Insan-IT Search:

Sunday, August 14, 2011

Android Security - A Year in Review

Paul Sparrows has posted a summary of Viruses and Trojans to hit Android this year. The Linux security model (SELinux excluded) leaves much to be desired and while Android takes a step in the right direction by having Apple-like granular permissions, I believe it falls down huge by failing to empower users. Android security would be much better served to select and enforce which permissions for apps during installation as opposed to the current take-it-or-leave-it (a.k.a my-way-or-the-highway) approach. My not so humble opinion as to why this scourge has hit Android so hard (that it might soon catch up to Windows on the desktop) as MVP (Most Vulnerable Platform) while long-established community Linux distributions (including "embedded" distributions such as MeeGo) have remained more acceptably secure comes down to 4 main points:

1) Mandatory open, reviewable, and debuggable source code versus Google's enabling and supporting of black-box DRM-supported proprietary binaries
2) Focus on repository QA/Testing versus Google's (inferrable and obvious) managerial push for throughput counts to build up a large number of apps in the marketplace
3) Shameless (and sometimes harsh) provision of user awareness, support, and higher expectations versus treatment of users like a herd of animals with only the lowest common denominator of expectations
4) Hashing and signing diligence and enforcement versus ... well let's just say I expected them to do a better job at this considering they're....you know...a company with the smartest geeks in technology... ... ...running an entire open-source project site... ... ...looking after more personal information than any Government... ... ...oh yeah... ... ...Google!!

I will have a followup post to go over these in detail and explain my rationale for these 4 points but in the meantime I recommend the install any of Symantic, Trend Micro, Sophos, AegisLab, or Lookout antivirus/malware scanners for your Android device. These should, until the Android Police come up with a community-developer and politically-neutral tool, should suffice to remove any less-than-welcome software.

Finally, Paul's list failed to include a list of apps delivering these infections and since this was something of interest to me I decided to compile a list myself. Keep in mind that several of the apps in this list have legitimate, uninfected counterparts and were simply infected and approved by Google for the Android marketplace (something which has me concerned about Google's priorities, but I digress). Here is the list which if you've installed apps from I would highly recommend a scan for infections:


AndroidOS_Droisnake.A
Tap Snake

Android.DroidDream AKA Android.Rootcager AKA AndroidOS_Lootoor.A
掷骰子
多彩绘画
Advanced App to SD
Magic Strobe Light
Advanced Compass Leveler
Super Stopwatch & Timer
Sexy Legs
Sexy Girls: Japanese
Bowling Time
软件强力卸载
Music Box
Best password safe
墨水坦克Panzer Panic
裸奔先生Mr. Runner
Hot Sexy Girls
Super sex sound
致命绝色美腿
Super Bluetooth Transfer
Advanced File Manager
Advanced Barcode Scanner
Task Killer Pro
Spider Man
蜘蛛侠
Funny Paint
Dice Roller
躲避弹球
Falling Ball Dodge
Photo Editor
Chess
APP Uninstaller
几何战机_PewPew
下坠滚球_Falldown
Falling Down
Screaming Sexy Japanese Girls
Hot Sexy Videos
Super History Eraser
Super Ringtone Maker
Hilton Sex Sound
Scientific Calculator
Super Guitar Solo
Super Sex Positions
Advanced Currency Converter
Basketball Shot Now
Omok - Five in a Row
Super Sexy Ringtones
手指赛跑 Finger Race
Magic Hypnotic Spiral
Quick Notes
投篮高手
Quick Delete Contacts
Advanced Sound Manager Version
Color Blindness Test

Android.BgServ AKA Troj/Bgserv-A AKA AndroidOS_BGSERV.A
Android Market Security Tool

Android.Zeahache

(Only have a photo of the app install screen available as seen below)
Android.Zeahache Infected App.jpg

Android.Adsms AKA AndroidOS_Adsms.A
(Usually installed from [link] in unsolicited SMS/Email message reading "Dear customer of [network provider], your mobile phone contains security system vulnerability. To increase the security level, please download the updated patch! [link]")
com.andriod
andiord.system.providers
org.me.androidapplication1

Android.Zsone AKA Android.Smstibook
iMatch
3D Cube horror terrible
ShakeBanger
Shake Break
Sea Ball
iMine
iCalendar
LoveBaby
iCartoon
iBook

Android.Spacem
Holy Fucking Bible

Android.LightDD
Beauty Breasts
Brightness Settings
Call End Vibrate
Contact Master
Delete Contacts
Floating Image Free
HOT Girls 1
HOT Girls 2
HOT Girls 3
HOT Girls 4
Paint Master
Quick Photo Grid
Quick SMS Backup
Quick Uninstaller
Sex Sound
Sex Sound: Japanese
Sexy Girls: Hot Japanese
Sexy Legs
Super App Manager
Super Color Flashlight
Super Photo Enhance
Super StopWatch and Timer
System Info Manager
System Monitor
Volume Manager

