::Trend Micro Threat Resource Center::

Showing posts with label iphone. Show all posts
Showing posts with label iphone. Show all posts

15 February 2016

Warning — Setting This Date On iPhone Or iPad Will Kill Your Device Permanently

Don’t Try this at Home! An interesting software bug has been discovered in Apple's iOS operating system that could kill your iPhone, iPad or iPod Dead Permanently.



Yes, you heard me right.

An issue with the date and time system in iOS had emerged recently when Reddit users started warning people that changing your iPhone's or any iOS device's date to January 1, 1970, will brick your iPhone forever.

You can watch the whole process in the video given below. Even regular recovery tricks do not work


So, you are recommended to Not Try This Trick with your iOS device really – unless you book a trip to your local Apple Store.

While I don’t have any intention or desire to try it out with my iPhone 6s to confirm the authenticity of the bug, it is pretty much clear based on reports that seem legitimate.

YouTuber Zach Straley first discovered the issue, which was later confirmed by iClarified, who tested the trick on an iOS device.

Affected iOS Devices
This bug affects any iOS device that uses 64-bit A7, A8, A8X, A9 and A9X processors and runs iOS 8 or newer, including iPhones, iPads, and iPod touches. However, for those running on 32-bit iOS versions are not affected by this issue.

How the Bug Kills the iPhone?
Basically, the whole process is due to this:

  • Set up the date to January 1, 1970, via settings on your iOS device
  • Reboot your device, and you are done.
Your iPhone or iPad will no longer boot and will be stuck to the Apple logo. Even recovery mode restore or DFU mode will not let you restore your device; it will remain stuck on the bootup screen.


Your device will reportedly not come back, and the only way to get it back to work once again is to take your iOS device to an Apple Store.

The Only Way to Get Your iPhone Back
The bug is believed to be related to UNIX timestamp epoch that causes the kernel to crash. The only way to get it back is to open the device's casing and physically disconnect the battery from the logic board. This could only be done with the help of Apple's Genius Bar.

This process will reset the iPhone's date and allow it to boot.

While there isn't any other fix at the moment, Apple is expected to come up with a software update to fix and unbrick the affected iOS devices.

Though some users are saying that letting the battery drain could make the iPhone work once again, or changing the SIM card could fix the issue, or waiting for the device to back after 5 hours, you are still advised to not try this on your device as there is no guarantee these tricks are going to work.

08 October 2015

YiSpecter threat shows iOS is now firmly on attackers’ agenda

YiSpecter Trojan abuses Apple’s iOS enterprise provisioning and private APIs to earn ad revenue. Avoid it by not installing apps from untrusted sources.


Until recently, iOS device users have had a relatively quiet ride on their mobile computing journey, particularly compared to their Android-owning counterparts. Apart from the odd threat popping up here and there, there’s not much to speak of in terms of major malware issues for iOS. But this status quo is starting to change.

This year, Symantec has seen an uptick in threats hitting the iOS platform. YiSpecter (IOS.Specter) is the latest piece of malware that continues the trend of increasing attacks against iOS devices. The malware is designed to target Chinese speakers and has affected East Asia, particularly China and Taiwan. We understand that the threat is being distributed through alternative app stores, hijacked internet service provider (ISP) traffic redirecting users to download YiSpecter, forum posts, and social media.

YiSpecter is a Trojan horse for both jailbroken and non-jailbroken iOS devices which is designed to perform a range of functions, but essentially provides the basis for a back door onto the compromised device and installs adware. The Trojan can allow an attacker to perform a range of functions such as uninstalling existing apps, downloading and installing new fraudulent apps, displaying advertising in other apps that are installed on the device, and much more.

Abusing enterprise certificates to target non-jailbroken devices
YiSpecter is an iOS threat that takes advantage of the enterprise app provisioning framework. In legitimate uses of the framework, businesses can avail of enterprise certificates to provide private apps to their own workforce without making them publicly available on the official App Store. Apps built and signed with the certificates do not need to be vetted by Apple before being distributed outside of the App Store. This gives the certificate owner more scope to develop apps with features that would otherwise be rejected by Apple.

The malware creator used iOS enterprise certificates to package and sign their threat. They could have gained access to the certs in a few ways:

  • Registering with Apple as an enterprise, paying the necessary fees, and going through the vetting procedure
  • Stealing the cert from an existing registered developer
  • Partnering with a registered developer

Once YiSpecter’s creators have the enterprise certificate, they are in a position to create and distribute their apps to potentially any iOS device without further oversight from Apple. It should be noted that if Apple learns of the misuse of an enterprise certificate, the company could instantly revoke the cert and render the signed apps useless.

