Hacking has always been a controversial issue. Whether people see it as a vigilante attempt at justice, an attempt to keep authority in check or simply a way to cause mischief and potentially serious harm, it has always had its critics and defenders. None of the continuing controversy sheds light on what hacking actually is however.
A Serious vulnerability has been discovered in the Android default browser(AOSP) that allows a malicious website to bypass "Same Origin Policy(SOP)" and steal user's data from other websites opened in other tabs. AOSP browser is the default browser in Android versions older than 4.4.
What is Same Origin Policy?
SOP plays an important role in the Web Security, restricts a website from accessing scripts and data stored by other websites. For example, the policy restricts a site 'Y' from accessing the cookies stored by site 'X' in user's browser.
Same Origin Policy Bypass:
Rafay Baloch, a security researcher, found a security flaw in the "Same Origin Policy" system used by the AOSP browser. The bug allows the website 'Y' to access the scripts and user's data stored by website 'Y'.
Imagine You are visiting attacker's website while your webmail is opened in another tab, the attacker is now able to steal your email data or he can steal your cookies and could use it to compromise your mail account.
"Its because when the parser encounters the null bytes, it thinks that the string has been terminated, however it hasn't been, which in my opinion leads the rest of the statement being executed." Rafay said in his blog.
Metasploit Module:
Rafay published the poc on his blog in August. However, it remained largely unnoticed until rapid7 released a metasploit module that exploits the vulnerability.
http://www.rapid7.com/db/modules/auxiliary/gather/android_stock_browser_uxss
This browser also known for the remote code execution vulnerability, has been discontinued by Google. But older versions of Android do come with this browser.
What you should do?
Stop using the default android browser, Use Google Chrome or Mozilla.
File managers are an essential part of any operating system. Whether you’re browsing files in Windows or Android, there is always a need for a way to look at the files on your devices. To meet this need, there are a lot of file manager apps. Which ones are the best? Below we’ll detail the best file manager apps for Android.
[Price: Free with in app purchases]
AntTek Explorer Ex adorns our list thanks to the suggestion of a few readers. It has a clean, multi-pane UI complete with drag-and-drop functionality and about half a dozen different panels you can use for various things. It’s free to use with in app purchases and if you liked the old version better, you can get it by clicking here. It’s a clean, solid option with a lot of graphical UI elements that are pleasing to the eye.
[Price: Free / $3.99]
Astro File Manager is one of the iconic file managers along with ES File Explorer because they were the two big dogs back in the old days. Astro is still totally free with no in app purchases as long as you don’t mind ads and there is a $3.99 pro key you can get to get rid of those. It’s managed to stay relevant over the years with phone and tablet support along with cloud support. It’s also had a few UI upgrades over the years and it does look pretty good. It’s trusted by a lot of people and it has a lot of features.
[Price: Free]
Next on our list is the venerable ES File Explorer. This file manager has been around for a very long time, but the developers have done an excellent job of keeping it up to date in terms of both features and looks. It has a pleasant interface that’s easy to use and pretty much every feature that the other ones have had so far. It supports a number of languages and even supports Android versions 1.5 and up. If you want to try it out, use the button below.
[Price: Free with an option $2.99 plugin]
File Explorer Ex is another one that was recommended by our readers and it’s really good. It features a more graphically pleasing interface that can come off as flashy sometimes but it’s not a bad thing. It comes with all of the standard features including FTP, Windows networking, file browsing and management features and there are even some extra features for those who keep music on their devices. It has a good rating and it’s worth checking out.
[Price: Free]
This one is called File Manager and it is done by Gira.me. This is the first on the list that is optimized specifically for Android tablets. It’s themed in the style of Holo, so #holoyolo fans will be pleased. It can be switched from dark to light themed, depending on your tastes. Aside from that, it comes with the standard features and a few advanced ones as well. It also comes with a built in image gallery so if you’re looking for a new one of those too, you can kill two birds with one stone here. To give it a shot, use the button below.
[Price: Free]
Next on our list is simply called File Manager by Rhythm Software. This is a highly rated and highly capable file manager. The theme is a little old school, but you can theme it slightly to take the edge off of that older style. It comes with the standard features and some features for advanced users as well. This includes FTP support, LAN support, streaming media, and cloud storage support. It doesn’t look the best, but it is easy to use and has some of the more advanced features.
[Price: Free]
File Wrangler is a bit more of a minimal file manager compared to these other ones. It has two panels that let you browse various folders at once and that means it also supports drag and drop functionality. You can also do the basic stuff like file browsing and management and it has support for creating and unpacking tar and zip files. It doesn’t do much more than that so if you just want something simple without all of the extra fluff then this is worth checking out.
[Price: Free]
Next up is called PowerGrasp file manager and it’s a relatively newer, but powerful file manager. It’s not as feature filled as some others on this list, but it makes up for it with its ease of use and sleek interface. It’s been optimized for tablets and it’s a very simple file manager. If you need something simple and good looking, this is one of the best there is.
