Google Play pulls sneaky data-harvesting apps with 46m+ downloads
- Reference: 1649674871
- News link: https://www.theregister.co.uk/2022/04/11/in_brief_security/
- Source link:
Apps included a speed camera radar, several Muslim prayer apps, a QR scanner, a WiFi mouse tool, a weather app and others.
A Panama-based company Measurement Systems developed the code, according to AppCensus co-founder Joel Reardon, whose mobile app testing firm discovered the overly nosy software, reported it to Google, and published [1]research about how it works.
[2]
According to the Wall Street Journal , which first [3]reported the story, Measurement Systems has ties to a Virginia defense contractor that does cyber-intelligence, network-defense and intelligence-intercept work for US national security agencies.
[4]
[5]
Google removed the apps as of March 25, but said they could be re-listed if they removed the dodgy code to comply with Google Play Store's rules for collecting users' data. Some of the apps did this, and were already back for sale as of April 6.
"All apps on Google Play must comply with our policies, regardless of the developer. When we determine an app violates these policies, we take appropriate action," a Google spokesperson told The Register .
Infosec folk spot open Fox News database
Fox News said it has secured an open database after bug hunters at Security Discovery alerted the news organization about the security incident waiting to happen.
For its part, Fox News said the open database was in a development environment, not a live, production environment, and that no customer records were exposed.
[6]
"We were contacted in October of 2021 by Security Dynamic about what would correctly be characterized as a general company development environment primarily containing an archival snapshot of public video metadata such as program descriptions and talent bios," a spokesperson said in an email to The Register .
"Additionally, there was a list of business email addresses as well as URLs, other ID's and environments that were no longer in use at the time of discovery," the statement continued. "This environment did not service any Fox News applications or systems. The database was secured within hours following the receipt of the report from Security Dynamic in accordance with our responsible disclosure policy."
Security Discovery co-founder Jeremiah Fowler, working with the research team at website building info firm Website Planet, discovered the non-password protected database. They said the 58GB dataset contained almost 13 million records that spanned storage information, internal emails, usernames, employee ID numbers and affiliate station information.
[7]
"One folder contained 65k names of celebrities, cast and production crew members and their internal FOX ID reference numbers," the threat researchers [8]wrote . "The records also captured a wide range of data points including event logging, host names, host account numbers, IP addresses, interface, device data, and much more."
Despite Fox News' assurances that this was a test environment, Fowler and friends noted that many records were labeled "prod," which is typically an abbreviation for production records.
But even in a development environment, this data could pose a security risk as these environments often use the same storage repositories, middleware and infrastructure as live production environments, the threat researchers added.
Additionally, the security researchers made it clear that they aren't implying any customer or user data was at risk, and they applauded the Fox security team for acting "fast and professional" to close the exposed database. Still, "any non-password protected database could potentially allow someone to insert malicious code into the network," they noted.
Autodesk patches high-severity bugs
Autodesk has [9]patched multiple high-severity vulnerabilities that, if exploited, could allow attackers to run any malicious code on infected machines and steal sensitive information.
Security firm Fortinet's threat research team [10]discovered the bugs, which affect Autodesk's DWG TrueView, Design Review and Navisworks, and reported them to the software provider. Its research team also provided a run-down of all seven vulns.
Both companies urge users to apply the patches ASAP.
[11]Google must pay €150 million fine to French Competition Authority, court orders
[12]Patch now: RCE Spring4shell hits Java Spring framework
[13]Fintech platform flaw could have allowed bank transfers, exposed data
[14]Cryptocurrency-mining AWS Lambda-specific malware spotted
The first five bugs, CVE-2022-27525, CVE-2021-40167, CVE-2022-27526, CVE-2022-27527 and CVE-2022-25797, are memory corruption vulnerabilities.
[15]CVE-2022-27525 affects Autodesk Design Review. It's caused by a malformed Design Web Format (DWF) file, "which causes an out-of-bounds memory write due to an improper bounds check," Fortinet explained.
If exploited, this bug can allow cybercriminals to execute arbitrary, malicious code via a specially crafted DWF file.
[16]CVE-2021-40167 affects the same product and is also caused by a buggy DWF file. It could allow an attacker to leak memory within the context of the application.
[17]CVE-2022-27526 , which could also be exploited to leak memory, affects Autodesk's Design Review product. A malformed Truevision (TGA) file causes this bug. Specifically, the TGA file "causes an out-of-bounds memory access, due to improper bounds checking when manipulating a pointer to an allocated buffer," Fortinet said.
[18]CVE-2022-27527 effects Autodesk Navisworks. It's caused by a malformed PDF file, which also leads to out-of-bounds memory access.
