Showing posts with label Android Hacking. Show all posts
Android Phones Now Harder To Hack Than iPhones | RISC
While governments and law enforcement agencies continue to push device makers to create backdoors, there is always a workaround that lets them crack open devices on there own in the name of investigation.
In this regard, companies like Cellebrite and Greyshift have turned out to be very helpful, as they provide solutions to break into almost any device.
Back in 2016, we saw a major controversy involving Apple and the FBI when Apple refused to unlock the iPhone of the shooter involved in the San Bernardino case.
It’s a different story that recently Apple faced criticism for not encrypting iPhone backup data on iCloud, thereby leaving scope for government access.
iPhone more hackable than Android
Anyway, when it comes to cracking smartphones, iPhones are assumed to be superior to Android in terms of privacy and security.
However, the story has taken a u-turn, and Android phones have become harder to crack than iPhones. That’s according to a forensic detective Rex Kiser who works with the Fort Worth Police Department.
“Right now, we’re getting into iPhones. A year ago we couldn’t get into iPhones, but we could get into all the Androids. Now we can’t get into a lot of the Androids,” Kiser told Vice.
Kiser suggests that it has now become tougher to extract data from newer operating systems. Probably, they are “trying to make it harder for law enforcement to get data from these phones, under the guise of consumer privacy.”
During a test conducted by NIST, Cellebrite’s UFED InFeild Kiosk tool couldn’t efficiently harvest browsing activity, GPS data, or app data from social media apps like Facebook, Instagram, Twitter, etc., when trying to get inside Google Pixel 2 and Galaxy S9.
Surprisingly, the tool returned empty-handed in the case of Huawei P20 Pro. As per the test report, the tool (version v7.5.0.875) supports over 15,000 types of devices on paper, including Android, iOS, and feature phones.
On the other hand, the UFED tool could suck in a lot more when tested on iPhone X.
Overall, it’s evident that OEM encryption backdoors could be helpful, but law enforcement agencies aren’t relying on them entirely. Instead, they’re trying to create backdoors on their own by reverse engineering.
So, technically, it’s possible to get inside a smartphone as new as iPhone 11 Pro Max; it will just take time, patience, and resources.
However, one thing to note here is that breaking a smartphone’s encryption isn’t the end of the road, according to former FBI agent Bob Osgood.
Beyond that, forensic detectives need to decipher millions of lines code inside apps containing complex data structures that constantly change with software updates. That’s where companies like Greyshift, Cellebrite, and MSAB jump into the game with their magic wands.
Monday, March 2, 2020
Posted by Sivapriya
Why Android Malware is worse than you thought.
The future will not only
be about thinner, faster, and bendable smartphones, but it will definitely also
be about security and bigger online threats.
Let’s imagine a scenario
where you don’t need to take photos any more because Google will simply choose
the best pictures from a live stream of the day’s events just to make your life
easier.
Soon you won’t even need
to decide what to eat, your Android phone will know exactly what you need and
what you like, showing you the most suitable foods for your age.
But there’s so much hype
around the future of Android that we forget to see the obvious threats, the
alarmingly increasing number of Android malware, and the criminal activities
carried out on smartphones.
According to a recent
International Data Corporation (IDC) study, one out of every one hundred mobile
devices (1.4%) on the global market was infected with malware in Q2 2015.
The same study reveals
that vendors shipped a total of 334.4 million smartphones worldwide in the
first quarter of 2015 and Android dominated the market with a 78% share. That’s
a lot of Android phones affected by malware!
0.2% of the devices in
the U.S. were infected with malware in the second quarter of 2015. Of the 0.2%
infected devices, more than half (62%) were infected with malware aimed at
stealing the user’s personal data.
Privacy-stealing malware
can get a wide range of personal information and data from your Android device,
including contacts, locations, pictures, and login credentials for your online
banking.
Using this type of
malware, hackers can easily gain access to your bank account data and use it to
carry out criminal acts on your behalf or sell your info on the black market.
This is not a spy movie we’re talking about, this is a very common scenario in
2016, anywhere in the world.
The good thing is that
Google has been constantly making security improvements to the Android
platform. The number of vulnerabilities that affect the OS compared to PC
platforms is really small. But the customizable nature of the OS still leaves
the door open to security breaches.
Guess where that leaves
your Android smartphone security? That’s right, in your own hands. Every click
counts!
Here are 5 must-follow
tips to protect your Android device from malware:
- Stop exposing yourself to bad
apps in unofficial stores. Always get the latest apps from official Google
& partner stores.
- A good Antivirus is a must on
your phone.
