[-]
Who's Online
There are currently 985 online users. [Complete List]
» 3 Member(s) | 982 Guest(s)
AvatarAvatarAvatar

[-]
Latest Threads
Prime Сasual Dating - Legitimate Girls
Last Post: lukasz1
Today 10:26
» Replies: 0
» Views: 6
[ROM] NEED ROM ZH960-MB-V5.0 MTK 6592
Last Post: sendycat2
2024-04-21 08:57
» Replies: 0
» Views: 43
ZH960 Tablet Bricked
Last Post: luis mar que
2024-03-20 19:52
» Replies: 15
» Views: 9736
Thanks, I've been looking for this for a...
Last Post: StevenRip
2024-02-25 05:00
» Replies: 0
» Views: 42
[SOLVED] Need ROM for ZH960-MB-V4.1
Last Post: ery1988
2024-02-21 08:59
» Replies: 0
» Views: 142
NEED ROM ZH960-MB-V4.1
Last Post: ery1988
2024-02-21 08:53
» Replies: 18
» Views: 13611
Budget phone choice help needed
Last Post: sabir7272
2024-02-10 06:52
» Replies: 4
» Views: 4233
ZH960-MB-V3.1 SOLVE
Last Post: Pranav1
2023-12-20 20:22
» Replies: 77
» Views: 33651
Need ROM for SONIM XP7S Android 5.1.1
Last Post: Alpa
2023-11-29 22:17
» Replies: 0
» Views: 94
Need rom for X101 Mt6592
Last Post: carencell
2023-11-24 21:30
» Replies: 3
» Views: 2080
Gizbeat 101: Get your MTK6589 MTK6577 MT...
Last Post: Alexia78
2023-11-13 11:28
» Replies: 8
» Views: 22278
ZH960-MB-V3.1
Last Post: Giankyworld81
2023-11-01 19:35
» Replies: 21
» Views: 15408
Need rom for a tablet with board id "K10...
Last Post: oliver2
2023-10-24 20:23
» Replies: 6
» Views: 5294
How to Connect open public wifi
Last Post: oliverben45
2023-10-24 16:03
» Replies: 11
» Views: 8813
I NEED FILE FOR ITEL MOBILE PHONE AND TO...
Last Post: Meghnad45
2023-10-22 02:38
» Replies: 1
» Views: 1389
NEED Help Bricked my phone.
Last Post: Meghnad45
2023-10-22 02:36
» Replies: 4
» Views: 4801
Introduction
Last Post: ezrahidaya
2023-10-14 14:38
» Replies: 3
» Views: 1312
Needs help to root a china tablet brand ...
Last Post: ezrahidaya
2023-10-14 14:37
» Replies: 1
» Views: 186
Any tips to stay awake?
Last Post: ezrahidaya
2023-10-14 14:35
» Replies: 6
» Views: 5208
Need ROM for china TAb MT6797
Last Post: ezrahidaya
2023-10-14 14:34
» Replies: 1
» Views: 326
need this stock firmware for my tablet M...
Last Post: ramzii888
2023-10-14 02:20
» Replies: 4
» Views: 4491
Encryption Unsuccessful - Reset Android
Last Post: Aakriti
2023-10-13 16:51
» Replies: 3
» Views: 12390
betools
Last Post: egdeim
2023-09-21 12:41
» Replies: 4
» Views: 5031





Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[BBC] eBay pulls sales of 'spyware phones'
#1
eBay pulls sales of 'spyware phones'

Online marketplace eBay is blocking the sale of a Chinese-made Android handset after reports the model is pre-installed with spyware.


http://www.bbc.co.uk/news/technology-279...hannel=rss&ns_source=PublicRSS20-sa
Reply
#2
This is hugely concerning. I remember reading about some of this a while ago on some other Chinese phones. The Lookout App flagged a process or two on my friend's phone as potentially being this.

Here at CPA we do have documented process for removing Chinese bloatware. I'll have to double-check to see if it addresses the software that is in question for the phone mentioned in this article.