The fifth memory corruption bug, [19]CVE-2022-25797 , caused by a malformed DWG file, affects DWG Trueview and could allow a criminal to execute arbitrary code using a crafted DWG file.
[20]CVE-2022-27523 , a buffer over-read vulnerability in Autodesk DWG TrueView, could allow a remote attacker to leak sensitive data using a malicious DWG file.
And finally [21]CVE-2022-27524 , is an out-of-bounds vuln in DWG TrueView that could be exploited to leak sensitive data.
CISA, D-Link urge end-of-life router retirement
CISA has advised anyone using certain older D-Link routers to take them offline before miscreants find and exploit a critical remote control execution vulnerability.
On Monday, CISA [22]added the RCE bug, dubbed [23]CVE-2021-45382 , to its catalog of known exploited vulnerabilities. It exists in all series H/W revisions D-Link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the dynamic domain name system (DDNS) function in the ncc2 binary file.
The ncc2 service allows for some firmware and language file upgrades via the web interface. But as Malwarebytes Labs researcher Pieter Arntz [24]explained , "the ncc2 service on the affected devices appears to have been shipped with a number of diagnostic hooks available."
If exploited, this would allow an attacker to call these hooks without authentication. "These files appear to be rendered when queried and can be used to both interrogate the given device for information, as well as enable diagnostic services on demand," he added.
The software bug received a 9.8 CVSS score, which means it's critical that users address it immediately. But because the affected routers are end-of-life, D-Link isn't issuing any patches for the vulnerable devices.
Both CISA and [25]D-Link suggest that you retire these models ASAP, before a cyber criminal finds the vuln.
And if you still aren't convinced, there's a proof-of-concept on [26]GitHub , which makes it really easy for any evil doers to remotely take over the vulnerable devices and then execute malicious code.
Cybercriminals still exploiting Spring4Shell
Miscreants continue to exploit the Java Spring framework remote code execution vulnerability a week after security researchers [27]discovered the nasty software bug.
A week after the initial outbreak, Check Point Research said it's seen about [28]37,000 attempts to allocate the vulnerability, dubbed "Spring4Shell."
While organizations around the globe have been affected by the bug, Europe was the hardest hit, according to the security shop.
In the first four days after post discovery, 16 percent of orgs worldwide experienced exploitation attempts. But in Europe, that number jumped to 20 percent. Australia and New Zealand ranked second, at 17 percent, followed by Africa (16 percent), Asia (15 percent), Latin Americas (13 percent) and North America (11 percent).
Perhaps unsurprisingly, the software vendor industry felt the most pain from Spring4Shell. According to Check Point, 28 percent of companies in this sector were impacted by the vulnerability. Education and research orgs were the second-most affected, with 26 percent impacted. And insurance/legal, ISPs/MSPs, and finance/banking institutions tied for third place at 25 percent.
While noting its own CloudGuard AppSec customers were not vulnerable, "If your organization is using Java Spring and not using CloudGuard AppSec, immediately review your software and update to the latest versions by following the official Spring project guidance," the security firm advised. ®
Get our [29]Tech Resources
[1] https://blog.appcensus.io/2022/04/06/the-curious-case-of-coulus-coelib/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YlRQs6@P1iNyB8SV2R2d4QAAANQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.wsj.com/articles/apps-with-hidden-data-harvesting-software-are-banned-by-google-11649261181?mod=djemalertNEWS
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlRQs6@P1iNyB8SV2R2d4QAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlRQs6@P1iNyB8SV2R2d4QAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YlRQs6@P1iNyB8SV2R2d4QAAANQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YlRQs6@P1iNyB8SV2R2d4QAAANQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.websiteplanet.com/blog/foxnews-leak-report/
[9] https://www.autodesk.com/trust/security-advisories/adsk-sa-2022-0004
[10] https://www.fortinet.com/blog/threat-research/fortinet-security-researchers-discover-multiple-vulnerabilities-in-autodesk-products-dwg-trueview-navisworks-and-design-review
[11] https://www.theregister.com/2022/04/08/google_france_advertising/
[12] https://www.theregister.com/2022/03/31/spring_vuln/
[13] https://www.theregister.com/2022/04/07/salt-fintech-platform-vulnerability-ssrf/
[14] https://www.theregister.com/2022/04/07/aws_lambda_malware/
[15] https://fortiguard.com/zeroday/FG-VD-21-084
[16] https://fortiguard.com/zeroday/FG-VD-21-085
[17] https://fortiguard.com/zeroday/FG-VD-21-086
[18] https://fortiguard.com/zeroday/FG-VD-21-088
[19] https://fortiguard.com/zeroday/FG-VD-21-090
[20] https://fortiguard.com/zeroday/FG-VD-21-064
[21] https://fortiguard.com/zeroday/FG-VD-21-065
[22] https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[23] https://nvd.nist.gov/vuln/detail/CVE-2021-45382
[24] https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/04/cisa-advises-d-link-users-to-take-vulnerable-routers-offline/
[25] https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10264
[26] https://github.com/doudoudedi/D-LINK_Command_Injection1/blob/main/D-LINK_Command_injection.md
[27] https://www.theregister.com/2022/03/31/spring_vuln/
[28] https://blog.checkpoint.com/2022/04/05/16-of-organizations-worldwide-impacted-by-spring4shell-zero-day-vulnerability-exploitation-attempts-since-outbreak/
[29] https://whitepapers.theregister.com/
And there was much rejoicing
Impressive. Now if they applied the same level of zeal to Google's software...
