Android

Android device migration

The exchange of smartphones has a significant complication in transferring data to the new device. To overcome this problem, Cloning applications were introduced to overcome this problem, which will clone the entire device to the new one. This includes applications, photos, personal data, mail accounts, and even session data of applications. However, CloudSEK’s researchers found that many applications do not invalidate or revalidate the session after this data migration to a new device. Threat actors are aware of this and use this lack of validation with highly privileged migration tools to copy to their devices, which can result in impersonation. As per the migration experiment conducted by CloudSEK, WhatsApp transferred the secret keys to the new device, which resulted in the application not asking for 2FA. “Researchers conducted an experiment using two Realme devices. After the data was transferred from the victim’s device to the attacker’s device, the two applications (Whatsapp and Whatsapp Business) were accessible on both devices via the same account.” Even though the victim had activated WhatsApp 2FA, it wasn’t asked on the new (attacker’s) device, and now both devices could send messages via the same account. However, the replies from the user on the other end will only be received on the device which sent the last message. A threat actor gaining access to this kind of vulnerability can impersonate a person and WhatsApp and send messages on the victim’s behalf. Once the migration is completed, WhatsApp will receive messages on the device to which the last message was sent. In such cases, the victims will only be able to know if they log on to Web WhatsApp and look for conversations. Threat actors can bypass this easily if they delete the messages. Meta owns WhatsApp. However, the same Meta-owned Instagram did not have this vulnerability, as it logged out all accounts when migrated to a new device. As these applications do not invalidate or revalidate session cookies, threat actors can manipulate victims into installing Stealer Log malware that records users’ activities and sends them back to their servers which can be used to gain unauthorized access to victims’ accounts. Once attacker steals the cookies not validated by the applications, they can use anonymous browsers to use stolen cookies resulting in the impersonation of network location and GPS. Checking for unusual activity on their accounts and their device Keeping the device locked when not in use Do not leave the devices in the public places Enable Two-factor authentication for the applications. Read the rest of this exclusive interview in our latest issue here. Never miss a story… Follow us on:  Security Buyer  @SecurityBuyer  @Secbuyer Media Contact Rebecca Morpeth Spayne, Editor, Security Portfolio Tel: +44 (0) 1622 823 922 Email: editor@securitybuyer.com

Android device migration Read More »

Will MazarBOT be the straw that breaks Android’s back?

That’s according to Jan Vidar Krey, Head of Development at Norwegian app security firm Promon, who found the most alarming part of the malware was not its ability to penetrate and compromise an Android device, but that the existence of this strain was not protected against since it was first identified on the Dark Web several months ago.

Will MazarBOT be the straw that breaks Android’s back? Read More »

Ubiqz adds Y-cam to further expand IP camera range

Specialist security distributor adds Y-cam IP cameras to its portfolio, enhancing its offering of affordable surveillance to small business & residential customers Ubiqz, the specialist security division of the Midwich Group, has today announced a new and exciting distribution agreement with Y-cam Solutions Ltd, a UK-based manufacturer of innovative IP network cameras and software solutions. Y-cam is the second major manufacturer that Ubiqz has signed in as many weeks and follows a similar agreement with Exacq Technologies. The addition of Y-cam gives Ubiqz access to another strong IP camera brand that is positioned as an easier to use and more affordable surveillance solution, with several uniques in the industry. These include full compatibility and support for Apple Mac platforms, a suite of smartphone apps, more attractive looks better suited for residential or hospitality applications, and a simpler and more concise product range providing multiple installation options. Commenting on the deal, Anand Subbiah, General Manager at Ubiqz, said: “We’re delighted to add Y-cam to our growing portfolio of industry leading security brands. These IP cameras are absolutely ideal for small business and residential security purposes but they are also suitable for retail, industrial and other commercial applications. All Y-cam cameras are compatible with free apps for iPhone, Android and Blackberry and come with setup software to simplify installation, plus free MultiLive multi-camera viewing software. We will be demonstrating selected IP cameras from the Y-cam range at the upcoming IFSEC show on Stand 20 in Hall 4.” “We’re very excited by the new partnership with Ubiqz,” commented Simon Carr, Head of Sales for Y-cam, “we believe that the addition of Y-cam products to the Ubiqz portfolio will help them attract, and make it easier for, security installers to move from yesterdays analogue technology to today’s higher quality digital surveillance systems, providing more flexible, powerful and upgradeable solutions for customers.” Y-cam will be demonstrating its extensive range of IP cameras, including its new Y-cam EyeBall mini-dome, on the Ubiqz stand in Hall 4 (stand 4/H20) at IFSEC between the 16th and 19th May at the NEC, Birmingham UK. About Y‐cam Solution Ltd Y‐cam is a British manufacturer of affordable and easy‐to‐use remote monitoring solutions designed for residential and small‐to-medium-sized business users. Founded in 2005, Y‐cam is a young and dynamic company with rapid growth and award‐winning products, with strong strength in wireless security. For more information visit http://www.y‐cam.com About Ubiqz Limited Ubiqz is a specialist trade-only distributor of security products based in the UK. With a respected and proven track record, Ubiqz provides solutions in both analogue and IP security, supported by the leading brands in the security industry. As a trading division of the Midwich Group, Ubiqz offers competitive pricing, specialist technical support and comprehensive after-sales service. Ubiqz can offer its customers a reliable next day delivery service throughout the UK and to most European destinations from its two state of the art warehouses. Ubiqz sells branded products into Europe and has a growing client base in the EMEA region. For more information, visit www.ubiqz.com. About Midwich Midwich is the UK’s leading trade-only distributor of AV, IT and consumer electronics technology products. Midwich was named Specialist Distributor of the Year at the Channel Awards 2004, 2005, 2006, 2007, 2008 and 2009, and AV Distributor of the Year at the AV Awards 2003, 2006, 2008 and 2009. Midwich won the Microscope ACE Award for AV Distributor of the Year 2008, 2009 and 2010 and Logistics Team of the Year 2010. The business is currently ranked 174 on the Times Top Track 250 of private mid-market companies. To find out more, visit www.midwich.com.

Ubiqz adds Y-cam to further expand IP camera range Read More »

Scroll to Top