DroidForums.net is the original Verizon Android Forum! Registered Users do not see these ads. Please Register - It's Free!
Results 1 to 9 of 9

Thread: Potential Design Flaw in Android Could Allow Malware to Mimic Legitimate Apps

  1. Editor in Chief
    dgstorm's Avatar
    Member #
    154790
    Join Date
    Dec 2010
    Posts
    4,537
    Liked
    1189 times
    Phone
    Enter Current Phone Model Here
    Premium Member
    #1

    Potential Design Flaw in Android Could Allow Malware to Mimic Legitimate Apps


    Some researchers recently demonstrated what may be a design flaw in Android that would allow malware to mimic legitimate apps. Sean Schulte, SSL developer at Trustwave, and Nicholas Percoco, the senior vice president and head of SpiderLabs at Trustwave, revealed at a DefCon Hacking Convention, what they believe is a design flaw in Android. They indicated that the design flaw could be used by advertisers to bring annoying pop-up ads to phones, or even by criminals to steal data via phishing.

    Basically the exploitable flaw centers around the fact that Android allows a developer to override the standard for hitting the back buttons. Because of this, an app can be created that is able to steal the focus and keep you from being able to hit the back button to exit out. This is similar to some malware attacks on Windows based computers. They are calling it the "Focus Stealing Vulnerability", and they were able to demonstrate an app they created that did exactly what they described. Here's a quote from the CNET article with more details,
    The researchers have created a proof-of-concept tool that is a game but also triggers fake displays for Facebook, Amazon, Google Voice, and the Google e-mail client. The tool installs itself as part of a payload inside a legitimate app and registers as a service so it comes back up after the phone reboots, Percoco said.

    In a demo showing a user opening up the app and seeing the log-in screen for Facebook, the only indication that something odd has happened is a screen blip so quick many users wouldn't notice. The fake screen completely replaces the legitimate one, so a user wouldn't be able to tell that anything is out of place.

    With this design flaw, game or app developers can create targeted pop-up ads, Percoco said. The ads could be merely annoying, like most pop-ups are, but they could also be targeted to pop up an ad when a competitor's app is being used, he added.
    The worst part about this potential vulnerability is that it could do more than just create a replacement pop-up ad; it could also detect when you are using a banking or email app, and create a legitimate looking overlay "phishing" for your credentials. Afterwards, the user would never even realize what happened. Supposedly,
    The malware could even install itself as a service and run seamlessly in the background even after the phone is rebooted.
    Google is looking into the issue, and for now, no malware infections for this exploit have been reported. In the meantime, the best thing you can do is to always be cautious about where you get your apps, and don't download anything that looks even remotely suspicious.

    Source: Android.net via PhoneArena and CNET
  2. Sponsor
    DF Advertising
    Join Date
    Nov 2008
    Location
    DroidForums.net
     
     
     
     
  3. Senior Droid
    Immolate's Avatar
    Member #
    89852
    Join Date
    Jul 2010
    Location
    Central Florida
    Posts
    240
    Liked
    8 times
    Phone
    Samsung Galaxy Note (AT&T)
    #2
    and for now, no malware infections for this exploit have been reported.
    Glad everyone waited until the hole is plugged before disseminating the information globally. Whew. Another bullet dodged.
  4. Master Droid
    DroidXDoes4G's Avatar
    Member #
    199139
    Join Date
    May 2011
    Posts
    952
    Liked
    9 times
    Phone
    DROOOOID 3
    #3
    Google can fix it. There google.

    Sent from my DROID3 using DroidForums
    HTC Incredible>Droid2>DroidX>HTC Thunderbolt>Back to Droid X>Droid 3>Prime?

    Sent from either my Droid 3 using DroidForums or my laptop using Chrome.


  5. Droid
    chasehammer's Avatar
    Member #
    181365
    Join Date
    Mar 2011
    Location
    Franklin, TN
    Posts
    97
    Liked
    1 times
    Phone
    Droid 2 R2D2
    #4
    first thing that came to mind.

    "Hey guys i found this design flaw that can infect a whole lot of people if it gets out. Lets tell everyone."
    R2D2 SBF - VRZ_A957_2.4.5_1FF_01.sbf
    Works if you cant update to new update, flash this then update
    THANKS TO GREYGIFFORD
  6. Master Droid
    NoBloatware's Avatar
    Member #
    206799
    Join Date
    Jun 2011
    Posts
    747
    Liked
    46 times
    Phone
    Droid 3
    #5
    So an app can show an ad when you press the back button? That's considered malware?

