[-]
Who's Online
There are currently 3590 online users. [Complete List]
» 11 Member(s) | 3579 Guest(s)
AvatarAvatarAvatarAvatar
AvatarAvatarAvatarAvatar
AvatarAvatarAvatar

[-]
Latest Threads
K107-MB-V4.2
Last Post: Alby
2024-04-24 00:37
» Replies: 0
» Views: 156
[ROM] NEED ROM ZH960-MB-V5.0 MTK 6592
Last Post: sendycat2
2024-04-21 08:57
» Replies: 0
» Views: 107
ZH960 Tablet Bricked
Last Post: luis mar que
2024-03-20 19:52
» Replies: 14
» Views: 9759
Thanks, I've been looking for this for a...
Last Post: StevenRip
2024-02-25 05:00
» Replies: 0
» Views: 88
[SOLVED] Need ROM for ZH960-MB-V4.1
Last Post: ery1988
2024-02-21 08:59
» Replies: 0
» Views: 171
NEED ROM ZH960-MB-V4.1
Last Post: ery1988
2024-02-21 08:53
» Replies: 18
» Views: 13642
Budget phone choice help needed
Last Post: sabir7272
2024-02-10 06:52
» Replies: 4
» Views: 4244
ZH960-MB-V3.1 SOLVE
Last Post: Pranav1
2023-12-20 20:22
» Replies: 74
» Views: 33680
Need ROM for SONIM XP7S Android 5.1.1
Last Post: Alpa
2023-11-29 22:17
» Replies: 0
» Views: 109
Need rom for X101 Mt6592
Last Post: carencell
2023-11-24 21:30
» Replies: 3
» Views: 2091
Gizbeat 101: Get your MTK6589 MTK6577 MT...
Last Post: Alexia78
2023-11-13 11:28
» Replies: 8
» Views: 22290
Need rom for a tablet with board id "K10...
Last Post: oliver2
2023-10-24 20:23
» Replies: 6
» Views: 5332
How to Connect open public wifi
Last Post: oliverben45
2023-10-24 16:03
» Replies: 11
» Views: 8846
I NEED FILE FOR ITEL MOBILE PHONE AND TO...
Last Post: Meghnad45
2023-10-22 02:38
» Replies: 1
» Views: 1397
NEED Help Bricked my phone.
Last Post: Meghnad45
2023-10-22 02:36
» Replies: 4
» Views: 4816
Introduction
Last Post: ezrahidaya
2023-10-14 14:38
» Replies: 3
» Views: 1318
Needs help to root a china tablet brand ...
Last Post: ezrahidaya
2023-10-14 14:37
» Replies: 1
» Views: 195
Any tips to stay awake?
Last Post: ezrahidaya
2023-10-14 14:35
» Replies: 6
» Views: 5407
Need ROM for china TAb MT6797
Last Post: ezrahidaya
2023-10-14 14:34
» Replies: 1
» Views: 341
need this stock firmware for my tablet M...
Last Post: ramzii888
2023-10-14 02:20
» Replies: 4
» Views: 4518
Encryption Unsuccessful - Reset Android
Last Post: Aakriti
2023-10-13 16:51
» Replies: 3
» Views: 12396
betools
Last Post: egdeim
2023-09-21 12:41
» Replies: 4
» Views: 5031
[Movie Suggestion] Automata with Antonio...
Last Post: GottaGetX
2023-09-07 09:19
» Replies: 3
» Views: 4119





Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[BBC] eBay pulls sales of 'spyware phones'
#1
eBay pulls sales of 'spyware phones'

Online marketplace eBay is blocking the sale of a Chinese-made Android handset after reports the model is pre-installed with spyware.


http://www.bbc.co.uk/news/technology-279...hannel=rss&ns_source=PublicRSS20-sa
Reply
#2
This is hugely concerning. I remember reading about some of this a while ago on some other Chinese phones. The Lookout App flagged a process or two on my friend's phone as potentially being this.

Here at CPA we do have documented process for removing Chinese bloatware. I'll have to double-check to see if it addresses the software that is in question for the phone mentioned in this article.