How to remove Pre-Installed Bloatware:
http://www.chinaphonearena.com/forum/Thr...re-removal

Cliffs Notes Version:
- Run MTK Droid Tools
- Go to the Root/Recovery/Backup Tab
- Choose "Remove China"

I'm also personally a fan of Titanium Backup. From there, you can uninstall any regularly-installed or factory-installed program. If you're unsure about it, you can "freeze" it first, which is effectively like disabling it.
LG Nexus 4 | APQ8064 | 2GB / 16GB | 4.7"
Star S7589 | MTK6589 | 1GB / 8GB | 5.8"
THL T200C | MTK6592W | 2GB / 16GB | 6.0"
Mlais M52 | MTK6752 | 2GB / 16GB | 5.5"
innos D6000 | MSM8939 | 3GB / 32GB | 5.2"
Asus Zenfone 2 | Z2560 | 2GB / 16GB | 5.5"
Reply
#3
Very worrying indeed, I use online banking on my phone on a daily basis on my Pulid F17. Nothings gone missing yet, but who knows? The F17 is a clone of the N9500 by a different name. I haven't found anything on my phone yet.
The thing is that spyware is a very catch all term. Some people would consider certain cookies to be spyware, or things that produce spurious adverts. I think its blown up a little more because it could in theory install any new app/trojan on your phone, though this ability can be explained fairly innocuously, you've got to be able to update your software somehow in countries that don't have access to the android market. I'd be interested if anyone can actually identify some spyware/trojans on their phone, as the BBC failed to point at exactly what the code of concern is.

EDIT: This story mentions "...the Android.Trojan.Uupay.D trojan masquerading as the Google Play Store"
http://www.slashgear.com/star-n9500-chin...-17334108/
GizBeat likes this post
Reply
#4
Apps like framaroot and stuff like that are flagged by given scary names too. I've used china brand phones for couple years. The SMSreg is sometimes flagged and MTK Droid Tool removes it. But i've never had any problem with this. i normally leave it alone. I log into my admin accounts, banking, everything. never had an issue.

I believe it's overkill by ebay and maybe some complaint from samsung, HTC and such. Well looks like Aliexpress and vendors with their own online shops will now be gaining the fruit of ebay's decision if they really have stopped selling all China brands.

Anyway, if it's true, it's one more reason to not by cheap clones with software you no idea where it came from. Stick with the name brands who have something to lose by getting a bad rap for this. It doesn't necessarily mean you'll be fully protected, but is one way to protect.
You like this post
Reply
#5
Heck if you like to worry how about something more universal that affects Windows users, Mobile users and even sweet innocent good looking Linux users

(OK I lied I am not sweet)

your router may have a weakness.....and may take some time to have new firmware
----some companies seem a little slow to admit there might be an issue.
Your Bank's router may have a weakness
Your ISP etc etc

http://www.openssl.org/news/secadv_20140605.txt

Although its off topic, openssl has put out a new tarball
and you should check to see how to update your ca-certificates

Maybe a more experienced Android user might like to comment?

Using your web browser you can test any of your banksites etc that normally use
Code:
https://www.somedomain.com
eg the following site passes the latest vulnerbility which is -----CVE-2014-0224
https://www.ssllabs.com/ssltest/analyze....google.com&hideResults=on

test site
https://www.ssllabs.com/ssltest/

what you are looking for as well is a certificate issued AFTER the latest openssl release
---but that does not prove its using the latest

the date you are looking for is after June 5 2014.....to pass CVE-2014-0224
or a version that is not vulnerable

good luck

####################

back on topic as I use Linux I can't use
Quote: How to remove Pre-Installed Bloatware
nice tip from WuddaWaste

Instead, I install En versions of various apps
Use a root file manager = Root Browser to first go to /system/apps
uninstall Chinese app
long press the app and delete it

don't forget to have a backup before trying it

good luck

#####

edit 68

It looks like you can update your certificates but Android uses different names
they use the term keystore

in your system we appear to have
/system/lib/ssl
/system/etc/security/cacerts

this might be useful but I have not tested yet.....any comments from experienced Android users?
http://www.codeproject.com/Articles/7865...-authority
Reply
#6
Hi,
I have bought (last week) an jiake i9500w via ebay.
I have just read information about trojan in star i9500. Does jiake is the same company than star. May I have the trojan in my phone ?
Last question, ca we remove the trojan after rooting ?

Thank you
You like this post
Reply
#7
This is nothing to be concerned about for your phone.

If you want to check, use https://play.google.com/store/apps/detai...lesecurity . If Android.Trojan.Uupay.D is on your device, it should find it.
You and GizBeat like this post
Reply
#8
hmmm I have lost ability to give thanks here
----am I too naughty?

