Showing posts with label mobile. Show all posts
Showing posts with label mobile. Show all posts

Thursday, May 29, 2008

Scams Exploiting Use of Cell Phone Remote Services - dongA.com - 28 May 2008

"Your personal information has been released. Failure to subscribe to the X-rated Internet site I’ve mentioned and pay the fee immediately will result in blockage of your cell phone.”

A 42-year-old urban worker, identified only as Hwang, got this message from an unidentified person this month. He considered it a nuisance and hung up, but then his cell phone could not connect to its wireless network.

Feeling confused, Hwang felt he had no choice but to join the site and pay the subscription fee of 80,000 won.

After reporting the case to the Korea Information Security Agency, the victim found out con artists employed a new type of voice phishing in which they illegally exploited remote control services and deceived handset users.

Remote control services are designed to help subscribers register, change, and cancel services via a phone call to service providers. Most users use the last four digits of their cell phone numbers as passwords instead of creating new numbers. The new phishing scam targets handset users who do not change their passwords.

Since Hwang kept the same password when he subscribed to the service, the swindler was able to block his cell phone calls.

The security agency said, “A few similar cases have been reported, but we’re worried that more people will be conned by the new voice phishing as many mobile phone users have subscribed to remote control service.”

More than 870,000 people subscribe to the remote control service of SK Telecom, the nation’s largest wireless service provider. In addition, 5,000 subscribers of LG Telecom and 1,000 of KTF use remote control services every month.

LG helps subscribers of remote control services with call blocking and forwarding. KTF offers voice mail and call rejection while SK provides call waiting and forwarding.

Wireless carriers said that since they provide many services, they generally use the last four digits of mobile phone numbers as passwords to help subscribers better remember the numbers.

The security agency said, “Subscribers can significantly protect themselves from swindlers if they just change their passwords in advance. If handset users get similar phone calls, they should unlock cell phones at customer service centers and sellers of wireless service and report them to the agency

Wednesday, May 28, 2008

Do Hackers Pose a Threat To Smart Phones? - The Wall Street Journal - 27 May 2008

In addition to placing calls, smart phones pack many of the functions found on computers: Internet, email, multimedia programs and even word-processing and spreadsheet capabilities. But, like computers, smart phones are vulnerable to viruses and other types of malicious software.

By all accounts, the risk of a smart-phone attack is low. But as people start using the devices for more sensitive tasks -- handling customer data and transferring corporate files -- security experts say smart phones may become more vulnerable to attack. So companies are working to protect both the devices and the networks behind them.

At the corporate level, IT departments are cracking down, mainly by limiting access these devices have to internal networks. And on the consumer front, computer-security companies are selling antivirus software that scans for rogue applications.

"They are real but rare" threats, says Jan Volzke, head of world-wide mobile marketing for Santa Clara, Calif., based McAfee Inc., which sells computer-security software.

Smart phones are used mainly by professionals who want to access corporate email and send documents on-the-go. But the market for these high-end devices is growing. Last year, Apple Inc. introduced the iPhone, a consumer-friendly device that appeals to students and others who like the touch screen and multimedia features. Market-research company NPD Group estimates that smart phones comprised 17% of all mobile-phone sales in the first quarter, an increase of 10 percentage points since the same period a year ago.

We've gotten to the point where smart phones are almost as sophisticated as desktop computers, says Ken Silva, chief technology officer for VeriSign Inc. So users should be just as protective of their smart phone as their home computer, he says.

So far, there are about 300 to 500 known versions of malicious software, or malware, written for phones -- a small number compared to those that attack personal computers. Malware infects phones through email attachments and text messages that ask users to download an application. They also can be delivered over wireless connections using Bluetooth technology.

Still, one reason why malware hasn't gained traction is a lack of a dominant operating system for attacker to focus on, says Nick Magliato, chief executive for Trust Digital, a security vendor. "It's very inefficient to write a virus for phones."

The majority of mobile malware has been written for phones using the Symbian operating system, which is found in about 65% of the global smart-phone market, according to ABI Research. Phones that run Symbian include some models made by Nokia, Samsung and Sony Ericsson.

Security experts at Symbian Ltd. monitor networks for potential malware outbreaks but haven't identified any serious threats so far, says David Wood, executive vice president of research. But, he adds, "we can never say never."

Another 11% of smart phones use the Windows Mobile operating system, which is used by some models made by Samsung and Palm. Phones on other platforms, such as Research In Motion Ltd.'s BlackBerry and Apple's iPhone, haven't had any serious malware outbreaks, says David Frazer, director of technology and services for security vendor F-Secure Corp.

Regardless of the operating system, the greatest risk of infection comes from third-party applications, such as games and ringtones, which give users an easy way to customize their phones. But people should exercise caution and only download software from trusted sources, says John Traynor, senior director of product marketing for Microsoft Corp.

Some types of malware can disable all the applications on a phone, including the ability to make calls, says Mark Komisky, chief executive for Bluefire Security Technologies, which makes antivirus software for smart phones. Another type of malware is so-called "snoopware," which was originally sold in Asia as a spouse-monitoring tool, says Paul Miller, managing director for mobile security at Symantec Corp. Now attackers see this application as a way to eavesdrop on conversations, intercept text messages or peek at call logs.