How to remove Pre-Installed Bloatware:
http://www.chinaphonearena.com/forum/Thr...re-removal

Cliffs Notes Version:
- Run MTK Droid Tools
- Go to the Root/Recovery/Backup Tab
- Choose "Remove China"

I'm also personally a fan of Titanium Backup. From there, you can uninstall any regularly-installed or factory-installed program. If you're unsure about it, you can "freeze" it first, which is effectively like disabling it.
LG Nexus 4 | APQ8064 | 2GB / 16GB | 4.7"
Star S7589 | MTK6589 | 1GB / 8GB | 5.8"
THL T200C | MTK6592W | 2GB / 16GB | 6.0"
Mlais M52 | MTK6752 | 2GB / 16GB | 5.5"
innos D6000 | MSM8939 | 3GB / 32GB | 5.2"
Asus Zenfone 2 | Z2560 | 2GB / 16GB | 5.5"
Reply
#3
Very worrying indeed, I use online banking on my phone on a daily basis on my Pulid F17. Nothings gone missing yet, but who knows? The F17 is a clone of the N9500 by a different name. I haven't found anything on my phone yet.
The thing is that spyware is a very catch all term. Some people would consider certain cookies to be spyware, or things that produce spurious adverts. I think its blown up a little more because it could in theory install any new app/trojan on your phone, though this ability can be explained fairly innocuously, you've got to be able to update your software somehow in countries that don't have access to the android market. I'd be interested if anyone can actually identify some spyware/trojans on their phone, as the BBC failed to point at exactly what the code of concern is.

EDIT: This story mentions "...the Android.Trojan.Uupay.D trojan masquerading as the Google Play Store"
http://www.slashgear.com/star-n9500-chin...-17334108/
GizBeat likes this post
Reply
#4
Apps like framaroot and stuff like that are flagged by given scary names too. I've used china brand phones for couple years. The SMSreg is sometimes flagged and MTK Droid Tool removes it. But i've never had any problem with this. i normally leave it alone. I log into my admin accounts, banking, everything. never had an issue.

I believe it's overkill by ebay and maybe some complaint from samsung, HTC and such. Well looks like Aliexpress and vendors with their own online shops will now be gaining the fruit of ebay's decision if they really have stopped selling all China brands.

Anyway, if it's true, it's one more reason to not by cheap clones with software you no idea where it came from. Stick with the name brands who have something to lose by getting a bad rap for this. It doesn't necessarily mean you'll be fully protected, but is one way to protect.
You like this post
Reply
#5
Heck if you like to worry how about something more universal that affects Windows users, Mobile users and even sweet innocent good looking Linux users

(OK I lied I am not sweet)

your router may have a weakness.....and may take some time to have new firmware
----some companies seem a little slow to admit there might be an issue.
Your Bank's router may have a weakness
Your ISP etc etc

http://www.openssl.org/news/secadv_20140605.txt

Although its off topic, openssl has put out a new tarball
and you should check to see how to update your ca-certificates

Maybe a more experienced Android user might like to comment?

Using your web browser you can test any of your banksites etc that normally use
Code:
https://www.somedomain.com
eg the following site passes the latest vulnerbility which is -----CVE-2014-0224
https://www.ssllabs.com/ssltest/analyze....google.com&hideResults=on

test site
https://www.ssllabs.com/ssltest/

what you are looking for as well is a certificate issued AFTER the latest openssl release
---but that does not prove its using the latest

the date you are looking for is after June 5 2014.....to pass CVE-2014-0224
or a version that is not vulnerable

good luck

####################

back on topic as I use Linux I can't use
Quote: How to remove Pre-Installed Bloatware
nice tip from WuddaWaste

Instead, I install En versions of various apps
Use a root file manager = Root Browser to first go to /system/apps
uninstall Chinese app
long press the app and delete it

don't forget to have a backup before trying it

good luck

#####

edit 68

It looks like you can update your certificates but Android uses different names
they use the term keystore

in your system we appear to have
/system/lib/ssl
/system/etc/security/cacerts

this might be useful but I have not tested yet.....any comments from experienced Android users?
http://www.codeproject.com/Articles/7865...-authority
Reply
#6
Hi,
I have bought (last week) an jiake i9500w via ebay.
I have just read information about trojan in star i9500. Does jiake is the same company than star. May I have the trojan in my phone ?
Last question, ca we remove the trojan after rooting ?

Thank you
You like this post
Reply
#7
This is nothing to be concerned about for your phone.

If you want to check, use https://play.google.com/store/apps/detai...lesecurity . If Android.Trojan.Uupay.D is on your device, it should find it.
You and GizBeat like this post
Reply
#8
hmmm I have lost ability to give thanks here
----am I too naughty?