A common feature of enterprise-signed apps is that they can generally only be installed after the user accepts the request to trust the app or developer. From past experience, Symantec knows that asking the user whether they trust an app or developer is rarely an effective security measure but this is still a line of defense that needs to be crossed before the malware can be installed.

Invoking private APIs
YiSpecter can carry out a lot of advanced functionality because it uses Apple’s own private APIs to perform activities that standard iOS apps can’t. These APIs are designed to allow Apple’s apps to carry out a range of system-level actions. iOS developers are not supposed to use these APIs in their apps.

Any third-party apps that use these private APIs are rejected from inclusion on the Apple App Store. YiSpecter ignores the official App Store, instead relying on unofficial distribution channels to spread the malware. As a result, the threat can take advantage of the private APIs for its own purposes.

Potential copycats
The idea of invoking the private APIs in iOS is not a new idea, but it was not something that we had seen before in iOS malware. Similarly, the abuse of enterprise provisioning is a well-known problem dating back a number of years.

What YiSpecter has demonstrated is that when these two techniques are combined, the potential for misuse is high. Now that the combination of these techniques have been proven, we may yet see copycat threats in future.

Mitigation
iOS device owners are advised not to download and install apps from untrusted sources. Instead, they should only download apps from the official App Store or from their company’s own approved app library.

We would also recommend that iOS users should avoid jailbreaking their devices. This practice violates the terms of the iOS license agreement and puts the device at an increased risk of attack.

Users should ensure that the device’s operating system and software are up to date with latest patches.

Symantec has listed top tips on how to better secure your iOS device from attacks.

21 September 2015

Apple’s iOS App Store suffers first major attack

Apple Inc said on Sunday it is cleaning up its iOS App Store to remove malicious iPhone and iPad programs identified in the first large-scale attack on the popular mobile software outlet.


The company disclosed the effort after several cyber security firms reported finding a malicious program dubbed XcodeGhost that was embedded in hundreds of legitimate apps.

It is the first reported case of large numbers of malicious software programs making their way past Apple’s stringent app review process. Prior to this attack, a total of just five malicious apps had ever been found in the App Store, according to cyber security firm Palo Alto Networks Inc.

The hackers embedded the malicious code in these apps by convincing developers of legitimate software to use a tainted, counterfeit version of Apple’s software for creating iOS and Mac apps, which is known as Xcode, Apple said.

“We’ve removed the apps from the App Store that we know have been created with this counterfeit software,” Apple spokeswoman Christine Monaghan said in an email. “We are working with the developers to make sure they’re using the proper version of Xcode to rebuild their apps.”

She did not say what steps iPhone and iPad users could take to determine whether their devices were infected.

Palo Alto Networks Director of Threat Intelligence Ryan Olson said the malware had limited functionality and his firm had uncovered no examples of data theft or other harm as a result of the attack.

Still, he said it was “a pretty big deal” because it showed that the App Store could be compromised if hackers infected machines of software developers writing legitimate apps. Other attackers may copy that approach, which is hard to defend against, he said.

“Developers are now a huge target,” he said.

Researchers said infected apps included Tencent Holdings Ltd’s popular mobile chat app WeChat, car-hailing app Didi Kuaidi and a music app from Internet portal NetEase Inc.

The tainted version of Xcode was downloaded from a server in China that developers may have used because it allowed for faster downloads than using Apple’s U.S. servers, Olson said.

Chinese security firm Qihoo360 Technology Co. said on its blog that it had uncovered 344 apps tainted with XcodeGhost.

Apple declined to say how many apps it had uncovered.

18 September 2015

AirDrop vulnerability is an easy avenue for hackers to exploit Apple devices



Recently, an alarming vulnerability has cropped up on iOS devices. This security loophole allows an attacker to overwrite arbitrary files on a targeted device and, when used in combination with other procedures, install a signed app that devices will trust without presenting a warning notification to users.

In a recent article published on Threatpost, it’s noted that the vulnerability is located in a library that lies within both iOS and OS X. In this case, the library in question is AirDrop, the tool featured on Apple devices that allows users to directly send files to fellow Apple device quickly and effortlessly.

The problem lies within the fact that Airdrop doesn’t use a sandboxing mechanism in the same way that many other iOS applications do. When making use of a sandbox, every application has its own container for files that it can’t get beyond the so-called “walls“ of.

AirDrop gives users to the choice to accept file transfers either from only their own contacts or anyone who sends them a request to send files. In the case that a user can receive files from anyone, it’s quite easy for an attacker to exploit their device on their locked iOS device.What’s more, the attacker can even make the attack without the user agreeing to accept a file transferred using AirDrop.

