Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Tuesday, May 2, 2017

Insecure Apps that Open Ports Leave Millions of Smartphones at Risk of Hacking



The University of Michigan team says that the actual issue lies within apps that create open ports — a known problem with computers — on smartphones.

So, this issue has nothing to do with your device's operating system or the handset; instead, the origin of this so-called backdoor is due to insecure coding practices by various app developers.


The team used its custom tool to scan over 100,000 Android applications and found 410 potentially vulnerable applications — many of which have been downloaded between 10 and 50 Million times and at least one app comes pre-installed on Android smartphones.

Here I need you to stop and first let's understand exactly what ports do and what are the related threats.

Ports can be either physical or electronic in nature. Physical ports are connection points on your smartphones and computers, such as a USB port used to transfer data between devices.

Electronic ports are those invisible doors that an application or a service use to communicate with other devices or services. For example, File Transfer Protocol (FTP) service by default opens port 21 to transfer files, and you need port 80 opened in order to connect to the Internet.

In other words, every application installed on a device opens an unused port (1-to-65535), can be referred as a virtual door, to communicate for the exchange of data between devices, be it a smartphone, server, personal computer, or an Internet-connected smart appliance.

Over the years, more and more applications in the market function over the Internet or network, but at the same time, these applications and ports opened by them can be a weak link in your system, which could allow a hacker to breach or take control of your device without your knowledge.

This is exactly what the University of Michigan team has detailed in its research paper [PDF] titled, "Open Doors for Bob and Mallory: Open Port Usage in Android Apps and Security Implications."

According to the researchers, the major issue is with the apps like WiFi File Transfer, which has been installed between 10 million and 50 million times and allows users to connect to a port on their smartphone via Wi-Fi, making it easy to transfer files from a phone to a computer.

But due to insufficient security, this ability of the apps is apparently not limited to merely the smartphone's owner, but also malicious actors.

However, applications like WiFi File Transfer pose fewer threats, as they are designed to work over a local network only, that requires attackers to be connected to the same network as yours.

On the other hand, this issue is extremely dangerous in the scenarios where you connect to a public Wi-Fi network or corporate network more often.

To get an initial estimate on the impact of these vulnerabilities, the team performed a port scanning in its campus network, and within 2 minutes it found a number of mobile devices potentially using these vulnerable apps.
"They manually confirmed the vulnerabilities for 57 applications, including popular mobile apps with 10 to 50 million downloads from official app marketplaces, and also an app that is pre-installed on a series of devices from one manufacturer," the researchers say.

"The vulnerabilities in these apps are generally inherited from the various usage of the open port, which exposes the unprotected sensitive functionalities of the apps to anyone from anywhere that can reach the open port."
No doubt, an open port is an attack surface, but it should be noted that port opened by an application can not be exploited until a vulnerability exists in the application, like improper authentication, remote code execution or buffer overflow flaws.

Besides this, an attacker must have the IP address of the vulnerable device, exposed over the Internet. But getting a list of vulnerable devices is not a big deal today, where anyone can buy a cheap cloud service to scan the whole Internet within few hours.

However, smartphones connected to the Internet via wireless network behind a router are less impacted by this issue, because in that case, attackers would need to be on the same wireless network as the victim.

To prove its point, the team of researchers has also demonstrated various attacks in a series of videos, posted below:

1. Using an app's open ports to steal photos with on-device malware

2. Stealing photos via a network attack

3. Forcing the device to send an SMS to a premium service

The team says these vulnerabilities can be exploited to cause highly-severe damage to users like remotely stealing contacts, photos, and even security credentials, and also performing sensitive actions such as malware installation and malicious code execution.

The easiest solution to this issue is to uninstall such apps that open insecure ports, or putting these applications behind a proper firewall could also solve most of the issues.

Tuesday, November 1, 2016

Delete unused Android apps now, or risk a security nightmare






By Jack Wallen | October 31, 2016, 12:27 PM PST


Your Android device most likely contains unused apps that could still use data or fall prey to vulnerabilities. The solution to this potential security problem: delete those apps.

Quick! Open your Android device, go to the App Drawer, and count the number of apps you no longer use that are still installed. Now go back through that list of apps you no longer use and find out which ones are no longer maintained or which suffer from long-standing malware vulnerabilities.

Done? Didn't think so.


You may have forgotten that you installed a particular app from a third-party source—and yet, there it sits in your app drawer, waiting for you to use it. Was it sitting in the background, all this time, collecting data and sending it to a nefarious destination? According to Cheetah Mobile, malware accounts for up to 1% of all applications installed every day. That means there's a 1% chance that your device has been compromised by malware.

One percent isn't much, but it's not zero.

All of a sudden, keeping track of your Android apps from a security perspective is no longer such an easy task. But this challenge does come with a purpose to illustrate a single point: Uninstall unused apps on your device. It's simple and elegant, yet the advice so often falls on deaf ears.

It's so easy to forget them

According to Google 25% of installed apps are either never used or used immediately and then forgotten. Also, the average Android app loses 77% of daily active users within the first three days of an app being installed and 90% within the first 30 days. After that magic 30 days, chances are you will have forgotten you ever installed the app.

And the thing is, we are creatures of habit...even with our mobile devices. We use the apps we use and beyond that...everything else is easily forgotten.


This is especially true of apps like home screen launchers. Most often this type of app is installed without an associated icon in the App Drawer; because of this, it's very easy to forget you ever installed the app—out of sight, out of mind. In fact, the only time you
Related Posts Plugin for WordPress, Blogger...