Android.Uxipp AKA Android/YZHCSMS.A
com.ppxiu
PPXIU
YHZC
YZHC

Andr/Plankton-A AKA Android.Tonclank
Favorite Games Backup

DroidDream Light Variant
Quick FallDown
Scientific Calculator
Bubble Buster
Best Compass & Leveler

Android/Sndapps.A AKA Android.Snadapps
Mosquito Repellent
Whoopee Cushion
Easy Button
Flashlight
Air Horn

17 comments:

Anonymous said...

brinkka2011 says: Resources such as the 1 you mentioned right here will be extremely useful to myself! I will publish a hyperlink to this web page on my personalized blog. Im sure my site site visitors will locate that fairly advantageous.

Anonymous said...

brinkka2011 says: Congratulations on possessing certainly one of one of the vital sophisticated blogs Ive arrive across in a while! Its just superb how a lot you'll be capable of think about away from a thing mainly simply because of how visually gorgeous it is. Youve place collectively an incredible weblog site space –nice graphics, films, layout. This is definitely a should-see web site!

Anonymous said...

Which came first? chicken or the egg

Anonymous said...

Wе're a bunch of volunteers and starting a new scheme in our community. Your website offered us with valuable info to work on. You'ѵe ԁοne a
formіԁable аctivity anԁ ouг entіre group will bе thаnkful to уou.


Reviеw my wеb-ѕite :: wedding dresses

Anonymous said...

Үou maԁe somе gooԁ pοints there.

I loοked on the web foг аԁditiоnal information about the іssue and founԁ
most peoplе will gο аlong ωith your ѵіews on thiѕ wеb site.


Heгe is my ωeb sіte ... SEO Wordpress Plugin

Anonymous said...

Each ρartісipant obsеrved pοsitive
aѕpects thгoughout thе assesѕment.



my webѕite; dirtytorque.co.za

Anonymous said...

hello there аnԁ thank you fоr уοuг info – I have definitely pickeԁ up somethіng new from rіght here.
I did however еxpertise ѕome teсhnical pointѕ
using this ωeb sіte, aѕ I expеrienced
to reloaԁ thе websіte many timeѕ pгevious to I could get it to load
properly. I had beеn wоnԁering if youг hosting іs OK?
Not that ӏ'm complaining, but slow loading instances times will very frequently affect your placement in google and could damage your high quality score if ads and marketing with Adwords. Anyway I am adding this RSS to my e-mail and could look out for much more of your respective fascinating content. Ensure that you update this again very soon.

Feel free to surf to my homepage - preserving your wedding dress

Anonymous said...

A good slot machines for sale will help you with tips and ideas,
giving you an overview of some possible less expensive materials available that you haven't even considered. This forces them to essentially bid on the project of building a deck.

Anonymous said...

fantastic submit, very informative. I'm wondering why the opposite specialists of this sector do not notice this. You should proceed your writing. I'm
sure, you have a great readers' base already!

my homepage: Affordable-Dental-Plan.Org

Anonymous said...

No added time expended on the fitness center, no
back pain due to the fact of to various crunches or other stomach workout routines
and no far a lot more sweaty workout routines basically to ensure that your abs
appear outstanding.

Here is my blog - Www.gobayuenergy.com

Anonymous said...


[url=bhagavadgita.ru/bhagavad_gita_kamenskaya_manziarli_16.htm]Гита, глава 16, в переводе А. А. Каменской[/url]

Anonymous said...

This doesn't really have to do with the topic at hand, but I wanna ask if you might know where I could obtain a quality captcha plugin that I might use on my blog?? I'm implementing the same blog
platform as you and I'm having trouble locating one?

Also visit my website ... mortgage Rates loans

Anonymous said...

Довольно интересно, мне понравилось!
[url=http://appcases.ru/index.php?route=product/search&filter_name=кабель]кабель для ipod shuffle[/url] не так уж и сложно, рекомендую!

Anonymous said...

We would propose stopping by the helpful web-site for far more information and
facts.

Here is my webpage; http://www.Marsvenusatwork.com/

Anonymous said...

Ηello еverybody, herе eνеry ρеrѕon
іs ѕhaгing theѕe kіnds of κnowledgе, thus
it's good to read this webpage, and I used to visit this web site everyday.

Feel free to visit my page - abrir cuenta facebook

Anonymous said...

It's truly very difficult in this busy life to listen news on Television, therefore I only use internet for that purpose, and obtain the latest information.

Also visit my weblog: http://crearfacebook.weebly.com/

Anonymous said...

Youг style іѕ гeally unique сomрareԁ to οther people I've read stuff from. Thanks for posting when you have the opportunity, Guess I'll
just boοkmark thіѕ blog.

Here іѕ mу weblog crear facebook gratis

Best of Insan-IT