Directory traversal attacks make the exploitation of this vulnerability possibleMark Dowd, the security researcher who discovered the vulnerability, has been able to repeatedly and reliably exploit the security flaw. The vulnerability allows the attacker to execute a directory traversal attack, in which the attacker attempts to access files that are not intended to be accessed. Thus, the attackers are capable of writing files to any location they choose on the file system.

Since sandboxing rules weren’t being strictly enforced on AirDrop, Dowd was able to read/write hidden system resources in combination with his own directory traversal attack. In doing so, he was able to upload his own application into the system and make it appear as trusted.

This bug has been reported to Apple, but a full patch has not yet been released for the recently-launched iOS 9. Therefore, if you’re the owner of one or more Apple devices, make sure that your AirDrop sharing options are set to private and that you’re only able to receive files from your contact list.

17 September 2015

Apple passcode increased to 6-digits in new iOS release

Apple rolled out its new iOS 9 operating system Wednesday and with that comes a big security upgrade.


The new operating system will now automatically default to a six digit PIN to unlock your device, instead of just a four digit PIN. While this might seem like a small change, it actually makes breaking into your iPhone a lot more difficult.

With a four digit PIN, there are a possible 10,000 combinations. But with a six digit code, there are 1 million possible combos, making it a lot tougher for someone to crack your security code.

If you are currently using a four digit PIN and update your software, you will need to manually opt in for the six digit PIN.

You can do this in your settings under "Passcode." But if you are just enabling the feature it will automatically prompt you to use six numbers for your PIN.


While the six number passcode is not mandatory, it is highly recommended. If you would rather take your chances, though, and go with a four digit code, you can make that selection in your settings as well.


The tech giant is also rolling out built-in two-factor authentication as part of iOS 9. Once you enroll for the security feature, you will be prompted to enter a verification code each time you log into a new device or browser. The code will appear on your other Apple device or your phone.

07 February 2015

Espionage app targets iOS devices

Trend Micro has discovered an interesting poisoned pawn - spyware specifically designed for espionage on iOS devices. While spyware targeting Apple users is highly notable by itself, this particular spyware is also involved in a targeted attack.


The iOS malware found is among those advanced malware and it is believed the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware Trend Micro found for Microsoft Windows’ systems. Two malicious iOS applications were found in Operation Pawn Storm. One is called XAgent and the other one uses the name of a legitimate iOS game, MadCap. XAgent is designed to work specifically with iOS7, which is still in one of every 5 iPhones and iPads. Fortunately, for iOS 8 devices, the user will see multiple notifications that the phone is trying to install an app. And it can’t run without the user launching. Both tools have the ability to record audio, which is very intrusive, and highly suggests the targeting of offline and confidential information.

Following analysis, Trend Micro concluded that both are applications related to SEDNIT – which is a spyware that aims to steal personal data, record audio, make screenshots, and send them to a remote command-and-control (C&C) server. Some of the data theft capabilities include:

  • Collect text messages
  • Get contact lists
  • Get pictures
  • Collect geo-location data
  • Start voice recording
  • Get a list of installed apps
  • Get a list of processes
  • Obtain Wi-Fi status

There may also be other methods of infection that are used to install this particular malware. One possible scenario is infecting an iPhone after connecting it to a compromised or infected Windows laptop via a USB cable.

For a more detailed analysis of the spyware, read here.

Background of Operation Pawn Storm
Operation Pawn Storm is an active economic and political cyber-espionage operation that targets a wide range of entities, like the military, governments, defense industries, and the media.

The actors of Pawn Storm tend to first move a lot of pawns in the hopes they come close to their actual, high profile targets. When they finally successfully infect a high profile target, they might decide to move their next pawn forward: advanced espionage malware.

The iOS malware we found is among those advanced malware. We believe the iOS malware gets installed on already compromised systems, and it is very similar to next stage SEDNIT malware we have found for Microsoft Windows’ systems.

05 October 2014

“The new iPhone 6 recharges with two minutes in the microwave”: A new urban myth about Apple

Remember when some Apple users ‘lost’ their phones after believing stories about the iOS7 making the iPhone waterproof?
After the presentation of the latest new features in Apple devices and the new iOS8 operating system, the Internet is full of articles either in praise of or criticizing the company’s latest efforts. Users, eager to find all the latest information and the best tips on how to get the most from the new iPhone 6, scour forums and blogs to stay up-to-speed with everything about these new releases.
That’s why it’s no surprise to find these types of practical jokes doing the rounds on the Web, or to encounter some poor unsuspecting user, who perhaps expecting more than is reasonable from the new device, falls for the trick.
This story took the form of an advert, similar in style to the one launched by Apple on 4chan, announcing the new ‘Wave’ feature of iPhone, which could supposedly recharge the phone in the microwave.
click to enlarge
So do you believe everything you read on the Internet?

