PRESENTED BY PALAPPLE

ADVERTISE WITH US

Posted by iPhoto.org - Feb 26, 2009

Advertise here in this prominent space for only $100 per month, your advertisement will appear in all of the post pages available across this website.
Check out the link about for more advertisement options provided, get your message across!

Advertise with Us

SNAPSHOCK IS COMING TO TOWN

Posted by iPhoto.org On Feb 26, 2009

You better watch out,
You better bookmark,
You better ready your pics, cos I'm tell you why...

Snapshock is coming to town!!

Snapshock

THE BEST PLACE FOR DRY SEAFOOD

Posted by StarryGift On Mar 20, 2009

全香港其中一間最具規模的海味網上專門店。專營零售燕窩、鮑魚、海參、魚翅、花膠、元貝、冬蟲草,極具食療價值。此外亦提供各項中藥海味烹調方法,以導出各食品的固本培元及補生之效。

客戶服務熱線:3158 1276
傳真熱線:3158 1416
電郵查詢:info@starrygift.com

海味軒 | 香港燕窩海味網上專門店


Tuesday, June 14, 2011

Android Malware Found in Angry Birds Add-On Apps

Researchers spotted a number of malicious applications on the Android Market. (Photo: Jim Merithew/Wired.com)


Google recently removed at least 10 applications from the Android Market, all of which contained malicious code disguised as add-ons to one of the most popular apps of all time.


Each of the removed apps posed as a cheat or an add-on to Angry Birds, the much-lauded mobile application created by Finnish game development studio Rovio.


A number of the apps in question contained a spyware program called Plankton, which connects to a remote server and uploads phone information like the IMEI number, browser bookmarks and browsing history.


“Market descriptions for these apps included the statement ‘brought to you free sponsored by Choopcheec Platform,’” Lookout Security spokesperson Alicia diVittorio told Wired.com. “[They include] a link to an EULA that does seem to accurately describe the behavior observed to date. We do not see these as desirable behaviors and classify it as Spyware.”


Xuxian Jiang, an assistant professor of computer science at North Carolina State University, initially discovered the malicious applications last week, and reported them to Google on June 5. Google suspended the questionable applications the same day, “pending further investigation.”


Jiang found malicious programs other than Plankton in his research. YZHCSMS, for example, is a Trojan horse virus that jacks up your phone bill by sending large amounts of SMS messages to premium numbers. Jiang says apps containing the virus were available on the Android Market for at least three months before Google pulled them.


Jiang found a similar application, DroidKungFu, circulating Chinese application markets before YZHCSMS made its way to the Android Market. “DroidKungFu can collect various information about the infected phone, including the IMEI number, phone model and Android OS version,” according to a Lookout Security blog post.


For many app developers, the Android Market offers a freedom not found in other application retail outlets. Unlike Apple’s strict application review process, apps submitted to the Android Market are published almost instantaneously. Many appreciate the freedom given to push programs out to the public at such a speed.


However, the Android Market’s app submission process comes at a cost. Google’s lack of vetting applications lends the Market to security vulnerabilities like these. Google mostly relies on a self-policing community — including researchers like Jiang — to spot offending apps, which means malware can sit in the market for months before someone spots it.


With a relatively open submission process like Android’s, this obviously isn’t Google’s first run-in with malicious app removals. Google pulled nearly two dozen malware-infected applications in early March, but not before close to 200,000 downloads occurred.


Going outside of the official Android Market for apps can be even riskier. Because users are able to download applications from alternative app markets — a feature unavailable to iPhone users — many have popped up over the past two years. Without Google’s moderation capabilities in these outside markets, users are more susceptible to downloading malicious apps. A Trojan with “botnet-like capabilities” popped up in early April, for example, highlighting the risk in going to alternative markets for applications.








Full story at http://feeds.wired.com/~r/GearFactor/~3/j10vJLc2YoI/

No comments:

Post a Comment



iPhoto.org facebook group
Advertise with Us