ADVERTIZE HERE

New Post

Rss

Showing posts with label SECURITY MANAGEMENT. Show all posts
Showing posts with label SECURITY MANAGEMENT. Show all posts
Thursday, 24 August 2017
MOBILE VIRUSES

MOBILE VIRUSES

                                          SMART PHONE VIRUSES


 We are all aware that the android phone is a permanent point through which one can have access to the internet.What I mean is that every now and then you are on the internet with your smart phone making a research or doing something different with it.So as they( smart phones) are mostly on the internet, they can easily be compromised with a malware.
A malware is a program on the computer that has the tendency or the capacity of harming the system in which it dwells. Some examples of malware are viruses, worms and Trojans.
A virus is defined as a malicious software which is been designed to spread to other computers by putting itself in to running programs.
A Trojan is a program that is on the smart phone and allows external users to connect discreetly.
A Worm is a program that multiplies on multiple computers across a network.
Recent studies have shown that malware in smart phones have increased in the last few years posing as a threat to analysis and detection.
mycomsec.blogspot.com_mobile_virus_alert
Smart Phone Virus Alert


                                        Malware Attacks 

There are three processes of malware attacks:
  • Infection; This is a means by which a malware can use to penetrate inside a smart phone as infection.There are four forms of malware infection according to the user interaction degree.
a) Explicit permission;The explicit permission is to ask the user if it is allowed to infect the system indicating its potential malicious nature.
b)Implied permission;The implied permission is when the user is fond of downloading and installing soft wares such as games and other important applications. The Trojan will do all its best in to luring you to install these attractive applications that carry malware.
c)common interaction;This is based on reading or opening an email or messages which is a common behavior among users.
d)No interaction;This form of infection do not have any interaction with the user ( no emails or messages). It just infects without your notice. This one is very dangerous isn't it?
mycomsec.blogspot.com_virus_alert_image

  • Achieving the goal: As quickly as the malware has infected the smart phone it will want to achieve its goal which is getting access to the user data or detailed information by way of damaging the device, deleting important information of the user, modifying data on the device and the like.It can also steal the user data and sell to a third party or the user themselves.

  • Spread to other systems;After achieving the goal, it will now spread to other devices through Wi-Fi, blue tooth or infrared, telephone calls and emails or messages.
                                Mobile Viruses

Below are some viruses that can infect your smart phone.
a)Trojan and viruses such as:
  • Red Browser; Red Browser is a Trojan that allows smart phone to visit a Wireless Application Protocol(a type of technology that allows you to send an email and look at information on the internet using a mobile phone) site without WAP connection.During the application installation, the user will be asked to grant a permission for it to send messages. If the permission is granted, Red browser  can send messages to paid call centers. It will use the smart phone's connection to social media networks such as Twitter, Face book, Whats App etc in order to get the details of the user and send them messages.
  • Card Trap; This is a virus which is present in different models of smart phones which aims in deactivating the system and third party applications.It also infects the memory card with a malware capable of infecting Windows.
  • Ghost push; This is a malicious software on smart phones that roots the device and install malicious application directly in to the system and then divides and unroots the device to prevent users from removing the threat by master reset.Ghost push is hard to detect and it cripples the system resources and executes quickly.
  • Caribe/Cabir;This one is a worm of computers which was developed in 2004. It is believed to have been the first computer worm that can infect mobile phones running Symbian OS.

b) Ransomware; This is another form of mobile virus that locks out the users so that they cannot have access to their mobile phones. The user will be demanded to pay before they unlock the device.
c) Spyware;This is a software put onto your mobile phone or computer without you realizing it that sends information about you and your Internet use over the Internet.Spyware is mostly classified into four types: Adware, System Monitors, Tracking Cookies, and Trojans; Some examples of spyware are;

  • CoolWebSearch;This is a group of programs that takes advantage of Internet Explorer vulnerabilities. The package directs traffic to advertisements on Web sites including Coolwebsearch.com. It displays pop-up ads, rewrites search engine results, and alters the infected computer's hosts file to direct DNS lookups to these sites.


  • Internet Optimizer; also known as DyFuCa, redirects Internet Explorer error pages to advertising. When users follow a broken link or enter an erroneous URL, they see a page of advertisements. However, because password-protected Web sites (HTTP Basic authentication) use the same mechanism as HTTP errors, Internet Optimizer makes it impossible for the user to access password-protected sites.