20 September 2014

iPhone 6 Launches Millions of Scam Messages

The new iPhone 6 has gone on sale around the world, sparking long lines and campouts, and a whole lot of buzz. Unsurprisingly, internet scammers quickly took advantage of the frenzy to distribute their wares.


Immediately following the unveiling of the new iPhone 6 and iPhone 6 plus, scammers accordingly began circulating email and web scams attempting to capitalize on its popularity. The gambits however take many forms.

For instance, Hoax-Slayer uncovered a bogus Facebook competition offering the ability to “win a new iPhone 6 by carrying out three easy steps.” To get a chance to win, the site claims that users must first like the site's Facebook Page and then further promote the site by sharing a link with Facebook friends. They are then instructed to go to a second page on the site to download a ‘Participation Application.’ But, a pop-up window will direct users to a list of links that open third-party survey websites.

And here’s where the real malicious activity starts: many of these ask users to submit their mobile number, which, in turn, will subscribe them to a premium SMS service that charges several dollars every time the scammers send the victim a message.

Others collect names, addresses and phone details, which can be used for a variety of nuisance campaigns.

“Meanwhile, the scammer who created the fake promotion will earn a commission via a suspect affiliate marketing scheme each time you fill in a survey and provide your details,” Hoax-Slayer explained. “And, each time you return to the download page, the pop-up will inform you that the survey was not completed properly or there was a 'small error'. You will be urged to participate in yet another survey. But, no matter how many surveys you complete, you will still not get to download your 'application'.”

In one of the many other campaigns, spammers are using an iPhone 6 giveaway email to lure in potential victims; they are asked to follow instructions in the email to click on a link to, yet once again, a survey, but instead, an adware install will commence. Since Sept. 12, AppRiver researchers have seen nearly 1 million messages associated with this specific campaign.

“Adware is a form of software that is meant to generate revenue for its author by automatically displaying advertisements,” explained AppRiver researcher Troy Gill, in a blog. “Adware is not typically anything more than an annoyance but can often seriously infringe on users' privacy. This particular strain has a wide array of functionality and can make a victim’s web browsing experience fairly miserable.”

These types of scams, of course, also carry the possibility of malicious activity in the form of man-in-the-middle attacks, malware deployments and phishing.

“Though its presence is not secret, it is quite good at embedding itself into the victim’s system and can be quite difficult for the average user to remove,” Gill said. “Remember, advertisements promising you something for nothing are almost always too good to be true.”

17 September 2014

AppBuyer iOS Malware Steals Apple ID, Password & Buys Apps

Researchers from Palo Alto networks have discovered an iOS malware sample that affects iPhone devices that are jailbroken. The malware is named ‘AppBuyer’.

Photo: blvdone / Shutterstock

The AppBuyer malware is created and set up in a way that it will steal the user’s Apple ID login and password. Once these credentials have been stolen, the malware will purchase specific applications from the App Store and those behind the malware are utilizing the iOS environment to make some serious money.

The hackers first infect the device, and when it has been hacked, the device uploads Apple ID credentials. Once the hackers have access to the credentials, they are able to buy specific applications that may generate attractive revenue for the hackers.

The members of the WeiPhone Technical Group, who first mentioned AppBuyer in May, remotely assisted a user in finding out why some apps were periodically installed to his jailbroken device, and later found two strange files on the phone.

They discovered that the suspicious files would execute, download and delete other executable files from the web. They also tried to identify the hacker through analyzing the C&C server’s domain name with the samples. They also released samples for downloading.

WeiPhone Technical Group didn’t give a reason for how the samples were installing other apps into infected devices. On the other hand, the C&C servers are up and running, which may impact a greater number of users.

Palo Alto Networks analyzed the samples to disclose its working and provide suggests and solutions to defeat it. The researchers, however, still don’t know how the malware was installed on jailbroken Apple devices.

There are some possibilities that include via a malicious Cyber Substrate tweak that is hosted in third-party Cydia sources, through a PC jailbreaking utility, through other PC malware, or some other unknown way possibly.

After a device has been infected, the malware will first download executable files to generate a unique UDID. Then it will download a Cydia Substrate tweak for intercepting all HTTPS/HTTP sessions for stealing the Apple ID and password of the user and uploading to the attacker’s server.
Lastly, it will download a fake gzip utility that will login to the App Store through the user’s Apple ID credentials, and buy additional apps. Palo Alto Networks researchers, therefore, identify AppBuyer as a Trojan.

