| 

Apple iPhone Warranty Scam

  • Post author: Omid Farhang
  • Post published: February 21, 2010
  • Reading Time: 2 min
  • Word Count: 422 words

Symantec has recently observed phishing scams targeting Apple iPhones in order to gain serial numbers, IMEI, model, and capacity, etc. What is an IMEI? An IMEI (international mobile equipment identity) is a 15-digit unique number used by GSM networks to identify valid devices. Every GSM, WCDMA, or iDEN mobile phone (and even the odd satellite phone) has an IMEI. It can be found under the battery of the device or by typing *#06# on the mobile. If your phone or device is lost or stolen you can report it to your service provider, providing the IMEI number. The service provider can then blacklist the IMEI number, rendering the device unusable in that country. ...

Continue Reading Apple iPhone Warranty Scam

Source code for Blackberry and iPhone spyware published

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 531 words

At theĀ BlackHat DCĀ conference andĀ SchmooCon, Nicolas Seriot, an independent researcher and Tyler Shields ofĀ VeracodeĀ have independently presented two very similar papers. The papers analyse weaknesses in security and application delivery models for iPhone and Blackberry and provide interesting read, especially if you are looking to write the next spyware application or a bot for one of the platforms. For me, the most interesting part of the papers is the one that shows that regardless of the implemented security mechanisms like data caging, providing applications with its own private storage, a third party application will be able to access a lot of potentially confidential data, like contact lists, sms and email storage and even the Blackberryā€™s microphone. ...

Continue Reading Source code for Blackberry and iPhone spyware published

Between a PoC and a Hard Place

  • Post author: Omid Farhang
  • Post published: February 12, 2010
  • Reading Time: 3 min
  • Word Count: 491 words

Several reports have been published detailing a Blackberry proof of concept (PoC) exploit calledĀ txsBBSpyĀ that was recently presented at a security conference. Although it may not have been the aim of the original presenter, some reports have framed the PoC as being able to exploit so-called vulnerabilities that the writers believe to be present in the Blackberry platform. The ā€œvulnerabilitiesā€ involve secretly forwarding incoming emails, locating devices by way of their GPS capabilities, eavesdropping on conversations by surreptitiously turning on microphones, and other such nefarious behavior. ...

Continue Reading Between a PoC and a Hard Place

BlackBerry Messenger the new vehicle to distribute Hoaxes?

  • Post author: Omid Farhang
  • Post published: January 13, 2010
  • Reading Time: 2 min
  • Word Count: 301 words

I received an interesting IM from a friend via BlackBerry Messenger [BBM] this weekend. She was worried that it could do damage to her shiny new BlackBerry and, as she knew I work for [a security company], she forwarded it to me for my opinion. As soon as I read it, I knew it was a hoax and told her just to delete it. It didnā€™t really surprise me that these Hoaxes are now being spread via BBM as the devices are becoming increasingly popular. Iā€™m sure all of you have received the usual one via E-mail about a Virus which burns the whole hard disc C of your computer , well now I believe you will be seeing them on your BlackBerry. ...

Continue Reading BlackBerry Messenger the new vehicle to distribute Hoaxes?

Warning On Possible Android Mobile Trojans

  • Post author: Omid Farhang
  • Post published: January 13, 2010
  • Reading Time: 2 min
  • Word Count: 347 words

Googleā€™s Android mobile operating system has been out for a while and is generating more and more interest. Now there has been some buzz about fraudulent applications being posted on the Android Market. See these postings: Both of these apps were written by an anonymous developer known as 09Droid. In fact, he had a whole collection of online banking applications for sale on the Market: ...

Continue Reading Warning On Possible Android Mobile Trojans