David Ansermot Web Developer / TYPO3 Integrator

3mar/110

Google ban 21 infected Android apps

Google has banned 21 popular applications from the Android Market, because they contains many malware and trojans.
These applications belong to the same developer (Myournet) and integrate all the exploit called "rage-against-the-cage", which allows malicious code to get administrator rights (root) on versions of Android greater than 2.2.2.

27oct/100

A flaw in IOS 4.1 allow access to personal datas

A new security flaw has been discovered in iOS: it bypasses the password that protects iOS an iPhone running 4.1.
So, the hacker can access personal data stored in the mobile.

To achieve this, it must simply enter # # # on the keypad, instead of an emergency number, then just press all the buttons lock and appeal. This causes the release of the phone application that provides access to contacts, messaging and call history.

Apparently, this flaw is exploitable from version 4.2 Beta 3 IOS. Which suggests that Apple got wind of the vulnerability and that it has corrected

Source: Video of a Brazilian hacker who gave a demonstration of the exploit:

Video of bug on Vimeo

26mar/100

First malware to practice overwrite discovered hidden in an Adobe Updater

A malicious code has been spotted for the first time by computer security experts.

Indeed, researchers have discovered a malware that replaces the updates to certain applications. Usually, such programs do not overwrite practice.

Only computers running Windows are affected. The malware hides in the form of an updater for Adobe products or Java. A variant mimics Adobe Reader v.9 and overwrite AdobeUpdater.exe, which aims to connect regularly to the Adobe servers to check if a new version is available.

Once installed on a warm machine, the malware opens a client DHCP (Dynamic Host Configuration Protocol), DNS (Domain Name System), a network share, and a port to receive commands.

According to an expert at Trend Micro, good antivirus should detect this threat. It also states that infected computers will be altered even after uninstalling the malware, because they will lose the auto-update any infected software, exposing the machine has other threats if patches can not then be quickly installed (because of this defect). It will indeed users victim of these malicious codes, start to download updates to their hand, what some will do or will not want to do.

Source : Nguyen Cong Cuong's blog (Security analyst)

24déc/090

New jailbreaked iPhone worm !

A new worm is added to the family of malware targeting smartphones from Apple. The International Institute SRI Malware Threat Center has published a study on a new variant of the worm iKee.B (duh) that transforms the jailbreaked iPhone into zombie machines.

Captured on 25 last month, this new variant targets jailbroken iPhones, one operator as its predecessors, a flaw in the SSH service present on all jailbroken iPhones.

IPhones become infected by the result of zombie machines controlled remotely by a server located in Lithuania, to divert their data.

This worm does not seem to worry that Apple keeps repeating that the use of jailbroken iPhones is a security risk

Source