Defense
Palo Alto Networks researchers highly recommend iOS users to stay away from jailbreaking. They mention AdThief, another iOS malware discovered this year, infecting more than 75,000 devices. Another example is Unflod, a malicious Cydia Substrate tweak that steals the Apple ID credentials of the victim in a similar way.

For users who have already jailbroken their iOS devices should look for one or a combination of the following files in their device file system:

• /System/Library/LaunchDaemons/com.archive.plist
• /bin/updatesrv
• /tmp/updatesrv.log
• /etc/uuid
• /Library/MobileSubstrate/DynamicLibraries/aid.dylib
• /usr/bin/gzip

If there is any such file, the device may be infected by AppBuyer malware. However, just removing these files may not solve the issue as there is no word on how the malware actually got into the device. The Palo Alto Networks Platform says it can protect the malware in several ways.

They have already released signature URLs to prevent the download of the mentioned malicious files, and soon they will be releasing IPS and DNS signatures. The new iOS malware can be essentially deleted by blocking AppBuyer’s executable files from downloading. 

22 August 2014

'AdThief' Chinese Malware Infects Over 75,000 Jailbroken iOS devices

If you have jailbroken your iPhone, iPad, or iPod touch and have downloaded pirated tweaks from pirated repositories, then you may be infected by “AdThief” malware, a Chinese malware that is now installed on more than 75,000 iPhone devices.


According to a recent research paper published on Virus Bulletin by the Security Researcher Axelle Apvrille, the malware, also known as "spad," was first discovered by security researcher Claud Xiao in March this year.

Till now, AdThief aka Spad malware has hijacked an estimated 22 million advertisements and stealing revenue from developers on the iOS jailbreak community, Axelle Apvrille says.

The malware allegedly infects iOS jailbroken devices by disguising itself as Cydia Substrate extension, presents only on jailbroken Apple devices, when a malware infected Cydia package is downloaded and installed by the unsuspecting user.

Once installed, the malware modifies certain advertisements displayed on your iOS devices in an effort to redirect all the revenues to malware developer. In short, if you download or install a free ad-supported iOS app from the App Store, all of the cash generated by that app goes to the cyber criminal behind AdThief rather than the app’s developer.

Adthief has targeted advertisements from 15 popular mobile advertising networks, including Google’s AdMob and Mobile Ads, AdWhirl, MdotM, and MobClick, four of which were based in the US, two in India and the remainder in China.
The security researcher was able to identify the targets because the hacker mistakenly forgot to remove identifying information from the code. Further investigation allowed Apvrille to identify the coder who ran a blog providing details of various Android hacks, a Github and inactive Twitter account. Researcher located a Chinese vxer Rover 12421 who admitted writing the AdThief code but denied propagating it.
According to the researcher, the number of infected devices by the malware is small if compared to the figure of iOS devices in use, attackers likely generated significant revenue with an estimated 22 million advertisements hijacked.
The most important thing about this particular hack is that there is no way to find out if your device is infected by AdThief malware, because it runs in the background and is almost impossible to detect. Users of unmodified iOS devices need not to worry as they are safe from this malware infection.
Users of jailbroken Apple iOS devices are recommended to avoid downloads from untrusted repositories. Always be careful about adding new sources, and also be suspicious of those sources that promise pirated downloads of paid apps or tweaks.

26 March 2013

Apple adds two-step verification option to iCloud accounts

Apple has finally introduced a two-step verification feature that will allow its users to secure their iCloud (Apple ID) accounts, 9 to 5 Mac reports.

The option is currently available only to users based in the US, UK, Australia, Ireland, and New Zealand, and is definitely an improvement over the previous additional protection mechanism that included security questions.



Users can set up the feature in the "Password and Security" settings in their Apple accounts, and will be required to add (if they haven't already) the number of the phone(s) to which Apple will be sending the verification code.

They will also be given a recovery key to use in case they lose the device or forget their password, and are advised not to store it on the device or computer in case they are compromised.

Apple has also decided to prevent their support personnel falling for social engineering attacks such as those that led to the unfortunate compromise and trashing of Mat Honan's Twitter, Google and iCloud accounts by making it impossible for anyone but the account owner to reset their password, manage their trusted devices, or create a new recovery key once 2-step verification is turned on.

"You must be responsible for remembering your password, keeping your trusted devices physically secure, and keeping your Recovery Key in a safe place," the Apple FAQ page additionally warns. "If you lose access to two of these three items at the same time, you could be locked out of your Apple ID account permanently."

21 March 2013

Android, iOS bugs expose phones to voyeurs, data thieves

The first line of defense against smartphone snoops is a handset's lock screen, but the two largest smartphone makers are having trouble keeping them secure.

Bugs were discovered Wednesday in both Android and Apple smartphones.

