The OpenSSL Heartbleed vulnerability “allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read” [1]. Heartbleed surprised the public by allowing attackers to steal sensitive information from vulnerable websites by sending crafted SSL heartbeat messages. However, due to the fact that servers can send heartbeats to clients as well, malicious servers can, in turn, attack vulnerable clients and steal sensitive information. For the Android platform, we find that roughly 150M downloads of Android apps contain OpenSSL libraries vulnerable to Heartbleed.
Showing posts with label Android. Show all posts
Showing posts with label Android. Show all posts
Wednesday, April 23, 2014
Tuesday, April 15, 2014
[fireeye] Occupy Your Icons Silently on Android
FireEye mobile security researchers have discovered a new Android security issue: a malicious app with normal protection level permissions can probe icons on Android home screen and modify them to point to phishing websites or the malicious app itself without notifying the user. Google has acknowledged this issue and released the patch to its OEM partners.
Monday, March 31, 2014
[dwaterson] Android Wear OS security issues
Last week, Google announced the launch of Android Wear – a new operating system for wearable computing. Wearable devices currently are in the form of glasses, braces and watches. With the advent of Android Wear, many more devices will come to market – smartwatches, fitness monitors, health devices, spectacles, and other wearable computers including those built into clothing. It is now a much simpler task for example, for a watch manufacturer with no experience in software, to produce a smartwatch running Android Wear and apps written by independent developers.
Friday, March 14, 2014
[securityintelligence] DIY: Android Malware Analysis – Taking Apart OBAD (Part 2)
Let’s give OBAD a run
Last time we discussed about various tools for analysis, setting up the app to be debugged in jdb, identifying anti-emulator code, hacking and compiling AOSP code and then running the emulator with our modified system image to bypass antivm check. So now that you can bypass the anti vm checks, if you run OBAD in the emulator you would see it asking for enabling it as a DeviceAdmin
[securityintelligence] DIY: Android Malware Analysis – Taking Apart OBAD (Part 1)
I plan on writing regular posts in the DIY series with the goal of not only understanding malware, vulnerabilities and exploits but also to share with our readers some techniques and tools they can use themselves to “know the enemy”. I am also looking forward to hearing about your experiences in analyzing similar threats with similar or more efficient tools & techniques.
Saturday, February 15, 2014
[thehackernews] 300000 Android Devices infected by Premium SMS-Sending Malware
Downloading various apps blindly from Google play store may bring you at risk in terms of money.
PandaLabs, the Cloud Security Company, has identified malicious Android apps on Google Play that can sign up users for premium SMS subscription services without their permission and so far it has infected at least 300,000 Android users, although the number of malicious downloads could have reached 4 times higher i.e. 1,200,000 users.
Monday, February 10, 2014
[infosecurity-magazine] New Snapchat Flaw Can DoS and Spam iOS and Android
10 February 2014
A security researcher has discovered a new flaw in Snapchat that allows users to deliver a denial of service attack against individual iOS or Android users, or alternatively more easily deliver spam to a large number of users. It is the latest in a series of problems experienced by Snapchat over the last few months.
Subscribe to:
Posts (Atom)