Google Search

Showing posts with label Pictures. Show all posts
Showing posts with label Pictures. Show all posts

Tuesday, October 8, 2013

Android malware in pictures - a blow-by-blow account of mobile scareware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Thanks to Nagy Ferenc László of SophosLabs for the
behind-the-scenes work that he put into this article.

Fake anti-virus, also suggestively known as scareware, tricks you into paying money by pretending to find threats such as viruses and Trojans on your computer.

The scan to find the "threats" is free; the cleanup part is not.

If you do pay up, the software then pretends to remove the non-existent threats so you may not even realise that you've been scammed, on the principle that all's well that ends well.

But not only are you out of pocket, typically between $40 and $100, you're also led into a false sense of security, because the clean bill of health provided after you've paid is as bogus as the infection report at the start.

This sort of scam is most common on Windows, with OS X a long way back in second place. But other operating systems aren't exempt from the depredations of cybercriminals.

SophosLabs recently acquired an Android scareware sample going by the entirely hokum name of Android Defender. It's not particularly polished, and it crashed quite a bit as we played with it, but it does show that the scammers have an active interest in the Android ecosystem.

I thought I'd give you a guided tour of what it looks like. That way, you'll have some pointers that I hope will help you determine real from fake security software in future.

I started by creating a fresh Android 4.2.2 emulator image and firing it up.

Then I installed the malicious APK (Android Package file). In real life, you might be encouraged to download it from a handy website; I just used the Android Debug Bridge (adb) to inject it from my research computer into the emulated image.

You can see the application icon at top left, since its name conveniently starts with 'A'.

I launched it to see what would happen. It advised me that my device "is at risk of being infected," which is an understatement: my device is already infected, because Android Defender is on it.

I'm invited to buy, but there's no serious pressure yet.

The inital scan quickly suggests I have a problem.

Two viruses, one Trojan and a Malware, to be precise.

You might be inclined to believe this report, since the "threats" found are Android malware names you might have heard of.

But it's all smoke and mirrors. You don't have to be a Java coder, or even a programmer at all, to spot in the source code below that the app is using the Math.random() function to build up a list of virus names to report later.

The malware names are field-updatable, stored in Russian and in English in an XML data file that is part of the malware's APK file.

This is about as close to "malware identities" (also known as signatures, patterns or definitions) as you will find in the app.

There isn't anything to help the product actually locate viruses in infected files. There's just a list of names: when you're choosing randomly even on uninfected devices, recognition patterns just aren't needed.

Most of the viruses on the list are existing Android malware names, in order to add a ring of verisimilitude. But somehow the Windows-only virus Conficker managed to get in there.

The pressure on me to register the product is increasing, because it's now time to think about cleaning up the malware.

So I gave it my best shot, and tried to "activate" the software.

The buy page wasn't working, so I can't tell you how much the scammers intended to charge.

But it didn't matter, because I had an activation code up my sleeve from the source code itself.

We saw this happy-go-lucky attitude to activation in early Mac scareware.

Was the activation system this simplistic for experimental convenience, or is it just a prototyper's indolence? We shall probably never know.

The product crashed after I clicked the Activate button, but when I started it up again, I found that the activation had worked and my device was "fully protected."

The next system scan is no longer a scary red but a go-ahead green.

Better still, the app is pretending to have "eliminated" the malware it "detected" earlier.

In fact, the software builds a small sqlite database in which it remembers what viruses it has "found", and whether it has fraudulently "cleaned" them, so it will be consistent in its dishonesty.

There's a half-hearted privacy manager tool built in to the app, presumably because that's the sort of feature that other Android security products provide.

And there's an update page, though the crooks forgot to translate that part properly.

The update pretends to work, even listing signature files it supposedly downloaded from the internet.

(In my case, it couldn't have downloaded anything from outside - I tested in with my device in Airplane Mode, which inhibits all outbound connections. That cuts you off in the emulator, just as it would on a real device.)