A bug discovered by Android researcher Terence Eden allows anyone to bypass the security measures in place at a phone's lock screen and gain total access to the contents of a handset.

Eden outlined the method for bypassing the lock screen in his personal blog. The technique exploits the 911 feature of a phone, which allows emergency calls to be made whether a phone is locked or not.

The researcher noted that he found his attack to work only on a Samsung version of Android. It does not work on phones running a stock version of Android from Google.

He tested the attack on a Galaxy Note II from Samsung, but he predicted it would also work on a Samsung Galaxy III, as well as other Samsung devices, too.

Samsung did not respond to a request for comment for this story.

Eden explained that he reported the bug to the company in February, and that he expected a bug fix to be issued shortly.

Meanwhile, another lock screen bug was discovered in Apple's iPhone. The bug was discovered less than a day after Apple began pushing a version of its iOS operating system, version 6.1.3, to address a lock screen flaw discovered several seeks ago.

The bug was revealed by a reader of the Cult of the Mac website. It uses an iPhone's control feature to bypass the lock screen. However, the exploit appears to only work on iPhone 4's.

When a call is voice dialed, the publication explained, if the phone's SIM card is ejected during the dial-up, the phone will display its recent call log. From that screen, a peeper can browse and edit contacts and add pictures to the phone.

Both the Android and Apple bugs are similar, according to Diogo Monica, a security engineer with Square, a mobile payments company in San Francisco.

"They both exploit the emergency call system," he said in an interview. "When an emergency call is made, it allows a logic bug to be exploited and let you access the screen without authentication."

Once the lock screen is bypassed, not only can the information in it be eyeballed, but it can be copied, too. If your phone is unlocked, it can be connected to a computer and its contents dumped to the device, Monica explained.

He estimated that all the important data in a phone can be siphoned into a computer in a couple of minutes. A complete data dump of everything in a phone would take a maximum of 15 minutes.

Faulty lock screens would create serious concerns for corporations, maintained Glenn Chisholm, CSO and vice president of Cylance, a cyber security firm in Reston, Va.

"When you try to access your corporate mail, it usually forces you to enable your lock screen," he explained  in an interview. "If the corporation can't trust a lock screen to protect their corporate information ... that's a big problem."

Another big problem for corporations is lost or stolen smartphones, added Giri Sreenivas, vice president and general manager of mobile for Rapid7.

To mitigate those risks, companies require their employees to secure their phones with a PIN. "These vulnerabilities allow those controls to be bypassed," he said in an interview.


A video run through of the issue:

13 March 2013

Tips for removing data from mobile devices

AVG released tips on how consumers can remove their personal data before they recycle or throw away their old smartphones.



In an era of frequent and seamless device upgrades, it’s easy to ditch an old handset and move on to the next. However, chances are the old device has personal information lingering on it, putting consumers at a greater risk of identity theft.

“Think about all the personal data stored on your phone: text messages, emails, even intimate photos of you or your significant other,” said Tony Anscombe, senior security evangelist at AVG. “Consumers are now carrying more and more personal information on their devices, and AVG wants to ensure everyone is well equipped to wipe out that data when the time comes. Your identity is essentially yours to lose, so take every precaution possible to stay safe.”

While the factory reset button seems like the logical place to start, numerous industry and security experts report that even after consumers carry out this exercise, personal information often remains.

The following tips will help ensure private information is erased:
  • Remove the memory and SIM cards. Both store personal data and are best kept safe in your possession or destroyed.
  • Use a data removal application to ensure data really is deleted.
  • Once the data is deleted, then run a factory reset. Instructions can be found on manufacturers’ or carriers’ websites.
  • If you are going to simply throw away your mobile phone, older handsets can contain toxic materials. Consult your local authority or drop it off at a mobile phone retailer, where they will be able to dispose of it correctly. Additionally, there are specialist companies that will take it apart and recycle each component.
  • Of course, recycling or handing it on for use is a good option; there are many charities and organizations that redistribute old phones and will even send you a pre-paid postage box to send it in. Just search on the Internet for the many options!

14 September 2012

iPhone 5 release brings out email scammers

Apple's long awaited release of iPhone 5 has provided cyber crooks with a perfect opportunity to scam users.

Even before yesterday's official presentation of the new device, a mass mailing campaign offering a protective case for it has been spotted by Kaspersky Lab researchers:



Now - even if this offer was legitimate, it is highly unlikely that the case would fit, as the iPhone 5 is thinner and longer than its predecessor. The fact that the senders sent out the email before the release of the device indicates that this is likely a scam.

It's hard to tell just what type of scam it is, but at best you can get saddled with a case that doesn't fit, and at worst your credit card information can be stolen and used by the scammers.