Several years ago, Symbian started requiring third-party software vendors to provide a "digital signature" when writing applications, Mr. Wood says. If the software is signed, Symbian can track which developer wrote the malware. The Windows Mobile operating system also uses digital signatures for software written by third-party developers.

Beyond downloading software only from trusted companies, individuals who own personal smart phones can protect themselves with antivirus software. Symantec and McAfee both offer programs that typically cost $30 for a one-year consumer subscription. Bluefire Security offers antivirus software for businesses and plans to release a consumer product next month.
Still, the majority of smart phones are connected to corporate networks, putting the onus on IT departments to protect the work force.

Rob Israel, chief information officer for John C. Lincoln Health Network in Phoenix, is in charge of guarding the data flowing through the company's network of hospitals and physician practices that employs about 4,400 people. A year ago Mr. Israel installed a system that prevented employees from uploading or downloading files to the company's computer network.
"Before that, it was the Wild West," and anyone could bring in any device and upload files to their computers, Mr. Israel says. "This was a real security hole."

Chief among his concerns was that an infected phone would transfer malware to the company's network. Mr. Israel acknowledges that chances are slim that a phone could get infected with malware, but says he doesn't want to take any chances.

For now, though, the greatest threat to corporate security is the loss of a smart phone -- especially one that's crammed with sensitive personal or corporate data.

Miriam Neal, vice president of information systems for South Western Federal Credit Union based in La Habra, Calif., says she worries mostly about lost smart phones. "We are a financial institution, and we need to protect the privacy of our members," Ms. Neal says.

Many companies are investing in technologies that will wipe clean all the information stored on a lost or stolen phone so that the data can't be used for criminal purposes, says Paul Roberts, a senior analyst with the 451 Group, a technology-research firm.

Write to Joseph De Avila at joseph.deavila@wsj.com

Tuesday, May 27, 2008

Hackers cracking mobile phones, warn experts - The Hindu

New Delhi: Much to the discomfort of mobile users, hackers, who are already wrecking websites and e-mails, are now targeting cell phones as well. Hackers are intruding mobile phones using hacking tools like spyware and spoofing, according to cyber experts..

Spyware is a tool which manipulates short message service (SMS) and allows them to be read by others, while spoofing, replaces mobile number of sender’s message, they said.

Explaining the functions of spyware, a Delhi-based cyber expert said, “A hacker sends an SMS to the targeted person. The person opens the message, installing spyware onto the device. The spyware, unknown to the victim, takes the SMS and forwards it to the hacker.”

Once installed, the hacker can monitor the ‘compromised’ phone call details and can even listen to the calls made or received by the user, Rajat Khare Director of Information security consulting firm Appin said.
However, it’s very difficult for the user to find out whether his/her phone has been hacked.

Besides spyware, SMS spoofing is another tool which hackers are widely using, Mr. Khare said.
Spoofing is used for changing the identity of source of SMS either with text or any desired number.

The Asian School of Cyber Law on its website stated an incident where “a young lady received an SMS from her husband’s cell phone informing her that he had had an accident and was at the hospital and urgently needed money. On receiving the SMS, she rushed out of the house with the money. She was attacked and robbed by the person, who had sent her the spoofed SMS.”

Spoofing has legitimate uses as well. A firm can set the company name in place of the number from which the message is being sent. — PTI

Sunday, May 11, 2008

Spam migrates to mobiles and gets more invasive - TOI Delhi 11 May 08

Spam migrates to mobiles and gets more invasive
Laura M Holson
If you thought spam on your computer was a bother, brace yourself: spammers want to find you on your cellphone. Some industry executives, along with consumer groups and security experts, are concerned that unwanted text messages on phones will be an even greater headache than unwanted computer messages. Cellphone spam is particularly annoying to its recipients because it is more invasive—announcing itself with a beep—and can be costly. Taber Lightfoot, an assistant director for new media at the Yale School of Management, is among those who have paid for the privilege of receiving cellphone spam. “I was at work and I got so annoyed,” she said of the first burst of three messages she received. She got another burst two days later. “That is when I called Verizon and demanded they reimburse me $1.60 for eight text messages,” Lightfoot said. “It wasn’t a lot of money, but it was my money.” American consumers are expected to receive an estimated 1.5 billion unsolicited text messages in 2008, according to Ferris Research, based in San Francisco, which tracks mobile messaging trends. That is nearly double what they received in 2006. Now some consumers, like Lightfoot, are monitoring their cellphones more aggressively for unwanted messages and, in some cases, demanding refunds. Computer security companies have developed products to help fight mobile spam. And phone companies and others are making it easier for customers to block unsolicited messages and keep spammers at bay. Most phone spam is actually e-mail that comes through gateways linking the internet and cellphone networks, industry executives said. And the inconvenience caused is not the only downside; there is also the threat of viruses as phones become more like personal computers. NYT NEWS SERVICE