2) thanks Sniper47 for your link, my previous virus scanner was not giving me a recent virus defination list

Therefore I hope you don't mind me mentioning that the uupay issue was discovered on another device by
Kaspersky prior to the G app

rant starts.....name not mentioned for a reason
I installed recommended app.....and it did not appear under G in apps, in fact I could not easily spot it
but I admit my eyesight is not always the best
rant ends

For those who prefer Kaspersky here is some images and tips....I have only just installed this app----free version

Don't scan until you go into settings and turn off trust for system apps
----since that is the nature of the threat
[Image: 25p4bw2.jpg]

go back and do full scan

Here is a detected, known vulnerabiltiy.....I umm left it on but know how much I can't mention its name so have obscurred the name of the exploit?

[Image: 21lsbpi.jpg]

Finally after doing it....its nice to know how many checks scanner makes
and date of defs

[Image: 24cs28o.jpg]

Altho I am not a security expert in Linux and even less so in Android
IMHO go for a product that gives you transparency.
https://play.google.com/store/apps/detai...m.kms.free

good luck
WuddaWaste likes this post
Reply
#9
To be very clear, for the possibly Star brand firmware, the virus was first detected and announced by GData. Of course the virus may have existed and been known prior to the recent discovery on Star.

I've installed the GData just to see what you were talking about. Seems straightforward. Close the screen asking for reg info and tap scan.

You haven't been naugty. Well, maybe you have Fu Man but not that I've seen here. The thanks lingo has been changed. It's '+Rep' now. The little text button will be changed soon.
You and WuddaWaste like this post
Reply
#10
so the GDATA software will find the malware if install on the phone.
Will it remove it or have I to root my phone to remove it ?
I'm still waiting for my phone, I just want to prepare evrything befor I receive it?

Generally, have I to use an antivirus if I use only applications from google play store ?
You like this post
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [Sci-Am] Yes, Phones Can Reveal if Someone Gets an Abortion Scientific American 0 29 2022-05-19, 14:21
Last Post: Scientific American
  [Sci-Am] What is Pegasus? How Surveillance Spyware Invades Phones Scientific American 0 18 2021-08-14, 07:00
Last Post: Scientific American
  [Sci-Am] Home Sales Need Better Disclosure of Flood Risk, Experts Say Scientific American 0 269 2021-02-08, 06:37
Last Post: Scientific American
  [Wired] Phones Could Track the Spread of Covid-19. Is It a Good Idea? Wired Magazine 0 347 2020-03-21, 10:15
Last Post: Wired Magazine
  [Science Daily] Potential solution to overheating mobile phones Science Daily 0 456 2019-12-07, 05:07
Last Post: Science Daily

