Internet Explorer or Safari are "the internet".
Most people don't run bandwidth monitors on their phones, or disabled functions only to enable them "when necessary".

We aren't the intended target of these malware makers. Our parents are. Those kids on the corner txting each other (while standing next to each other), are. The uninformed and those that "just don't care" are their intended targets...because they're realistic targets. Coyotes don't attack Wolves. Coyotes attack small animals, easy prey, etc. In this context, we are the wolves...and the others I spoke of are the easy prey...therefore they go after them.

The problem is, the industry doesn't base things like their futures on us...it bases them on the common demographic...IE, the OTHER 99% of their customer base.

Kinda like when a mechanic can "hear" what's wrong with your car...and says, when it squeaks like that, X is going bad -- ya know...it's common sense. No, it's not. It common sense in that industry, but to the rest of us, it's a fucking squeak coming from somewhere under the hood.

Since these malicious apps are currently installed outside of the normal Android Market it isn't that big a deal. Most non-tech savvy people won't know how to enable the "Install from Unknown Sources" to begin with.

However, both the Android Market and iTunes App Store can be tricked by a savvy enough coder. That way the malicious app would be on a trusted site. There have already been apps pulled from both markets due to what they do after the install (see below).

Malicious apps? Whats that?

<----- iPhone user

/sigh

Ignorance is bliss I guess. I suppose you forgot about the wonderful SMS security hole that could have been easily exploited if the guy who discovered it had not been a White Hat.

http://www.businessweek.com/technol...hone_virus_vulnerability_thing_its_fixed.html

How about iPhone apps that were actually approved by Apple only to be pulled afterward? iPhone user entire contact list being sent to a central server. One company actually calling users after they install an application. Other companies collecting user data without their permission. I don't know about you but I damn sure consider those to be malicious applications. At least on Android you know what permissions the application is asking for. iPhone users are completely in the dark about what the application can access.

http://news.cnet.com/8301-27080_3-10446402-245.html

It's only logical that the next avenue of attack by virus/malware writers would be the mobile sector. At this point though it is nothing but fear mongering by the AV companies in order to try to get a foothold into the market and prey on the uninformed. The sad thing is AV on Android is worthless.

The way Android security works is that it sandboxes each application from each other. That means the AV software couldn't do jack shit about an infected application other then possibly throwing up a notification saying "Delete this application manually as it is malicious." The only way an AV would be effective on Android is if it had root access, which of course they do not have. ;)

Based on my reading I assume that iPhone and Windows Phone 7 have security models that are designed with the same idea in mind as well again making AV pretty damn worthless.
 
Back
Top