In any case, beware of offers like these and restrict your online shopping to legitimate e-commerce sites.

10 November 2011

iOS flaw allows App Store apps download malicious code

Since the App Store's inception, Apple has been carefully examining applications submitted by third-party developers in order to assure its customers a malware-free experience. Approved apps get signed with Apple's cryptographic seal, and only than can they be downloaded and run by iPad and iPhone users.

But well-known Mac hacker and researcher Charlie Miller has discovered a flaw in Apple's restrictions on code signing on iOS devices which would allow attackers to use applications sneaked into the App Store to download and run additional, unsigned code.

To prove his point, Miller created an app called InstaStock that ostensibly lists stock tickers and submitted it to the App Store. The app was approved by Apple and offered to users. But unbeknownst to the company, the app also contained a hidden payload which takes advantage of the aforementioned flaw.

The app was now capable to "phone home" to a server set up by Miller, from which new code - unapproved by Apple - was downloaded and executed without a hitch. This gave him remote shell access to the device and allowed him to do things like making it vibrate, run a video, and most frighteningly, downloading any file present on it to the server.

Miller, who has managed to sneak the InstaStock app into the App Store back in September, has already notified Apple of the flaw on October 14th.

But, as news that he was planning to demonstrate the attack next week at the SysCan conference in Taiwan broke, Apple reacted immediately: not only has his app been removed from the App Store, but he himself has been booted out of the iOS Developer Program since he violated the agreement that forbids developers to “hide, misrepresent or obscure” any part of the submitted apps.

Miller is, understandably, annoyed by the move. “They went out of their way to let researchers in, and now they’re kicking me out for doing research,” he says. “I didn’t have to report this bug. Some bad guy could have found it instead and developed real malware.”

I guess that his upcoming demonstration can't be executed now - unless he has predicted Apple's reaction and uploaded (or asked someone to upload) a second booby-trapped app.

05 November 2011

Siri - Can She Spill Your Secrets?

By Default, Yes.
An IT/infosec expert Ben Schorr points out in an article, the feature of the iPhone 4S that everyone is excited about is Siri, the voice-enabled personal assistant. Siri can do some cool things - she can direct you to the nearest gas station, read you your e-mails and help you remember the coffee shop you liked in Seattle the last time you visited - ah, the wonders of GPS.

Unfortunately, Siri has no loyalty - if someone else gets possession of your phone, Siri will obligingly read them your texts or e-mails - or send text and e-mails that appear to come from you. This is true EVEN if you have your phone locked with a PIN.

This recently discovered security flaw can be corrected, but you must take the affirmative step of disabling Siri when the phone is locked - and how many users are going to do that? Unless you take that step, be wary of what you share with the faithless Siri!

10 June 2011

10 most common iPhone passcodes

The problem of poor passwords is not confined to computer use, and the fact was discovered by an app developer who has added code to capture user passcodes to one of its applications.

"Because Big Brother’s [the app in question] passcode setup screen and lock screen are nearly identical to those of the actual iPhone passcode lock, I figured that the collected information would closely correlate with actual iPhone passcodes," says Daniel Amitay.

It turns out that of the 204,508 recorded passcodes, 15% were one of the most common ten:


Comparing it to the list of most common internet passwords, one can see the similarities. "Most of the top passcodes follow typical formulas, such as four identical digits, moving in a line up/down the pad, repetition," he points out. "5683 is the passcode with the least obvious pattern, but it turns out that it is the number representation of LOVE (5683), once again mimicking a very common internet password: “iloveyou.”

Another pattern that pops out when looking at the list of top 100 most used passcodes is the conspicuous use of numbers that mimic particular decades in the last century - the 1990s and 1980s in particular. Amitay chalks that up to the assumption that most users are between the ages of 11 and 21, as it is very likely that the passcode represents the year of their birth or graduation.

Again, nothing new here - people often use their birth dates (or those of their near and dear) for PINs, passwords and codes, fearing that they would soon forget a random number and choosing one they never could forget.

The conclusion is, once again, that people are predictable and don't think much about security. But the fact that makes Amitay's revelation extremely crucial is that if someone steals or finds a lost iPhone, he has a 15% chance of unlocking the device and accessing the data within before it gets wiped just by trying out the passwords on the aforementioned top 10 list.

29 April 2011

Mobile Security: Camelot And The Wild West

The only secure device is one that is not connected to a network. However, this more or less defeats the purpose of mobile devices. Especially with the onset of social media and cloud computing, users are no longer just browsing the internet. As mobile devices become the primary platform for users, so will hackers' attention.