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Tech & Science
[Sci-Am] In Matters of Scientific Debate, Follow the Houdini...
Last Post: Scientific American
Today 06:34
» Replies: 0
» Views: 12
[Harvard] Lifting a few with my chatbot
Last Post: Harvard
Today 06:34
» Replies: 0
» Views: 16
[Sci-Am] This Tiny Fish Makes an Ear-Blasting Screech for Lo...
Last Post: Scientific American
Yesterday 17:01
» Replies: 0
» Views: 23
[Sci-Am] How Plant Intelligence Can Soothe Climate Anxiety
Last Post: Scientific American
Yesterday 02:57
» Replies: 0
» Views: 36
[Sci-Am] Contributors to Scientific American’s May 2024 Issu...
Last Post: Scientific American
2024-04-21 13:36
» Replies: 0
» Views: 27
[Sci-Am] A ‘Computer’ Built from DNA Can Find Patterns in Ph...
Last Post: Scientific American
2024-04-20 23:27
» Replies: 0
» Views: 17
[Sci-Am] Unraveling the Secrets of This Weird Beetle’s 48-Ho...
Last Post: Scientific American
2024-04-20 09:17
» Replies: 0
» Views: 32
[Sci-Am] We Are Living in the Pyrocene, the Age of Fire that...
Last Post: Scientific American
2024-04-18 16:45
» Replies: 0
» Views: 85
[Harvard] Hate mosquitoes? Who doesn’t? But maybe we shouldn...
Last Post: Harvard
2024-04-18 03:05
» Replies: 0
» Views: 81
[Sci-Am] Why Some People Always Get Lost—And Others Never Do
Last Post: Scientific American
2024-04-17 13:33
» Replies: 0
» Views: 44
[Sci-Am] U.S. Carbon Removal Needs Have a $100-Billion Price...
Last Post: Scientific American
2024-04-16 23:48
» Replies: 0
» Views: 46
[Sci-Am] New Books Help Parents Explain Climate Disasters to...
Last Post: Scientific American
2024-04-16 10:13
» Replies: 0
» Views: 60
[Sci-Am] Renewable Energy Shatters Records in the U.S.
Last Post: Scientific American
2024-04-15 20:19
» Replies: 0
» Views: 68
[Sci-Am] The Dunning-Kruger Effect Shows that People Don’t K...
Last Post: Scientific American
2024-04-15 06:47
» Replies: 0
» Views: 68
[Sci-Am] AI Chatbots Will Never Stop Hallucinating
Last Post: Scientific American
2024-04-14 17:12
» Replies: 0
» Views: 57
[Sci-Am] How Do Periodical Cicadas Know When to Emerge?
Last Post: Scientific American
2024-04-14 03:11
» Replies: 0
» Views: 45
[Sci-Am] It’s Never Too Late to Take Climate Action
Last Post: Scientific American
2024-04-13 13:43
» Replies: 0
» Views: 55
[Sci-Am] To Ancient Maya, Solar Eclipses Signified Clashing ...
Last Post: Scientific American
2024-04-12 23:09
» Replies: 0
» Views: 58
[Sci-Am] What We Know about Taiwan’s Magnitude 7.4 Earthquak...
Last Post: Scientific American
2024-04-12 09:25
» Replies: 0
» Views: 77
[Sci-Am] Plastic Pollution Is Drowning Earth. A Global Treat...
Last Post: Scientific American
2024-04-11 19:50
» Replies: 0
» Views: 80
[Sci-Am] Eclipses Reveal a Comforting Clockwork in Our Chaot...
Last Post: Scientific American
2024-04-11 06:28
» Replies: 0
» Views: 43
[Harvard] ‘Harvard Thinking’: Climate alignment is no easy t...
Last Post: Harvard
2024-04-11 06:28
» Replies: 0
» Views: 46
[Sci-Am] Men Succumb to Anesthesia More Easily than Women
Last Post: Scientific American
2024-04-09 14:02
» Replies: 0
» Views: 58
[Sci-Am] How to Watch the Total Solar Eclipse Online
Last Post: Scientific American
2024-04-09 00:30
» Replies: 0
» Views: 76
[Sci-Am] Memories Are Made by Breaking DNA — and Fixing It, ...
Last Post: Scientific American
2024-04-08 10:50
» Replies: 0
» Views: 52
[Sci-Am] Ever Larger Cargo Ships Threaten Bridges, Ports and...
Last Post: Scientific American
2024-04-07 21:14
» Replies: 0
» Views: 58
[Sci-Am] Baltimore Bridge Collapse Will Teach Engineers to B...
Last Post: Scientific American
2024-04-07 07:47
» Replies: 0
» Views: 53
[Sci-Am] Pregnancy Increases Biological Age, but Giving Birt...
Last Post: Scientific American
2024-04-06 18:13
» Replies: 0
» Views: 20
[Sci-Am] Understanding Dyscalculia, Dyslexia’s Numeric Count...
Last Post: Scientific American
2024-04-06 04:35
» Replies: 0
» Views: 14
[Sci-Am] Baltimore Bridge Collapse Wreaks Havoc on Coal, Car...
Last Post: Scientific American
2024-04-05 15:14
» Replies: 0
» Views: 18
[Harvard] A playbook for policy change
Last Post: Harvard
2024-04-05 15:14
» Replies: 0
» Views: 16
[Sci-Am] Does Long-Term Benadryl Use Increase Dementia Risk?
Last Post: Scientific American
2024-04-05 01:43
» Replies: 0
» Views: 24
[Sci-Am] How Visually Impaired People Can Experience Solar E...
Last Post: Scientific American
2024-04-04 11:44
» Replies: 0
» Views: 20
[Harvard] Under pressure
Last Post: Harvard
2024-04-04 11:44
» Replies: 0
» Views: 41
[Sci-Am] Wild Birds Gesture ‘After You’ to Insist Their Mate...
Last Post: Scientific American
2024-04-03 08:12
» Replies: 0
» Views: 107
[Harvard] Glimpse into how mind may affect healing
Last Post: Harvard
2024-04-03 08:12
» Replies: 0
» Views: 57
[Sci-Am] The Future of Driving in the U.S. Is Electric—Sort ...
Last Post: Scientific American
2024-04-02 18:49
» Replies: 0
» Views: 26