  • Zango (180 solutions) ;This transmits detailed information to advertisers about the Web sites which users visit. It also alters HTTP requests for affiliate advertisements linked from a Web site, so that the advertisements make unearned profit for the 180 Solutions Company. It opens pop-up ads that cover over the Web sites of competing companies.


  • HuntBar, aka WinTools or Adware,Web Search was installed by an ActiveX drive-by download at affiliate Web sites, or by advertisements displayed by other SpyWare programs-an example of how SpyWare can install more SpyWare. These programs add toolbars to Internet Explorer, track aggregate browsing behavior, redirect affiliate references, and display advertisements.


o CoolWebSearch, a group of programs, takes advantage of Internet Explorer vulnerabilities. The package directs traffic to advertisements on Web sites including coolwebsearch.com. It displays pop-up ads, rewrites search engine results, and alters the infected computer's hosts file to direct DNS lookups to these sites.
o Internet Optimizer, also known as DyFuCa, redirects Internet Explorer error pages to advertising. When users follow a broken link or enter an erroneous URL, they see a page of advertisements. However, because password-protected Web sites (HTTP Basic authentication) use the same mechanism as HTTP errors, Internet Optimizer makes it impossible for the user to access password-protected sites.
o Zango (formerly 180 Solutions) transmits detailed information to advertisers about the Web sites which users visit. It also alters HTTP requests for affiliate advertisements linked from a Web site, so that the advertisements make unearned profit for the 180 Solutions Company. It opens pop-up ads that cover over the Web sites of competing companies.
o HuntBar, aka WinTools or Adware,WebSearch was installed by an ActiveX drive-by download at affiliate Web sites, or by advertisements displayed by other SpyWare programs-an example of how SpyWare can install more SpyWare. These programs add toolbars to IE, track aggregate browsing behavior, redirect affiliate references, and display advertisements


Article Source: http://EzineArticles.com/1054106
o CoolWebSearch, a group of programs, takes advantage of Internet Explorer vulnerabilities. The package directs traffic to advertisements on Web sites including coolwebsearch.com. It displays pop-up ads, rewrites search engine results, and alters the infected computer's hosts file to direct DNS lookups to these sites.
o Internet Optimizer, also known as DyFuCa, redirects Internet Explorer error pages to advertising. When users follow a broken link or enter an erroneous URL, they see a page of advertisements. However, because password-protected Web sites (HTTP Basic authentication) use the same mechanism as HTTP errors, Internet Optimizer makes it impossible for the user to access password-protected sites.
o Zango (formerly 180 Solutions) transmits detailed information to advertisers about the Web sites which users visit. It also alters HTTP requests for affiliate advertisements linked from a Web site, so that the advertisements make unearned profit for the 180 Solutions Company. It opens pop-up ads that cover over the Web sites of competing companies.
o HuntBar, aka WinTools or Adware,WebSearch was installed by an ActiveX drive-by download at affiliate Web sites, or by advertisements displayed by other SpyWare programs-an example of how SpyWare can install more SpyWare. These programs add toolbars to IE, track aggregate browsing behavior, redirect affiliate references, and display advertisements


Article Source: http://EzineArticles.com/1054106
  • Flexispy: This is an application which is considered to be a Trojan, based on symbian (
The Symbian OS is the operating system developed and sold by Symbian Ltd. The OS is used primarily by Nokia with its S60 user interface and by Sony Ericsson with its UIQ user interface, but the Symbian OS is also used by a number of Japanese mobile phone manufacturers for handsets sold inside of Japan). The program sends all information received and sent from the smart phone to a Flexispy server.
                         Suggested Preventive Measures
The preventive measures put in place to manage malware are as follows.


  • An antivirus software can be deployed on a device to verify that it is not infected by a known threat, usually by signature detection software that detects malicious executable files. A firewall, meanwhile, can watch over the existing traffic on the network and ensure that a malicious application does not seek to communicate through it. It may equally verify that an installed application does not seek to establish suspicious communication, which may prevent an intrusion attempt.   
  Read This too:Five things you should never post on Facebook

  • Bio-metric identification.
    Another method to use is Bio-metric identification. Bio-metric identification is a technique of identifying a person by means of their morphology(by recognition of the eye or face, for example) or their behavior (their signature or way of writing for example). One advantage of using bio-metric security is that users can avoid having to remember a password or other secret combination to authenticate and prevent malicious users from accessing their device. In a system with strong bio-metric security, only the primary user can access the smartphone.
    mycomsec.blogspot.com_mobile_biometric_image


  • Visual Notifications

    In order to make the user aware of any abnormal actions, such as a call they did not initiate, one can link some functions to a visual notification that is impossible to circumvent. For example, when a call is triggered, the called number should always be displayed. Thus, if a call is triggered by a malicious application, the user can see, and take appropriate action.