- Don’t be afraid of all the
updates your phone asks for from time to time. They can be a life saver.
- Use a VPN when making online
payments using public WiFi.
- Beware of data-pulling adware.
Install an ad blocker or at least an ad tracker.
No doubt that Android is here to
stay and dominate the smartphone market and we’re really excited about the
future of Android technology.
To Know more about Mobile Security.
Our Institute Location:
Redback IT Solutions
Private Limited,
#AL 24 TNHB PHASE III,
Sathuvacheri,( Near
Vallalar Water Tank)
Vellore. 632602
Contact :
Training Coordinator
8189985551
Best Hacking Apps For Android Phones
As
Android has emerged as the top mobile operating system, we have seen a great
rise in the Android hacking apps. For our readers, we have prepared a list of
the best hacking apps for Android that can be used by a technology enthusiast,
an IT security administrator, or an ethical hacker.
9
Best Hacking Apps For Android Phones – 2016
AndroRAT
AndroRAT
stands for Android and RAT (Remote Administrative Tools). This top hacking tool
was released a long time ago as a client/server application. The app aims to
give you the control of the Android system remotely and fetch the information
from it. This Android app runs as a service right after the boot. So, a user
doesn’t need to interact with the service. The app provides you the ability to
trigger the server connection by a call or SMS.
The
features in this useful Android hacking app include collecting information like
contacts, call logs, messages, and location. The app also allows you to
remotely monitor received message and state of phone, making a phone call and
sending texts, taking picture from camera, opening URL in the default browser
etc.
Hackode
Hackode
is an Android app which is basically a collection of multiple tools for ethical
hackers, IT specialists, and penetration testers. In the app, there are three
modules –Reconnaissance, Scanning, Security Feed — available in the
application.
With
this app, you get the functionalities like Google hacking, SQL Injection, MySQL
Server, Whois, Scanning, DNS lookup, IP, MX Records, DNS Dif, Security RSS
Feed, Exploits etc. It’s a great Android hacking app to start with and it
doesn’t ask for your private information to operate.
zANTI
zANTI
is a reputed Android hacking suite from Zimperium. This software suite comes
with multiple tools that are widely used for penetration testing purposes. This
mobile penetration testing toolkit allows the security researchers to scan a
network easily. This toolkit allows the IT administrators to simulate an
advanced hacking environment to detect multiple malicious techniques.
zANTI
could be called an app that brings the power of Backtrack on your Android
device. As soon as you login into zANTI, it maps the entire network and sniffs
the websites being visited along with their cookies — thanks to ARP cache
poisoning on devices.
The
various modules in the app are network mapping, port discovery, sniffing,
packet manipulation, DoS, MITM, and more.
FaceNiff
FaceNiff
is a top Android hacking app that allows you to intercept and sniff your WiFi
network traffic. This tool is widely used to snoop into people’s Facebook,
Twitter and other social media websites using your Android device. This
hacker-favorite tool steals cookies from WiFi network and gives an attacker an
unauthorised access to victim’s account.
FaceNiff
is developed by Bartosz Ponurkiewicz — the same developer who wrote Firesheep
for Firefox hacking on desktop.
Droidsheep
Droidsheep
is an effective hacking app developed for security analysts interested in
playing with Wi-Fi networks. The app has the ability to hijack the web session
profiles over a network and it works with almost all services and websites.
As
you fire up the Droidsheep app, it acts a router that monitors and intercepts
all the Wi-Fi network traffic and fetches the profiles of active sessions. With
this app, one can sniff Facebook, LinkedIn, Twitter and other social media
accounts.
DroidSheep
Guard, another version of app, helps you to detect ARP-Snoofing on the networks
i.e. the attacks by FaceNiff, Droidsheep, and other software.
APKInspector
APKInspector
is an app that allows you to perform reverse engineering tricks. With this app,
you can get the graphic features and analysis functions for the users to get a
deep insight. This powerful Android hacking tool helps you get the source code
of any Android app and visualize the DEX code to erase the credits and license.
Nmap
One
of the most popular network scanning apps for desktop can also be used on
Android operating system. Nmap works on both non-rooted and rooted phones. If
you are a beginner Android hacker, this hacking app app is a must have.
SSHDroid
SSHDroid
is a SSH server implementation developed for Android that allows you to connect
your Android device to a PC and run commands like ‘terminal’ and ‘adb shell’
and edit files. It provides an extra security later when you are connecting to
a remote machine.
The
app provides features like shared-key authentication, WiFi autostart whitelist,
extended notification control etc.,
Tuesday, January 19, 2016
Posted by Sivapriya