2) thanks Sniper47 for your link, my previous virus scanner was not giving me a recent virus defination list

Therefore I hope you don't mind me mentioning that the uupay issue was discovered on another device by
Kaspersky prior to the G app

rant starts.....name not mentioned for a reason
I installed recommended app.....and it did not appear under G in apps, in fact I could not easily spot it
but I admit my eyesight is not always the best
rant ends

For those who prefer Kaspersky here is some images and tips....I have only just installed this app----free version

Don't scan until you go into settings and turn off trust for system apps
----since that is the nature of the threat
[Image: 25p4bw2.jpg]

go back and do full scan

Here is a detected, known vulnerabiltiy.....I umm left it on but know how much I can't mention its name so have obscurred the name of the exploit?

[Image: 21lsbpi.jpg]

Finally after doing it....its nice to know how many checks scanner makes
and date of defs

[Image: 24cs28o.jpg]

Altho I am not a security expert in Linux and even less so in Android
IMHO go for a product that gives you transparency.
https://play.google.com/store/apps/detai...m.kms.free

good luck
WuddaWaste likes this post
Reply
#9
To be very clear, for the possibly Star brand firmware, the virus was first detected and announced by GData. Of course the virus may have existed and been known prior to the recent discovery on Star.

I've installed the GData just to see what you were talking about. Seems straightforward. Close the screen asking for reg info and tap scan.

You haven't been naugty. Well, maybe you have Fu Man but not that I've seen here. The thanks lingo has been changed. It's '+Rep' now. The little text button will be changed soon.
You and WuddaWaste like this post
Reply
#10
so the GDATA software will find the malware if install on the phone.
Will it remove it or have I to root my phone to remove it ?
I'm still waiting for my phone, I just want to prepare evrything befor I receive it?

Generally, have I to use an antivirus if I use only applications from google play store ?
You like this post
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [Sci-Am] Yes, Phones Can Reveal if Someone Gets an Abortion Scientific American 0 29 2022-05-19, 14:21
Last Post: Scientific American
  [Sci-Am] What is Pegasus? How Surveillance Spyware Invades Phones Scientific American 0 18 2021-08-14, 07:00
Last Post: Scientific American
  [Sci-Am] Home Sales Need Better Disclosure of Flood Risk, Experts Say Scientific American 0 270 2021-02-08, 06:37
Last Post: Scientific American
  [Wired] Phones Could Track the Spread of Covid-19. Is It a Good Idea? Wired Magazine 0 347 2020-03-21, 10:15
Last Post: Wired Magazine
  [Science Daily] Potential solution to overheating mobile phones Science Daily 0 456 2019-12-07, 05:07
Last Post: Science Daily

