Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > all things UNIX
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 8th, 2012, 12:47 PM
Ocky's Avatar
Ocky Ocky is offline
Very Frequent Poster
 
Join Date: May 2006
Location: George, S.Africa
Posts: 2,537
Default Clickjacking Rootkits for Android: the Next Big Threat ?

Clickjacking Rootkits for Android: the Next Big Threat?

Quote:
Mobile security researchers have identified an aspect of Android 4.0.4 (Ice Cream Sandwich) and earlier models that clickjacking rootkits could exploit.
__________________
Ubuntu Kubuntu Xubuntu Scientific Linux
  #2  
Old July 9th, 2012, 06:15 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

No.

To quote: The rootkit could be downloaded with an infected app and, once established, could manipulate the smartphone.

No. Because you would not install the infected app first. And this brings us back to square one - don't install crap.

Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #3  
Old July 10th, 2012, 10:09 PM
act8192 act8192 is offline
Frequent Poster
 
Join Date: Nov 2006
Posts: 726
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

And how do you know it's crap before installing.
On the google market aka play-store they do not display any crap/noncrap classifications.
And there's no such thing as download, virus scan, then install if clean.
Download is immediately followed by installation. A major flaw IMO.
  #4  
Old July 11th, 2012, 09:01 PM
x942's Avatar
x942 x942 is offline
Very Frequent Poster
 
Join Date: Feb 2011
Location: Your Network
Posts: 1,101
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

Quote:
Originally Posted by act8192
And how do you know it's crap before installing.
On the google market aka play-store they do not display any crap/noncrap classifications.
And there's no such thing as download, virus scan, then install if clean.
Download is immediately followed by installation. A major flaw IMO.

1) Google Play Store is protected by Bouncer

2) Don't install apps with 1 or 2 stars and read user comments.

3) Question all permissions (does that game REALLY need SMS?)

4) Root your phone and use Droid wall (firewall - default deny apps from getting internet access) and LBE Privacy Guard or PDroid (Revoke permissions). (yes, it's for the advanced user but still).

For the most part common sense is all that's needed. Android (mobile) malware is extremely overblown the majority of it comes from thrid-party stores (not the play store). Most of the crap in the play store that is considered "malware" is just advertising garbage saying "you won an ipad".

That said the state of AV's is worse. I have tested every AV on the play store (from a reputable source i.e Avast!) and all of them miss known malware (spam apps)! The detection rate is bellow 50% accurate. You are honestly better off without it and using common sense.
__________________
E-Mail: og8oh@notsharingmy.info
  #5  
Old July 12th, 2012, 07:24 AM
mack_guy911's Avatar
mack_guy911 mack_guy911 is offline
Very Frequent Poster
 
Join Date: Mar 2007
Posts: 2,483
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

http://news.softpedia.com/news/Troja...y-280687.shtml
__________________
Scientific Linux 6.2, xubuntu 11.10 *2x, Linux mint 10, Linux mint 12, opensuse 11.4, windows vista, ubuntu 10.04 and windows xp
  #6  
Old July 13th, 2012, 05:31 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

Quote:
Originally Posted by x942
That said the state of AV's is worse. I have tested every AV on the play store (from a reputable source i.e Avast!) and all of them miss known malware (spam apps)! The detection rate is bellow 50% accurate. You are honestly better off without it and using common sense.

That's crazy talk! We all know from the Windows world that AV software is a sure-fire way to have a 100% computer!
  #7  
Old July 13th, 2012, 05:41 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

Comparing AVs on Windows to those on Android is ridiculous because the capabilities are completely different. On Android it's a futile attempt at blacklisting. On Windows you get heuristics and various other forms of analysis that yield far better rates of detection.
__________________
  #8  
Old July 13th, 2012, 07:52 PM
RJK3 RJK3 is offline
Frequent Poster
 
Join Date: Apr 2011
Posts: 469
Default Re: Clickjacking Rootkits for Android: the Next Big Threat ?

Quote:
Originally Posted by x942
4) Root your phone and use Droid wall (firewall - default deny apps from getting internet access) and LBE Privacy Guard or PDroid (Revoke permissions). (yes, it's for the advanced user but still).

Good advice, only thing I could possibly add is:

5) Turn off auto-updates for less well known apps


Otherwise something harmless could slowly turn into something harmful, as was demonstrated earlier this year when researchers used incremental updates to get past Bouncer.
 

Wilders Security Forums > Software, Hardware and General Services > all things UNIX « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:46 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums