Exploiting Android Users
codeword.xyz
codeword.xyz
If you want to type Chinese, you'll need an IME. Most of Chinese people relies on them. It was indeed an exploitable point, that you slip a lot of stuff into it:
- News pop-ups of course; - System information gatherer? Sure; - Search engine, convenient; - Anti-Malware software, certainly; - Anti-Virus software, you'll have it; - Homepage? Come on, let's make a bolder move - Browser! - A PC Manager. It's a combination of AV/AM and a software catalog, and the sweetest feature is to tell you how many seconds it took to boot up to your desktop, and shows a % of population you've beat across the nation, people can be bitchy over this.
Not just one major software vendor did this, everyone capable did, and still doing. There's also large internet companies that used by people on daily basis uses 0day exploits to push their desktop software. Like if you browse the Chinese part of the internet for one day, you'll end up with bunch of cute little Anti-Virus/cleanup/tweaking goodies rest in your notification area, some times they fight each other and cause BSoD.
Mac OSX includes a decent IME for Japanese, for example.
I don't have either FB or FB messenger installed, since the split... mostly because they ate my battery life, and breaking apart existing/working functionality sucks. Not to mention they've been gimping their mobile website ever since, I've been avoiding them much more lately. But FB is nowhere near this level of sleaze.
It's easier to turn down unethical work when it's only a few thousand dollars, vs your full-time job. Still, I felt pressure because I was actually talking with him on behalf of a guy I was subcontracting for, and who had invited me to partner in his own agency, so I did worry about injuring that relationship. It did make me wonder though, if those were the leads he was turning up, whether a partnership was such a good idea. . . .
As an ex Android user of 5 years, I just got tired of this "coming soon" attitude.
There are two technical holes in how this was achieved, disregarding the initial drive-by update install:
* Unprotected browser cookie storage
* Android web-based App Install requires no user interaction past a request to a web endpoint
Are these holes still open?
Rick has had numerous problems over time with scammers wrapping Paint.NET with scumbag installers and with "backspaceware" distributions. He's documented these issues in his blog:
http://blog.getpaint.net/2009/11/06/a-new-license-for-paintn...
http://blog.getpaint.net/2007/12/04/freeware-authors-beware-...
http://blog.getpaint.net/2011/10/03/paint-net-v3-5-9-and-dow...
http://blog.getpaint.net/2010/12/22/photoshop-filters-and-mo...
For as long as I've used Paint.NET (since v1) his home page and download page have never obfuscated or tried to lure users into downloading and installing crapware.
EDIT: Just turned off my adblocker and see I'm sadly very wrong about the crapware download ads. My other points still stand though.
homepage: right below his link (paint.net 4.0...) is a "GET IT HERE" picture add which installs crapware
download page: pig green banner "START DOWNLOAD" above his text link for the download.
I have no sympathy whatsoever for him - he's directly benefiting from the same scummy industry he's complaining about.
Another example, as recently as 3 months ago a search on google for "chrome" would result in a few ads that were for malware like this.
The ones that are in the actual installers upset me a lot... more so in open-source, and one of the reasons people are starting to avoid source-forge like the plague.
I guess this might be one benefit of the Windows Store, as long as that hasn't been taken over. I haven't checked it in awhile nor know their guidelines.
As it stands, I get a little sad when I see a project still on or using SF.
> Over time, those notification and opt-in screens were “optimized” away as much as possible. They already “agreed” to our 23 page EULA when they were trying to install Paint.NET but accidentally clicked the wrong download button anyway, right?
I'd say that what he's talking about is those sites that offer software for download, and the download button is displayed under an advertisement which also shows an image of a download button. If you click on the ad (showing an image of a download button), you get the malware, instead of the Paint.NET installer that you were trying to download.
I suspect this was an example of one of the bait-apps that shonky download sites (download.com and now sourceforge.com etc) repackage with toolbar installers.
As for browser cookie storage, there's not much the browsers can do. Even if they were encrypted or obfuscated somehow, the browsers themselves would still need access so people would always be able to reverse-engineer the process.
The only way I could see them preventing the web-based install exploit would be to always require a password first (and not just rely on session cookies to identify the user). I'm not sure if Google is doing that now or not.
http://extensiondefender.com/blog/
I'm not sure if the news I released had any effect, but they rapidly pivoted from a "desktop to mobile" ad network: https://web.archive.org/web/20141209085229/http://vulcun.com...
To some kind of e-Sports betting site: https://vulcun.com/
Oddly enough I submitted a bug report to google telling them they should set a content-security-policy on play.google.com, and was basically told "wont-fix" so the vulnerability to play store still exists.
Money? You said "thousands" of "users", even if you sell those owned computers/phones at let's say $1 you don't make that much as a company.
Fame/street creds? Look how I got those lusers ?
Or you don't even care? you could optimise the deadliness of an atomic weapon and you would feel the same: code done ! Awesome !
In general, it's best to assume the market knows something you don't, rather than the other way around.
The point with all of these schemes is to get users to install applications on their computer (or phone) that we were getting paid for on a per-install basis. A user who ran through our installer and installed all of the offers might net you $3. Multiply that by thousands a day, hundreds of thousands a month.
On the mobile side, as I mentioned in the article, finding desktop users who we could actually make money off of on mobile offers was much harder, which is why I suspect the practice hasn't caught on and become much more widespread in the industry.
The culture was very money-centric... everyone's compensation included a bonus component that was directly tied to how much revenue your products generated, and there would be big celebrations whenever new milestones were met.
http://www.browserauth.net/channel-bound-cookies
I believe Google does this now for their auth cookies.
The malicious app has local access to the user's machine, which means it has the ability to read and overwrite all files that the browser manages.
In the worst case, we could create malware that just reads the browser's client public key and create our own session with the same one.
You can submit an app to the play store and get it approved within a day. I mean, come one, phone data are some of the valuable possessions one has in this century and they care less about it being abused. I wish there can be a tightly knit app store similar to iOS with stringent reviews & regulation, but I know it's never going to happen.
All I'm saying is atleast a pair of eyes are looking into the app before it's reaching their users.