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Tech & Science
[Sci-Am] Lemon-Scented Marijuana Compound Reduces Weed’s ‘Pa...
Last Post: Scientific American
Yesterday 13:20
» Replies: 0
» Views: 5
[Sci-Am] New Interactive Map Shows Where Extreme Heat Threat...
Last Post: macikus
Yesterday 01:38
» Replies: 1
» Views: 40
[Sci-Am] How Ugandan Tobacco Farmers Inadvertently Spread Ba...
Last Post: Scientific American
2024-05-02 09:12
» Replies: 0
» Views: 18
[Sci-Am] Will the Amazon Rain Forest Help Save the Planet?
Last Post: Scientific American
2024-05-01 19:43
» Replies: 0
» Views: 16
[Sci-Am] The U.S. Spends a Fortune on Beach Sand That Storms...
Last Post: Scientific American
2024-05-01 06:15
» Replies: 0
» Views: 20
[Sci-Am] Could JWST Solve One of Cosmology's Greatest Myster...
Last Post: Scientific American
2024-04-30 03:14
» Replies: 0
» Views: 36
[Sci-Am] How to See the Lunar Far Side Right Here on Earth
Last Post: Scientific American
2024-04-29 13:40
» Replies: 0
» Views: 41
[Sci-Am] How Big a Threat Is Bird Flu?
Last Post: Scientific American
2024-04-29 00:05
» Replies: 0
» Views: 32
[Sci-Am] The Amazon's Record-Breaking Drought Is about More ...
Last Post: Tauma
2024-04-28 22:35
» Replies: 1
» Views: 36
[Sci-Am] FDA Recalls Heart Pumps Linked to Deaths and Injuri...
Last Post: Scientific American
2024-04-28 09:53
» Replies: 0
» Views: 15
[Sci-Am] Deadly African Heat Wave Would Not Have Been Possib...
Last Post: Scientific American
2024-04-27 20:10
» Replies: 0
» Views: 12
[Harvard] Getting ahead of dyslexia
Last Post: Harvard
2024-04-27 06:36
» Replies: 0
» Views: 19
[Sci-Am] Hollywood Should Give Brain Science a Star Turn
Last Post: Scientific American
2024-04-26 17:14
» Replies: 0
» Views: 33
[Sci-Am] Milky Way's 'Sleeping Giant' Black Hole Lurks Shock...
Last Post: Scientific American
2024-04-26 03:48
» Replies: 0
» Views: 48
[Harvard] Why AI fairness conversations must include disable...
Last Post: Harvard
2024-04-25 13:58
» Replies: 0
» Views: 54
[Sci-Am] How a New AI Model Helps Volcanic History Rise from...
Last Post: Scientific American
2024-04-24 23:17
» Replies: 0
» Views: 51
[Sci-Am] Everyone Will Have Fewer Relatives in the Future
Last Post: Scientific American
2024-04-24 09:25
» Replies: 0
» Views: 40
[Sci-Am] The Dark Side of Nostalgia for Wild, Untouched Plac...
Last Post: Scientific American
2024-04-23 19:59
» Replies: 0
» Views: 31
[Harvard] How did you get that frog to float?
Last Post: Harvard
2024-04-23 19:59
» Replies: 0
» Views: 48
[Sci-Am] In Matters of Scientific Debate, Follow the Houdini...
Last Post: Scientific American
2024-04-23 06:34
» Replies: 0
» Views: 30
[Harvard] Lifting a few with my chatbot
Last Post: Harvard
2024-04-23 06:34
» Replies: 0
» Views: 37
[Sci-Am] This Tiny Fish Makes an Ear-Blasting Screech for Lo...
Last Post: Scientific American
2024-04-22 17:01
» Replies: 0
» Views: 35
[Sci-Am] How Plant Intelligence Can Soothe Climate Anxiety
Last Post: Scientific American
2024-04-22 02:57
» Replies: 0
» Views: 48
[Sci-Am] Contributors to Scientific American’s May 2024 Issu...
Last Post: Scientific American
2024-04-21 13:36
» Replies: 0
» Views: 37
[Sci-Am] A ‘Computer’ Built from DNA Can Find Patterns in Ph...
Last Post: Scientific American
2024-04-20 23:27
» Replies: 0
» Views: 68
[Sci-Am] Unraveling the Secrets of This Weird Beetle’s 48-Ho...
Last Post: Scientific American
2024-04-20 09:17
» Replies: 0
» Views: 49
[Sci-Am] We Are Living in the Pyrocene, the Age of Fire that...
Last Post: Scientific American
2024-04-18 16:45
» Replies: 0
» Views: 97
[Harvard] Hate mosquitoes? Who doesn’t? But maybe we shouldn...
Last Post: Harvard
2024-04-18 03:05
» Replies: 0
» Views: 94
[Sci-Am] Why Some People Always Get Lost—And Others Never Do
Last Post: Scientific American
2024-04-17 13:33
» Replies: 0
» Views: 59
[Sci-Am] U.S. Carbon Removal Needs Have a $100-Billion Price...
Last Post: Scientific American
2024-04-16 23:48
» Replies: 0
» Views: 60
[Sci-Am] New Books Help Parents Explain Climate Disasters to...
Last Post: Scientific American
2024-04-16 10:13
» Replies: 0
» Views: 72
[Sci-Am] Renewable Energy Shatters Records in the U.S.
Last Post: Scientific American
2024-04-15 20:19
» Replies: 0
» Views: 82
[Sci-Am] The Dunning-Kruger Effect Shows that People Don’t K...
Last Post: Scientific American
2024-04-15 06:47
» Replies: 0
» Views: 79
[Sci-Am] AI Chatbots Will Never Stop Hallucinating
Last Post: Scientific American
2024-04-14 17:12
» Replies: 0
» Views: 73
[Sci-Am] How Do Periodical Cicadas Know When to Emerge?
Last Post: Scientific American
2024-04-14 03:11
» Replies: 0
» Views: 58
[Sci-Am] It’s Never Too Late to Take Climate Action
Last Post: Scientific American
2024-04-13 13:43
» Replies: 0
» Views: 68
[Sci-Am] To Ancient Maya, Solar Eclipses Signified Clashing ...
Last Post: Scientific American
2024-04-12 23:09
» Replies: 0
» Views: 69