[Price: Free / $0.99]
This file manager specializes in browsing the entire system and can be used predominately by people who have root access. It’s a functional file browser with all the standard features such as tools to deal with compressed files, theming, and the ability to manage and edit your files. It comes with a sleek, easy-to-use interface and there are free and paid versions. You can pick it up using the button below.
[Price: Free(Trial)/$3.99]
Another great root-specific file manager is Root Explorer. This app is directed mostly at root users, so non-root users may want to use a different item on the list. Like Root Browser above, Root Explorer lets you explore those places on your device that many file managers do not. It comes with a sleek, minimal interface, your standard features, and even cloud storage support. It’s extremely stable, easy to use, and pretty much everyone who uses this app likes it. If you’re rooted, then give this a shot. It has an amazingly high rating in the Play Store.
[Price: Free(trial)/ $1.99]
Solid Explorer is already a very popular file manager and it’s also one of the best. It’s two-panel design is perfect for large devices and tablets, but you can use a one panel interface if you need to. If you do go with the two-panel interface, you can actually drag-and-drop from one panel to the next. This makes file browsing a lot easier in some cases. You can connect to cloud storage sites with it and it also acts as an FTP client. If you want to check it out, you can try the free trial using the button below.
[Price: Free]
Total Commander has a very, very long feature list so it’s great for those who need something powerful. It uses the increasingly popular dual-pane UI so you can drag and drop files and manage multiple locations at once and it employs a more minimal UI so you can more easily identify your files and manage them. There are also things like cloud support and some root stuff if you happen to need that. There are also optional plugins that deliver even more functionality. It’s totally free with no in app purchases.
[Price: Free with in app purchases]
Last up is X-Plore File Manager which has grown in popularity vastly since this last was last updated. It uses a dual-pane view and has root support if you need that. There is also cloud support, built-in viewers for almost any file type, Wi-Fi file management, and you can even view APK files as ZIP files for you modders out there. It’s powerful and free to try with some stuff being unlockable via in app purchases.
Best file manager apps wrap-up
If we missed any awesome file manager apps, let us know in the comments!
Android have been a long time target for cyber criminals, but now it seems that they have turned their way towards iOS devices. Apple always says that hacking their devices is too difficult for cyber crooks, but a single app has made it possible for anyone to hack an iPhone.
A security flaw in Apple's mobile iOS operating system has made most iPhones and iPads vulnerable to cyber attacks by hackers seeking access to sensitive data and control of their devices, security researchers warned.
The details about this new vulnerability was published by the Cyber security firm FireEye on its blog on Monday, saying the flaw allows hackers to access devices by fooling users to download and install malicious iOS applications on their iPhone or iPad via tainted text messages, emails and Web links.
MASQUE ATTACK - REPLACING TRUSTED APPS
The malicious iOS apps can then be used to replace the legitimate apps, such as banking or social networking apps, that were installed through Apple's official App Store through a technique that FireEye has dubbed "Masque Attack."
"This vulnerability exists because iOS doesn't enforce matching certificates for apps with the same bundle identifier," the researchers said on the company's blog. "An attacker can leverage this vulnerability both through wireless networks and USB."
Masque attacks can be used by cyber criminals to steal banking and email login credentials or users’ other sensitive information.
Security researchers found that the Masque attack works on Apple’s mobile operating system including iOS 7.1.1, 7.1.2, 8.0, 8.1, and the 8.1.1 beta version and that all of the iPhones and iPads running iOS 7 or later, regardless of whether or not the device is jailbroken are at risk.
According to FireEye, the vast majority, i.e. 95 percent, of all iOS devices currently in use are potentially vulnerable to the attack.
MASQUE ATTACK IS MORE DANGEROUS THAN WIRELURKER
The Masque Attack technique is the same used by "WireLurker," malware attack discovered last week by security firm Palo Alto Networks targeting Apple users in China, that allowed unapproved apps designed to steal information downloaded from the Internet. But this recently-discovered malware threat is reportedly a "much bigger threat" than Wirelurker.
"Masque Attacks can pose much bigger threats than WireLurker," the researchers said. "Masque Attacks can replace authentic apps,such as banking and email apps, using attacker's malware through the Internet. That means the attacker can steal user's banking credentials by replacing an authentic banking app with an malware that has identical UI."
"Surprisingly, the malware can even access the original app's local data, which wasn't removed when the original app was replaced. These data may contain cached emails, or even login-tokens which the malware can use to log into the user's account directly."
HOW TO PROTECT YOURSELF FROM MASQUE ATTACK
Apple devices running iOS are long considered more safe from hackers than devices running OS like Microsoft’s Windows and Google’s Android, but iOS have now become more common targets for cybercriminals.
In order to avoid falling victim to Masque Attack, users can follow some simple steps given below:
Do not download any apps offer to you via email, text messages, or web links.
Don't install apps offered on pop-ups from third-party websites.
