::Trend Micro Threat Resource Center::

Showing posts with label Amazon. Show all posts
Showing posts with label Amazon. Show all posts

31 March 2015

Android flaw puts personal data at risk for millions

Nearly half of Android devices are vulnerable to an attack that could replace a legitimate app with malicious software that can collect sensitive data from a phone.

Google, Samsung and Amazon have released patches for their devices, but 49.5 percent of Android users are still vulnerable, according to Palo Alto Networks, which discovered the problem. Google said it has not detected attempts to exploit the flaw.


A malicious application installed using the vulnerability, called "Android Installer Hijacking," would have full access to a device, including data such as usernames and passwords, wrote Zhi Xu, a senior staff engineer with Palo Alto.

The company wrote two exploits that take advantage of the flaw, which involves how APKs (Android application packages) are installed.

The vulnerability only affects applications that are installed from a third-party app store. Security experts generally recommend using caution when downloading apps from those sources.

Apps downloaded from third parties place their APK installation files in a device's unprotected local storage, such as an SD card, Xu wrote. From there, a system application called PackageInstaller finishes the installation. The flaw allows an APK file to be modified or replaced during installation without anyone knowing.

An attack would work like this: A user downloads what appears to be a legitimate application. The application asks for certain permissions on the device. During that process, Palo Alto found it was possible to swap or modify the APK file in the background because the PackageInstaller fails to verify it, Xu wrote.

After clicking the install button, "the PackageInstaller can actually install a different app with an entirely different set of permissions," he wrote.

Android devices do not need to be rooted for the attack to work, although rooting does make devices more vulnerable.

When the flaw was discovered, in January 2014, close to 90 percent of all Android devices were affected. That has since dropped to 49.5 percent, but many devices have not been patched.

Palo Alto's exploits were successful against Android versions 2.3, 4.0.3 to 4.0.4, 4.1.x, and 4.2.x. The 4.4 version of Android fixes the issue. Some Android 4.3 devices may still be affected, however, since some manufacturers have not patched yet, Xu wrote.

Google has published a patch here, and Amazon recommends downloading the latest version of the Amazon AppStore, which will update its Fire devices, Xu wrote.

Palo Alto has also developed an Android app that will detect if a device is still vulnerable.

28 December 2014

Hackers leak 13,000 Passwords Of Amazon, Walmart and Brazzers Users

Hackers claiming affiliation with the hacktivist group "Anonymous" have allegedly leaked more than 13,000 username and password combinations for some of the worlds most popular websites, including Amazon, Xbox Live and Playstation Network.

The stolen personal information was released in a massive text document posted to the Internet file-sharing website Ghostbin (now deleted), on Friday. The document contains a huge number of usernames and passwords, along with credit card numbers and expiration dates.

The news came just a day after the hacker group Lizard Squad compromised Sony’s Playstation and Microsoft’s Xbox Live gaming networks on Christmas day, which is estimated to have affected Xbox's 48 million subscribers and PlayStation's 110 million users, making it a total of more than 150 million users worldwide.

However, data breach of 13,000 users is not the biggest data breach we've ever seen. When millions of passwords are used for sites around the globe, chances are very minor that our’s among those compromised. But still it’s important to note as these accounts come from a variety of online sources and among those, some are really very popular.


The Daily Dot's Aaron Sankin has compiled a comprehensive list of sites associated with the username and password leaks, and discovered that the leaks came from the sites run the gamut from pornography to gaming to online shopping. The list of the compromised websites is as follows:

  • Amazon
  • Walmart
  • PlayStation Network
  • Xbox Live
  • Twitch.tv
  • Dell
  • Brazzers
  • DigitalPlayground
  • and see complete list.

Just to be on a safer side, users are recommended to change their passwords if they have accounts on these compromised websites, and also pay attention to your credit card transactions and if any suspicious activity found, immediately communicate with related banks and financial institutions.

Also, don't use the same passwords for banking and online shopping sites, and always keep an eye out for unusual activities or unauthorized purchases with your accounts.

18 September 2014

Download this Kindle eBook, and have your Amazon account cookies stolen

A security researcher has reported what appears to be an embarrassing flaw on Amazon’s website that could put Kindle users at risk.

Benjamin Daniel Mussler claims that the “Manage Your Content and Devices” and “Manage Your Kindle” services on Amazon’s web-based Kindle Library are vulnerable to a cross-site scripting (XSS) attack, which can be exploited by a boobytrapped eBook title.


Anyone wanting to target a Kindle user would go about go about their attack by creating an eBook with a specially-crafted title:

When the boobytrapped eBook is added to the intended victim’s library, the code will be automatically executed when the Kindle Library webpage is opened.

According to Mussler this means that “Amazon account cookies can be accessed by and transferred to the attacker and the victim’s Amazon account can be compromised”.

The good news is that you’re unlikely to find an eBook with a maliciously-crafted title in the official Kindle eBook store, provided Amazon keeps its eyes open. Instead, the only real chance that you might fall victim to the vulnerability is if you pirate eBooks, downloading them from dodgy sources and use Amazon’s “Send to Kindle” service to have them accessible on your reader.

