Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

7/11/13

Android flaw leaves 99% of devices open to attacks, details to be revealed at BlackHat

Mobile security company Bluebox claims to have discovered a flaw in Android that could leave any device released in the last four years vulnerable to attacks. The method demonstrated allowed modifying an app’s code without affecting its cryptographic signature, inserting malicious code completely unnoticed, leading to anything from data theft to creating botnets. The implications are huge, the researchers say.
Although specifics were left under wraps, the core issue involves discrepancies in how Android applications are verified and installed. As Bluebox explains, all Android apps contain cryptographic signatures to verify their authenticity. But through the use of some sort of “master key”, malicious coders are able trick Android into believing an app is unchanged even if its APK code has been modified.
The vulnerability has reportedly been around since the release of Android 1.6 in 2009 and Google was notified about it in February. But due to the way Android updates work, it’s up to manufacturers to produce and release firmware updates for their specific hardware, and so far only the Galaxy S 4 has been patched.
As proof of the vulnerability’s existence, Bluebox  CTO Jeff Forristal accompanied his blog post with a screenshot from an HTC device that had system-level software information modified to display “Bluebox” in the Baseband Version string (a value normally controlled & configured by the system firmware).
Technical details and related tools will be released at his BlackHat USA 2013 talk by the end of the month.
It’s worth noting that for all the doom and gloom that Bluebox is spelling -- it appears to be a serious issue after all -- falling prey to hackers would require you to download an actual app that has been modified with malicious code. In other words, it requires user action, and most likely downloading from a non-official source.

U.S. Commerce Department unnecessarily destroyed $170K worth of IT gear to hunt down malware

We’ve probably all reached a level of frustration when dealing with a malfunctioning or malware-infested PC or gadget where we simply want to smash it to bits. The U.S. Department of Commerce is no exception it seems as they took matters into their own hands to deal with a pesky malware issue last year.
In 2012, the department shelled out more than $2.7 million (more than half of their annual IT budget) trying to track down what appeared to be a major malware infestation. Acting on the guidance of the CIO of the Economic Development Administration (EDA), the department subsequently destroyed more than $170,000 worth of IT components including desktops, printers, TVs, cameras, computer mice and keyboards.
The department exhausted funds for the effort in August 2012 and thus had to halt the destruction of its remaining IT gear, valued at over $3 million. The plan was to continue the destructive behavior once more funds were available but as it turns out, it was all completely unnecessary.
Come to find out, malware was only present on two pieces of equipment. Furthermore, some department members were fully aware of this but due to a series of misunderstandings, that information was never fully conveyed to the appropriate officials in charge.
An audit on the situation concluded the department needs to better prepare itself to respond to future security breaches. After all, what good is it going to do to toss out computer mice and keyboard in the hunt for malware?