Updates are only simulated once a day, in order to appear more realistic.

The app pretends that its pattern database has increased in size every time you update. Once again, the Java pseudorandom number generator is used behind the scenes.

I don't imagine you installed this progam, but if you did, you need to remove it right away.

And you couldn't have installed it without first telling your device that you wanted the freedom to go looking for software outside Google's own official Play Store.

I'd suggest, if you did so (since it ended badly enough for you to get this malware!) that you turn "Unknown sources" off once again.

And you might want to consider installing a proper Android security tool in which the detection and the cleanup are free.

Sophos Security and Antivirus is available from the Play Store, so you don't need to enable "Unknown sources" to install it.

And yes, it does actually look for threats before it reports them.

If it finds a threat, there aren't any demands. Just a warning and an instant "Uninstall" button.

In the words of many a Naked Security video and podcast, thanks for listening, and until next time, stay secure!

Follow @duckblog


View the original article here

Saturday, November 17, 2012

LulzSec hacker pleads guilty to Sony Pictures attack, faces prison sentence

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Man with clapperboard. Image from ShutterstockRaynaldo Rivera, from Tempe, Arizona, has admitted hacking into computer systems belonging to Sony Pictures, and stealing the personal information and passwords of thousands of innocent internet users

The attack, which took place in May last year, was part of a concerted attack against Sony websites by LulzSec and Anonymous hackers during 2011.

Rivera, who was arrested by the FBI in August, admitted his guilt in the form of a plea agreement filed with Los Angeles Federal Court.

Rivera - who used online nicknames including "neuron", "royal", and "wildicv" - admitted launching an SQL injection attack against the Sony Pictures website, extracting confidential and personal user information - such as the names, birth dates, addresses, emails, phone numbers and passwords of people who had entered Sony contests.

The stolen information was subsequently published online by the LulzSec hacking gang, compounding the risk to innocent users.

The hack is said to have cost Sony more than $605,000 in losses.

HideMyAss logoIn an attempt to hide his true identity during the attack, Rivera used the HideMyAss anonymising proxy service to disguise his IP address as he probed the Sony Pictures' website for vulnerabilities.

However, Rivera had not been careful enough in disguising his tracks - and HideMyAss co-operated with the authorities when a court order was received by the anonymising proxy service.

Others considering committing crimes on the net might be wise to stop believing that using an anonymising proxy service will necessarily keep them out of the clutches of the law.

Under the plea agremement, Rivera will pay restitution to his victims. He also faces a maximum five year prison sentence, and a fine of at least $250,000.

Follow @gcluley

Man with clapperboard image from Shutterstock.


View the original article here

Saturday, June 25, 2011

Hackers claim 177K e-mails from Sony Pictures France

Sony's turn as the whipping boy for Internet hackers continued over the weekend. Two hackers posted a list of e-mails they say they took from the Sony Pictures France Web site.

The two hackers who claim responsibility are a Lebanese student who goes by the handle Idahc, and a French friend of his who goes by Auth3ntiq. The two say they copied 177,172 e-mails from the entertainment company's site, but posted only 70 of them on the code-sharing site Pastebin. They say they will not be posting all of the e-mails they found.

Jim Kennedy, Sony Pictures executive vice president of communications, said in a statement, "We are currently investigating this claim."

The brief Pastebin posting says the pair managed to lift the e-mail addresses through an SQL injection.

It's the same method that was used to extract personal data of customers from SonyPictures.com, Sony Pictures Russia, Sony Ericsson, and Sony Music Entertainment Japan in recent weeks.

Idahc isn't a stranger to attacking Sony's sites. He was the one who claimed to have taken data from a Sony Ericsson eShop Web site last month, leaked a database from Sony Europe, and compromised a Sony Portugal site.

Idahc said in an interview with Forbes last week he began hacking for "justice," but now says he's trying to prompt companies like Sony to improve their security.