The bad news, however, is that Mussler says he first reported the vulnerability to Amazon in November 2003 – along with an example eBook that ran proof-of-concept eBook that grabbed cookies and sent them to him. Amazon’s technical team managed to fix the flaw within four days. 

Most people would consider that a reasonable response, and a job well done… but there is more to this story.

To Mussler’s shock, the very same vulnerability was introduced approximately two months ago, and currently remains unfixed. The researcher informed Amazon that the security hole has re-emerged, but received no response from the company.

For that reason, Mussler has decided to go public with his findings and even published example code on his website that allows anyone to replicate the vulnerability.

Whether you think public disclosure of the vulnerability was the right approach or not is a matter of some debate. One thing is clear, however. Amazon needs to fix the security hole, even if it is only likely to be a risk for a small number of Kindle users, and fix it permanently.

In the meantime, Kindle users are advised to get their eBooks from official stores – just to be on the safe side.


28 July 2014

Malware scare on Amazon.in

Amazon India, the Indian arm of the world’s biggest e-commerce player has certainly been making all the right moves and a few months ago reportedly hit the $200 million mark in sales and could hit the $1 billion number by March 2016.

Amazon India sells 15 million products across 20 product categories, which makes Amazon bigger in terms of products on offer than competitors Flipkart as well as Snapdeal.

Clearly, Amazon India is expanding at breakneck speed and one of the ways the company is doing it is by reducing the time between merchant registration and listing the first product, with Amazon India almost 2-3 weeks quicker than competition.

Now, this focus on speed may be coming back to bite Amazon on its backside. Because at least on one vendor’s product pages, dangerous malware has been detected by Google.

Yesterday, I was purchasing a product on Amazon.in, when I clicked on some other products by the same vendor and to my horror saw Google browser Chrome warning me on some product pages with a message stating that Google Chrome had blocked access to the page on www.amazon.in. The warning further said that “content from s.m2pub.com, a known malware distributor” had been inserted into the Amazon.in webpage, and that visiting the page was likely to infect my computer with malware.


I wrote to Amazon India asking for a comment. Amazon India’s first response was to point a finger back at me, saying that it could mean that my computer was infected. I wrote back explaining that I hadn’t got pop-up ads whenever I opened a new tab (a clear sign of my computer being infected), but had got an unambiguous message from Google Chrome warning me that certain webpages on Amazon.in were infected with malware.

Later an Amazon India spokesperson admitted the problem, though still claiming it was just a misconfiguration error. “We were made aware of the issue through a few customers. On review we found there to be a misconfiguration in a third party vendor code. We have since rectified it,” the Amazon India spokesperson said. Most likely, images, etc, uploaded by the third party vendor may have contained this malware and if true may indicate that Amazon’s security didn’t work as it should.

When it comes to online shopping, reputation is everything and Amazon certainly knows that. And once a user comes across malware warnings, he would also be wary of other Amazon features such as the one where your credit card details are stored for easier purchase the next time. We’ve all seen what happened to retailer Target after a breach, with the after effects claiming the Target CEO himself.

Ebay is another recent example after intruders managed to access its database. In fact, though Ebay India would not admit it, immediately after the attack even the Ebay India website was going slow on transactions and cancelling many transactions even after payment.

And while the Target and Ebay breaches have to do with the wealth of data stored on their servers, malware through webpages is one route to infiltrate inside corporate systems.

Amazon India needs to be careful. If it sacrifices security for speed, the price it pays could be very heavy and all its mega growth plans may just remain that–mere plans on paper

22 June 2011

Spam e-books plague Amazon's Kindle store

If you are a regular customer of Amazon's Kindle store, you could already be aware of the fact that spammers are using it to fleece customers out of their hard-earned cash by tricking them into buying bogus e-books.

The scam is made possible by the fact that anyone can publish an e-book on Amazon and offer it for sale. Unfortunately, there is no barrier to publishing as many e-book as one wants, and scammers have jumped at the opportunity.

The scammers can either use an already published e-book, change the title, author and cover and pass it off as a completely different book, or they can use a piece of software that packages public domain content, equips it with a cover and title and submits it for sale.

All in all, the process is very fast and allows scammers to churn out dozens or even more titles a day. Since Amazon doesn't charge for the publishing of e-books or making it available in the store, if the bogus titles are bought even a couple of times, the scammer has earned enough money to justify the time spent on it.

Amazon does try to weed out these books, but a 48-hour approval process obviously allows quite a few of them to slip through unnoticed, mixed with the legitimate titles.

According to Eric Mack, a longer checking process might help with weeding out the offending e-books. Another simple but likely effective solution would be to institute a charge for everyone who wants to publish an e-book on Amazon.

"Charging authors $50, $20 or even just $10 to publish to Amazon would drastically cut back potential profits for spammers, and any author that spent months or years crafting a quality work should have no problem shelling out a small amount to access a global market and ensure that there's fewer titles to weed through," he believes.