::Trend Micro Threat Resource Center::

07 October 2010

Privacy concerns as some Apple iPhone apps transmit UDIDs

Some two thirds of popular iPhone apps transmit users UDIDs, leading to potential security concerns, a new study has warned.

Eric Smith, Assistant Director of Information Security and Networking at Bucknell University in Lewisburg, Pa., discovered 68 percent of the 57 top applications in the App Store sent out UDID information, back to a remote server, owned either by the application developer or an advertising partner.

Those popular iPhone applications tested included those from Amazon, Chase Bank, Target, Sams Club, Best Buy, Barnes & Noble, eBay, PayPal, Bank of America, Wells Fargo, Fidelity and American Express.

UDIDs, or unique device identifiers, are a 40-digit sequence of letters and numbers, and can be used to identify users and transmit sensitive information, unencrypted and to third parties.

Smith warned that popular applications such as those from Amazon, Facebook or Twitter inherently have the ability to tie a UDID to a real-world identity. “Most iPhone application vendors are collecting and remotely storing UDID data, and some of these vendors also have the ability to correlate UDID to a real-world identity,” Smith said.

“For example, Amazon’s application communicates the logged-in user’s real name in plain text, along with the UDID, permitting both Amazon.com and network eavesdroppers to easily match a phone’s UDID with the name of the phone’s owner.”

Smith noted in conclusion: “Privacy and security advocates, personal iPhone owners, and corporate iPhone administrators should be concerned that it would be feasible—and technically, quite simple—for their browsing patterns, app usage, and physical location collected and sold to unintended customers such as advertisers, spouses, divorce lawyers, debt collectors, or industrial spies.”

“Since Apple has not provided a tool for end-users to delete application cookies or to block the visibility of the UDID to applications, iPhone owners are helpless to prevent their phones from leaking this information.”

Apple’s mobile platform is not alone in being open to potential abuse. Researchers at Duke University, Pennsylvania State University and Intel Labs discovered only last week that many applications on Google’s rival Android platform were sending information, such as users GPS location and phone numbers, without the knowledge or permission of the user.

Smith’s full study, iPhone Applications & Privacy Issues: An Analysis of Application Transmission of iPhone Unique Device Identifiers (UDIDs), is available as a PDF.

Smith, author of the study, is a founding member of PreSet Kill Limit, the security research group which has won the Defcon Wardriving hacking contest several years in a row.

06 October 2010

Adobe plugs 23 holes in Reader, Acrobat

As expected, Adobe released updates for Reader and Acrobat today that fix 23 holes in the popular PDF-viewing programs, including two that are actively being exploited in attacks that could allow someone to take control of the computer.

One of the critical vulnerabilities is being used in attacks against Reader and Acrobat; the other, fixed in an emergency update late last month, targets Flash Player.

The updates affect Adobe Reader 9.3.4 for Windows, Macintosh, and Unix; Adobe Acrobat 9.3.4 for Windows and Macintosh; and Adobe Reader 8.2.4 and Acrobat 8.2.4 for Windows and Macintosh to resolve issues in Reader, Acrobat, and Flash Player. Details are in the latest security advisory.

The next quarterly security updates for Adobe Reader and Acrobat are scheduled for February 8, 2011.

05 October 2010

CYBER BANKING FRAUD: Global Partnerships Lead to Major Arrests

Just when you thought you could get away with cyber crime just becoz of anonymity online? Think again.

Law enforcement partners in the United States, the United Kingdom, Ukraine, and the Netherlands announced the execution of numerous arrests and search warrants in multiple countries in one of the largest cyber criminal cases ever investigated.

Using a Trojan horse virus known as Zeus, hackers in Eastern Europe infected computers around the world. The virus was carried in an e-mail, and when targeted individuals at businesses and municipalities opened the e-mail, the malicious software installed itself on the victimized computer, secretly capturing passwords, account numbers, and other data used to log into online banking accounts.

The hackers used this information to take over the victims’ bank accounts and make unauthorized transfers of thousands of dollars at a time, often routing the funds to other accounts controlled by a network of “money mules.” Many of the U.S. money mules were recruited from overseas. They created bank accounts using fake documents and phony names. Once the money was in their accounts, the mules could either wire it back to their bosses in Eastern Europe, or turn it into cash and smuggle it out of the country. For their work, they were paid a commission.

On 30 Sept 2010, New York office arrested 10 subjects related to the case, and they are seeking 17 others. Those arrested are charged with using hundreds of false-name bank accounts to receive more than $3 million from victimized accounts.

In all, the global theft ring attempted to steal some $220 million, and was actively involved in using Zeus to infect more computers.

More details here:
http://www.fbi.gov/page2/oct10/cyber_100110.html

04 October 2010

Remote Linux desktop for your iPad

Great news for Apple iPad users who want to administrate Linux machines remotely.

iLIVEx is a fast, secure and fault-tolerant X11 client that turns the Apple iPad into an X terminal for Linux and Unix. It allows iPad users to connect to Unix and Linux desktops and applications hosted on remote Unix and Linux servers.

iLIVEx features an ultra-thin data transfer protocol allowing for LAN-like performance, even over 3G connections. Its connections also run over securely encrypted SSH tunnels. Built-in session persistency allows users to reconnect to their remote desktops should the iPad get disconnected, turned off or the user temporarily switches to another iPad app.

iLIVEx is also designed to provide non-Linux users the ability to run a remote desktop. With their purchase of iLIVEx, StarNet provides a free Linux desktop account on a StarNet-hosted Linux server. On their remote desktop users gain a number of capabilities not currently available on iPads. These include:

Viewing Flash – By way of Firefox on their remote Linux desktop, iLIVEx enables iPad users to work with flash-based web sites and applications.

True multi-tasking – iLIVEx users can work on multiple office applications (wordprocessor, email, spreadsheet, etc.) simultaneously, even copy and paste data between them.

Persistency – Users can reconnect to their remote Linux/Unix desktop at any time, even after the iPad has disconnected from the network. No work is lost due to a disconnect.

Desktop switching – Users can seamlessly switch their remote desktops between iPads, Windows, Linux and Macintosh PCs.

03 October 2010

iTunes Store Spam Campaign

Right after LinkedIn Spam Campaign, we saw a brand new Spam Campaign impersonating iTunes Store.

The e-mail appears to arrive from on behalf of iTunes Store and is an exact copy of the official iTunes Store Receipt e-mail.

The whole purpose of the email is not to show what you have purchase from iTune Store, but to let you to click “Report a Problem” and lead you to a fake Adobe Flash installer.

Read more about this spam campaign here.

02 October 2010

Microsoft To Unveil Windows Phone 7 Devices In October

Jefferies & Co. expects Microsoft Corp. to announce the launch of Windows Phone 7 devices on Oct. 11 in New York City. The brokerage reiterated its "buy" rating on shares of the software giant with a price target of $33.

"Microsoft also has an event scheduled in London on Oct. 4, so the launch may even be as early as next week. New devices from at least five [device manufacturers] -- Asus, Dell, HTC, LG and Samsung -- are likely to be available first in Europe, and later in the United States. We expect the initial wave to support only GSM. CDMA versions might become available in early 2011," said Egbert.

More details here.