    As far as the app showing a fake login page, any app can do that now at any time. The problem is that when you press the back button you might actually think "oh, my bank account logged out. I better log in". This is a problem. If the stars align properly, a user could enter their password info.

    How can this be fixed? Disabling the ability to override the back button seems severe. But what else can be done? If an app has the ability to display itself in full screen, it can then mimic anything. A similar problem used to plague web browsers. The malware would mimic the URL bar and it would look like you were actually at your bank's web site when you weren't. While browsers could solve this by always showing the URL bar, there is no equivalent paradigm in Android. I could be looking at a screen that says "Bank Login" and there is no way for me to know which app is displaying that page. It will be interesting to see how/if Google fixes this.

    For now, when you press the back button you need to be sure of what you're looking at. Don't enter sensitive info without returning to the home screen and going to the app directly.
    Do you like uninstallable bloatware?
    It takes about 5 minutes to complain and it's kinda fun. Let's not be complacent!
    Contact Verizon (anonymous w/ fake name if you like)
    Chat/Email/Call Motorola (anonymous if you like)
    Vote for Google issue requires Google login. Just "star" it to vote.
  7. Droid Sensei
    OneTenderRebel's Avatar
    Member #
    53261
    Join Date
    Mar 2010
    Location
    Hampton Falls, NH
    Posts
    3,333
    Liked
    353 times
    Twitter
    JefFullerMyself
    Phone
    Galaxy Nexus
    #6
    I can tell you which phone OS this wouldn't happen to.............


    But I am not trying to incite riots, haha
    Anytime someone dares me to walk a mile in their shoes I do it! Because, hey free shoes and I am now a mile away from that person!

    Hatred is by far the ugliest trait any human can possess (think about it)
  8. Droid
    chasehammer's Avatar
    Member #
    181365
    Join Date
    Mar 2011
    Location
    Franklin, TN
    Posts
    97
    Liked
    1 times
    Phone
    Droid 2 R2D2
    #7
    Quote Originally Posted by OneTenderRebel View Post
    I can tell you which phone OS this wouldn't happen to.............


    But I am not trying to incite riots, haha
    webOS? ....
    R2D2 SBF - VRZ_A957_2.4.5_1FF_01.sbf
    Works if you cant update to new update, flash this then update
    THANKS TO GREYGIFFORD
  9. Droid Sensei
    OneTenderRebel's Avatar
    Member #
    53261
    Join Date
    Mar 2010
    Location
    Hampton Falls, NH
    Posts
    3,333
    Liked
    353 times
    Twitter
    JefFullerMyself
    Phone
    Galaxy Nexus
    #8
    Quote Originally Posted by chasehammer View Post
    Quote Originally Posted by OneTenderRebel View Post
    I can tell you which phone OS this wouldn't happen to.............


    But I am not trying to incite riots, haha
    webOS? ....
    haha exactly............
    Anytime someone dares me to walk a mile in their shoes I do it! Because, hey free shoes and I am now a mile away from that person!

    Hatred is by far the ugliest trait any human can possess (think about it)
  10. Master Droid
    GrillMouster's Avatar
    Member #
    8060
    Join Date
    Nov 2009
    Posts
    290
    Liked
    1 times
    Phone
    Droid
    #9
    Quote Originally Posted by chasehammer View Post
    webOS? ....
    Nicely played, good sir.

Ads

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Similar Threads

  1. Android malware
    By Jdroid09 in forum Android Forum
    Replies: 6
    Last Post: 08-06-2011, 11:31 AM
  2. Spyware and malware Droid Apps in the Android Market
    By Mattjames in forum Android Applications
    Replies: 3
    Last Post: 09-02-2010, 12:17 AM
  3. The only design flaw on this phone...
    By Grey Hawk in forum Android General Discussions
    Replies: 89
    Last Post: 02-07-2010, 09:26 PM
  4. G1 design flaw?
    By pyro6128 in forum Android Smart Phones
    Replies: 24
    Last Post: 02-01-2010, 02:46 PM
  5. InvisibleShield Full Body design flaw?
    By rda990 in forum Android General Discussions
    Replies: 22
    Last Post: 01-17-2010, 07:11 PM

Search tags for this page

android - license check flaw with back button
,
android app login page design
,
android login page design
,

android login screen design

,
android url bar always show
,
droid apps malware
,
droid malware
,
press the button malware android
,

sbf malware droid

,
screen design for banking application in android
,
sirsean trustwave
,

vrz a957

,
vrz a957 .4
,

vrz a957 2.4.5 1ff 01.sbf

,
vrz a957 sbf
Click on a term to search our site for related topics.
Find us on Google+