Just last month Google pushed the "Android Market Security Tool" onto at least 256,000 infected devices to remove apps with DroidDream malware, first reported by the Android Police. DroidDream was published within seemingly legitimate apps on the Android Marketplace which, once installed on Androids prior to 2.2.2, could obtain personal information as well as download additional code to run. The 58 apps infected with the malware were removed from the marketplace within minutes.

As with desktops, mobile malware can come in the form of anything from fake antivirus to "phishing" apps (apps posing as trusted banks or businesses), and they can be contracted through messages, app marketplaces, third-party marketplaces, and yes, even through the web browser. And this isn't just the case for Android. Even the iPhone has its own bout of security issues. Then, why is there so much hype regarding Android security?

The iPhone and Android exist in different worlds. The first is like Camelot, the second like the Wild West. On the iPhone platform, the operating system itself is tightly controlled and the App Store has strict regulations and screening. iOS users are looked after and protected by the "castle guards" at Apple. Exploits for iPhone are available only to very careless and those who install third party applications. The OS offers various encryption features and any known security holes in the OS are fixed and made available for users to easily upgrade upon syncing with their computer.

The Android platform is open source and there is little marketplace oversight. Users must lookout for themselves and the unguarded are vulnerable to exploit. There remains no built-in encryption available to apps, hence Skype's recent upgrade. That said, the lack of cooperation between carriers and Google to provide updates for the OS only compounds the issue, as this article discusses. Google has made security patches to its OS, but carriers have been unwilling to push the upgrades to its phones.

Both users and enterprises alike should realize the vast differences in the Android and iPhone environments. Be sure to confirm the authenticity of an app before installing, browse only trustworthy sites, and, as much as possible, keep devices upgraded.

23 April 2011

Newest IOS Update Jailbroken Already

Less than a week after Apple released the newest version of their mobile operating system iOS, the iPhone Dev Team has released its updated client for jailbreaking. Called redsn0w, this client allows iPhone users to install third party apps without the use of iTunes or the Apple approval process. For a lot of people, this is a very tempting offer even in the face of potentially voiding the warrantee. As of the writing of this article, only the iPad 2 remains impervious to redsn0w.

In their blog, the iPhone Dev Team announced the release of redsn0w 0.9.6rc14 on Tuesday, merely five days after Apple released iOS 4.3.2 for its devices. Having the update come so soon after the official release is thanks to the lack of a patch for the vulnerability which allowed the last version of iOS to be unlocked. Earlier this week, the iPhone 4 was only able to be jailbroken in a 'tethered' way. This meant that every time the device was rebooted, it would have to be connected to the user's Mac before it would work again. Obviously this is not the ideal situation for a mobile device, but that issue has since been rectified. Anyone who used this 'tethered' jailbreak can download the new client and simply patch their current install to the 'untethered' version.

I am not trying to justify jailbreaking. There are reasons why people do and there are reasons why Apple doesn't want them to, but in the end the decision lies with the user. The iPhone Dev Team strives to make the process as easy as possible for those willing to break out of Apple's so-called 'walled-garden' and install unverified apps. And they do make it look easy by exploiting vulnerabilities in the mobile OS created by a company who prides itself on its security.

10 March 2011

Safari And Internet Explorer, First To Fall In Pwn2Own

The Pwn2Own contest, reported earlier by SecurityProNews, has taken place this week and two web browsers have already fallen.According to a ComputerWorld report, Apple's Safari fell to a french security company, the hack only took five seconds to implement.

The team which hacked Safari was able to walk home with a $15,000 cash prize and the MacBook Air they performed the hack on. What makes the hack impressive is Apple released asecurity update for the browser which fixed 64 security flaws.

While the Safari hack was done quickly, many have been greatly impressed by the Internet Explorer exploit. Instead of a company, the IE8 hack was developed by a single person, Stephen Fewer. He's an independent researcher who caught the eye of Aaron Portnoy, one of the TippingPoint's team, the group who put the Pwn2Own contest together.

Fewer had to use a few vulnerabilities to successfully hack IE8 on Windows 7. Here's what Portnoy said of the hack, "The most impressive so far" he continues, "He used three vulnerabilities to [not only] bypass ASLR and DEP, but also escape Protected Mode. That's something we've not seen at Pwn2Own before."

While Safari and IE8 have been hacked, Chrome has remained safe. No one has attempted to hack the browser, so their $20,000 prize is safe. The purse was only available to those who hacked the browser on the first day of the content. If anyone is able to successfully hack the browser now or later on, they will receive $10,000 from Google and $10,000 more from TippingPoint.

Pwn2Own has two more days before all is said and done, which will see hackers make their attempts at Mozilla Firefox, and the four smartphone operating systems: Apple iOS, Google Android, Microsoft Windows 7, and RIM' Blackberry.