    I recommend:
    MOBILE PHONE SECURITY
      

  • Rootkit Detector:The intrusion of a rootkit ( A rootkit is a clandestine computer program designed to provide continued privileged access to a computer while actively hiding its presence. The term rootkit is a connection of the two words "root" and "kit." ) in the system is a great danger in the same way as on a computer. It is important to prevent such intrusions, and to be able to detect them as often as possible. If the Operating System is compromised due to Jailbreaking ( about unlocking your phone to do whatever you want with it.Jailbreaking is typically used in connection with the iPhone, the most 'locked down' of the mobiles on sale today: it lets you install apps that haven't been approved by Apple, customize the interface in various ways, and generally make iOS more like Android), root kit detection may not work if it is disabled by the Jailbreak method or software is loaded after Jailbreak disables Rootkit Detection.

    mycomsec.blogspot.com_rootkit_image

                          Security Software
    This security software is made up of individual components to strengthen various vulnerabilities: prevent malware,intrusions,the identification of a user as a human as well as user authentication.Examples are Anti-virus and firewalls.  

    Thanks a lot for your time.

    Do share this article by using the social network floating button below the article. 
   
Monday, 21 August 2017
MOBILE PHONE SECURITY

MOBILE PHONE SECURITY

MOBILE SECURITY.

It is interesting to know that the average person in the world can own up to about two or more mobile phones. You would agree with me that without mobile phones in this time of the world, man can not do most things.Whether you like it or not it is true. Can you do away with your mobile phone for a month? I know some could try but they will definitely fail the test.
computer_security_first _mobile_pnhone_inventer
MARTIN COOPER

Mobile phone was invented by a man named Martin Cooper 44 years ago.Now look at it today, everywhere in the world you will find a mobile phone.


You can also Read;Five things you should never post on Facebook


Mobile security is the way of giving protection to your smart phones,lap tops, tablets and computers from threats and any other form of vulnerabilities associated with them.

Smartphones collect and compile an increasing amount of sensitive information to which access must be controlled to protect the privacy of the user. We use smart phones to communicate and also plan for our private lives and works.Within companies, these technologies are causing too much of a change in the organization of information systems hence they have become a new source of risks.The mobile phone, especially the smart phone as well as computers are exposed to a lot of target attacks. These attacks exploit the weaknesses in the smart phones or computers that may be in the form of a text message, an email or MMS.

Challenges involved in Mobile phone Security. 
There are countless number of challenges or threats that mobile phone users are been exposed to.These sort of threats damage the operation system of the phone and can also modify or transmit user data.
A Smart phone

The bad guys target three areas concerning mobile usage.

  • Data: Mobile phones are data management devices and may contain sensitive data such as private information, call logs, credit card numbers, authentic information and the like.The bad guys may steal some of these important details of you or of your company or work.
  • Availability:When the bad guys attack your mobile phone, they deprive the owner of its usage and therefore you will have a limited access to it.
  • Identity: Smart phone is indisputably a device which is highly customizable in which the contents of it is associated with a specific personality.Every mobile phone gives  information about its owner and the bad guys may steal these information in order to do other offenses.
                                                                                      

When a mobile phone is being targeted by the bad guys, they do a lot of things to the phone when they succeed.
  • They control the phone, communicate with it, send commands in a form of spam via messages or emails to the phone.
  • They force the phone to make phone calls as if it were the owner.
  • The can discharge the phone's battery thereby reducing its usage.
  • They steal the user's identity in order to impersonate them. This point raises a security concern especially in countries where phones are used to place orders,check bank accounts information or used as an identity card.
  • The attacker can make the phone record the conversation between the owner and others which can be sent to a third party.
  • They can also remove the photos, videos, music,contacts, calendar and other professional data of the owner.
This is a just a few of what the bad guys( hackers,crackers,key loggers etc) can do to your smart phone.
Thanks for reading this article.
Do not forget to share this article by using the social network floating button at the left side or below this article. 
    
   
Copyright © 2012 Computersecuritywatch All Right Reserved