Attrition.org has been keeping track of the spate of attacks on Sony. It says this is the 20th breach of a Web site or network related to the company in two months, starting with the PlayStation Network breach in April that put the gaming service out of commission for more than three weeks.

This story was updated at 2:28 p.m. PT with comment from Sony.


View the original article here

Friday, June 24, 2011

Hackers hit Sony Pictures France site, grab 177K e-mails - ZDNet (blog)

Sony Pictures France is the latest Sony Web site to suffer at the hands of hackers. This time two hackers have claimed credit and say they copied more than 177,000 e-mails from the site.

The two hackers are identified as a Lebanese student called “Idahc” and “Auth3ntiq,” a friend of his from France. They claim to have exploited a SQL flaw to get the information.

Idahc and Auth3ntic posted information about their feat, along with a sample of the e-mails they took, to the Web site Pastebin.com.

The hackers aren’t doing anything new. The same sort of exploit was used to break into SonyPictures.com, Sony Pictures Russion and other Sony-owned sites in recent weeks. In fact, Idahc seems to be on a crusade to teach Sony a lesson about bad security.

In a recent interview on Forbes.com, Idahc said that he’s attacking global Sony sites to demonstrate Sony’s lax attention to security. “I don’t hack for ‘lulz’ but for moral reasons,” he said.

It’s the latest in more than a dozen and a half attacks on Sony Web sites since Sony pulled its PlayStation Network offline in April, when the company discovered that as-yet unidentified hackers broke in and stole information about tens of millions of customers. Within days Sony discovered that its Sony Online Entertainment servers, which manage access to online PC games, had been similarly compromised. All told, more than 100 million customers had their names, addresses and other personal information taken.

In the wake of that failure, Sony executives pledged to improve security and to hire a new executive to head up security operations for the company. But hacker aren’t slowing down their attacks on the company. What’s causing the frequent attacks?

Sony is, of course, a high-profile target, as they’ve already suffered substantial damages by having to shut down network operations on the PlayStation Network for almost a month.

But there’s more to it. Hackers’ hackles were raised earlier this year when Sony sought to sue George “Geohot” Hotz, a programmer who tried to restore the PlayStation 3’s “OtherOS” capability, which enables it to operate Linux. That’s a feature Sony originally supported on the PlayStation 3 but later removed in a firmware update. After that, the hacker collective that calls itself “Anonymous” declared open war on Sony, only backing off after gamers themselves made their displeasure known.

Hackers’ displeasure with Sony runs much deeper than that, however. Years after the fact, some harbor resentment about Sony BMG’s decision to put rootkit-based DRM software on some of its music CDs back in 2005.

Now hackers are going after Sony with a vengeance. Like sharks detecting blood in the water, they’re unlikely to let up any time soon, especially since Sony’s chronically lax security makes them an easy target.

A long-time veteran of the Apple news business, Peter has also spent more than fifteen years covering games and the game industry. A self-proclaimed Alpha Nerd, Peter also professes a love for anime, sci-fi cons, gadgets of all kinds and various geek subcultures.


View the original article here

Wednesday, June 22, 2011

Hackers hit Sony Pictures France

PARIS, June 21 (UPI) -- Two hackers said they copied 177,172 e-mails from the Sony Pictures France Web site and posted 70 of them on the code-sharing site Pastebin.

The hackers claiming responsibility for the incident identify themselves as a Lebanese student who goes by the handle Idahc and his French friend Auth3ntiq, the technology news site CNET reported.

The hackers said they managed to lift the e-mail addresses through an SQL (structured query language) injection, a technique that exploits a security vulnerability occurring in the database layer of an application.

It's the same method that was used to extract personal data of customers from SonyPictures.com, Sony Pictures Russia, Sony Ericsson and Sony Music Entertainment Japan in recent weeks.

Jim Kennedy, executive vice president of communications for Sony Pictures, said the company is investigating the hackers' claim.


View the original article here