If iOS alerts a user about an "Untrusted App Developer," click "Don't Trust" on the alert and immediately uninstall the application.
In short, a simple way to safeguard your devices from these kind of threats is to avoid downloading apps from untrusted sources, and only download apps directly from the App Store.
Google introduced a new security tool to help developers detect bugs and security glitches in the network traffic security that may leave passwords and other sensitive information open to snooping.
The open source tool, dubbed as Nogotofail, has been launched by the technology giant in sake of a number of vulnerabilities discovered in the implementation of the transport layer security, from the most critical Heartbleed bug in OpenSSL to the Apple's gotofail bug to the recent POODLE bug in SSL version 3.
The company has made the Nogotofail tool available on GitHub, so that so anyone can test their applications, contribute new features to the project, provide support for more platforms, and help improve the security of the internet.
Android security engineer Chad Brubaker said that the Nogotofail main purpose is to confirm that internet-connected devices and applications aren't vulnerable to transport layer security (TLS) and Secure Sockets Layer (SSL) encryption issues.
The network security testing tool includes testing for common SSL certificate verification issues, HTTPS and TLS/SSL library vulnerabilities and misconfigurations, SSL and STARTTLS stripping issues, and clear text traffic issues, and more.
"Google is committed to increasing the use of TLS/SSL in all applications and services. But 'HTTPS everywhere' is not enough; it also needs to be used correctly," Brubaker wrote in a blog post.
"Most platforms and devices have secure defaults, but some applications and libraries override the defaults for the worse, and in some instances we've seen platforms make mistakes as well. As applications get more complex, connect to more services, and use more third party libraries, it becomes easier to introduce these types of mistakes."
Nogotofail tool, written by Android engineers Chad Brubaker,Alex Klyubin and Geremy Condra, works on devices running Android, iOS, Linux, Windows, Chrome OS, OS X, and “in fact any device you use to connect to the Internet.” The tool can be deployed on a router, a Linux machine, or a VPN server.
The company says it has been using the Nogotofail tool internally for "some time" and has worked with developers to improve the security of their apps before releasing it. "But we want the use of TLS/SSL to advance as quickly as possible," Brubaker said.
The Nogotofail tool requires Python 2.7 and pyOpenSSL>=0.13. It features an on-path network Man-in-the-Middle (MiTM), designed to work on Linux machines, as well and optional clients for the devices being tested.
Do you use TextSecure Private Messenger for your private conversations? If yes, then Are you sure you are actually using a Secure messaging app?
TextSecure, an Android app developed by Open WhisperSystems, is completely open-source and claims to support end-to-end encryption of text messages. The app is free and designed by keeping privacy in mind.
However, while conducting the first audit of the software, security researchers from Ruhr University Bochum found that the most popular mobile messaging app is open to an Unknown Key-Share attack.
After Edward Snowden revealed state surveillance programs conducted by the National Security Agency, and meanwhile when Facebook acquired WhatsApp, TextSecure came into limelight and became one of the best alternatives for users who want a secure communication.
"Since Facebook bought WhatsApp, instant messaging apps with security guarantees became more and more popular," the team wrote in the paper titled, "How Secure is TextSecure?".
The messaging app attracted a lot of attention lately and was downloaded by half a million users from the Google's Play Store. The research team explained a complete and precise document and analyze of TextSecure’s secure push messaging protocol.
"We are the first to completely and precisely document and analyses TextSecure's secure push messaging protocol," the team wrote.
"We show that if long-term public keys are authentic, so are the message keys, and that the encryption block of TextSecure is actually one-time stateful authenticated encryption [and] prove TextSecure's push messaging can indeed achieve the goals of authenticity and confidentiality."
According to the research team, TextSecure works on a complex cryptographic protocol which is the part of the CyanogenMod Android operating system — a popular open source aftermarket Android firmware that has been installed on about 10 million Android devices. But researchers discovered an Unknown Key-Share Attack (UKS) against the protocol.
The research was conducted by Tilman Frosch, Christian Mainka, Christoph Bader, Florian Bergsma, Jorg Schwenk and Thorsten Holz. For better understanding the UKS against the protocol, the team explained it via an example as follows:
"Bart wants to trick his friend Milhouse. Bart knows that Milhouse will invite him to his birthday party using TextSecure. He starts the attack by replacing his own public key with Nelson's public key and lets Milhouse verify the fingerprint of his new public key. This can be justified, for instance, by claiming to have a new device and having simply re-registered ... if Milhouse invites Bart to his birthday party, then Bart may just forward this message to Nelson who will believe that this message was actually sent from Milhouse. Thus, Milhouse believes that he invited Bart to his birthday party, where in fact, he invited Nelson."
The researchers also provided a mitigation strategy, which has already been acknowledged by TextSecure's developers, that prevents the UKS attack. The proposed method actually resolves the issue, making TextSecure's push messaging secure and achieves one-time stateful authenticated encryption.