...
...
https://www.ftc.gov/system/files/documents/public_comments/2018/08/ftc-2018-0074-d-0018-155525.pdf
__[...]Surprisingly, Google collected or inferred over two-thirds of the information through passive means.
At the end of the day, Google identified user interests with remarkable accuracy.
__Both Android and Chrome send data to Google even in the absence of any user interaction. Our
experiments show that a dormant, stationary Android phone (with Chrome active in the background)
communicated location information to Google 340 times during a 24-hour period, or at an average of
14 data communications per hour.
__While using an iOS device, if a user decides to forgo the use of any Google product (i.e. no Android,
no Chrome, no Google applications), and visits only non-Google webpages, the number of times data
is communicated to Google servers still remains surprisingly high. This communication is driven purely
by advertiser/publisher services. The number of times such Google services are called from an iOS
device is similar to an Android device. In this experiment, the total magnitude of data communicated
to Google servers from an iOS device is found to be approximately half of that from the Android
device.
__Advertising identifiers (which are purportedly “user anonymous” and collect activity data on apps and
3rd-party webpage visits) can get connected with a user’s Google identity. This happens via passing of
device-level identification information to Google servers by an Android device.
...
...
...and the list goes on...
" D-Link suggest that you retire these models ASAP"
Fair enough - if they are unsafe to use then they ought to be scrapped.
Now, given that they are unsafe because of software errors that D-Link incorporated in them, it means that they were not fit for purpose when sold.
So, it seems reasonable to me that D-Link should recall the routers and replace them for free (or at least with a substantial discount) with models whose securty flaws are as yet undiscovered.
No? Thought not.
Re: " D-Link suggest that you retire these models ASAP"
Planned obsolescence ?
Even accidental as may be the case here should result in some form of compensation.
Hidden Functionality
My Son who is in the first year of driving his own vehicle does not have a black box. Now his insurance provider recently recommended that policies could be managed by installed their App.
He installed the App (from Google Play) as this looked to be the simplest way to update his annual mileage, and then a day or two later went through it to see what could be done........
He then found that there was a record of all his journeys (foot, cycle & car) with a driving score by them. From what understand there is nothing to show that this data is collected. What is worse is that there is no way to attribute the journeys to the driver.
Obviously he promptly uninstalled so I could not check permissions but my assumption is that it is asking for location data. We checked the vendor's website and in the gumpf on the App there is nothing about recording journeys. Now it may just be pulling the data from the Google TimeLine but whatever to then score the driving is grossly wrong.
Anyone get a notice from goog?
Anyone get a notice from goog to remove the bad software. And why don't they scan the software they are serving to people instead of waiting for others to tell them.
Why is goog exempt from notifying people they were provided malicious software? You have to have a valid Email to get the software, a notice is expected.
Keep it simple
Mines a D-Link, but not one of the numbers listed.
My thought (and plan) is to always get a device with the fewest possible features (e.g. no externally visible services implemented on the router, like web serving from plugged-in storage). That should reduce the externally exposed bug footprint. And, never, ever enable remote adminstration or management. Only allow management from the local network.
And yes, I'm aware that that last rules out the semi-custom devices provided by some ISPs as "you must use this device". If you can't avoid that, then I suggest a second router between the ISP thing and your local network.
Re: Keep it simple
And, if you can, do not allow WiFi management of network kit, although you will need something wired.
And always convert you ISP thing into modem only, if you can. That will also involve some wire.
If it was the Russians or the Chinese or bogeyman du jour of the USA...
-> Measurement Systems -> a Virginia defense contractor that does cyber-intelligence, network-defense and intelligence-intercept work for US national security agencies
Come on. You know full well this is the CIA/NSA collecting information. Don't beat about the bush.