Common mobile viruses:Mobile Security Threat



How they spread and what are the effects:

Cabir: When this virus infects  your mobile then  message 'Caribe' will be displayed  at each  time you switch off and  on the mobile. These worms are generally  spread through blue tooth signals from surroundings  mobiles. 
Duts: A parasitic  file infector virus .its alos  known as Pocket PC. It try to infect all EXE files which are more than 4kb present in the directory where it saved. 
Skulls:  it is a Trojan horse. Means a piece of code will be  downloaded  on your mobile nad then the virus called Skull replaces your phone desktop into  image of skull as icon.it is very dangerous as  It is usually  transferred with all phone applications and also with SMS and MMS. 
Comm warrior: It's also spread through MMS  and  unsecured blue tooth  to other devices. It has more impact on devices running under OS Symbian Series 60. This virus launches The executable worm file and the worm  hunt for gaining access to your blue tooth devices and sends the infected files under various different  name to various random device.

Mobile Security:How you will know your mobile is being tracked??

.HOW IT IS DONE
cell phone image by sonya etchison from Fotolia.com
 Mobile phones are always being tracked by the cell phone company. And it  is a necessity for provide you the facility to make  and receive phone calls.Mobile service provider can simply pinpoint the location where your mobile is by measuring the strength or weakness of the signal relative to there mobile towers.[sintuhack]. And With the help of  this, you can be traeced  within a few hundred feet. But what if your phone is tarcked by other than your service provider.[sintuhack].
Yes my friend , in this technical its world its possible that your phone are being traced by any other person/company (similarly like it is done in Hollywood movies). There are a lot of service provider for this types of spying on the internet.[sintuhack].
If you would like to know whether your phone is being tracked by someone other than the phone company there are a few signs on which you must pay attention.[sintuhack]
Points to ponder


Check to see if your phone is still warm in between phone calls. It  is normal for phones to heat up during a call, but they will usually cool down within 30 minutes after one. If your phone is still warm even when it has not been used in hours then it could still be transmitting, which is an indicator that it could be bugged.[sintuhack]


Check to see if your phone is interfering with the radio even when it is turned off. A cell phone bug will transmit your location at all times even when the phone is turned off. While it is normal for a phone to interfere with a radio when it is receiving or making a call, it is not normal if this happens when it is turned off.[sintuhack]


Check for signs that your battery is draining faster the normally. If the phone is bugged, you will notice that it drains much quicker than it would normally. This is because it is constantly transmitting even when it is off.[sintuhack]

Oberservation:

Pay  close attention on  these signs. if  one or two of them  are present then it may be possible that someone has bugged your phone, but  all three sign together ensures that there is a good chance that someone using some technology to track you.[sintuhack]

Solution:

The only way to keep from being tracked is to either remove the battery from your phone or to get the phone wiped clean at a phone shop and have them reinstall the operating system.[sintuhack]

Mobile security:Tips for using Bluetooth Securely

All  deficiencies(described in previuos post )  leave a Bluetooth device vulnerable to security threats. Even though security gaps are being filled every day by the manufacturer and technologist, Following are some of the tips that a normal user can keep in mind and protect himself from an amateur BlueTooth  security breacher.[sintuhack]
  • Keep BlueTooth   in the disabled state, enable it only when needed and disable immediately after the intended task is completed.[sintuhack]
  • Keep the device in non-discoverable (hidden) mode,[sintuhack]
  • DO NOT accept any unknown and unexpected request for pairing your device.[sintuhack]

  • Use non regular patterns as PIN keys while pairing a device. Use those key combinations which are non sequential, non obvious on the keypad.[sintuhack]
  • Keep a check of all paired devices in the past from time to time and delete any paired device which you are not sure about.[sintuhack]
  • Register your device at the Manufacturer site and insure that security updates are installed regularly to protect from previously know threat which had been rectified in new models.[sintuhack]
  • Always enable encryption when establishing Bluetooth connection to your PC.[sintuhack]
Above Bluetooth Security Tips should make your Bluetooth experience trouble free. Good Luck…!!! And that’s the end of chapter on bluetooth.[sintuhack].

Bluetooth Security Risks:MOBILE SECURITY



Bluetooth Security Risks
1. The first step in using any Bluetooth device is to turn on the Bluetooth feature in it. The default state of Bluetooth in any device is “Off” mode. 
2. Once Bluetooth is turned on, it is in active but dormant state. In order to use it, it needs to be put in to “Discoverable” state. In theory when a device is in “non discoverable” state it should not be visible to other devices but in reality the device is still discoverable to those devices it has made a connection before using MAC address. A hacker seeing the Blue LED can use Brute Force address discovery process to record the MAC address and hack the device using software such as RedFang.


3. During communication process also Bluetooth technology exposes itself to security breach as the address itself is not encrypted although the message may be encrypted. Technique such as frequency hogging provides some protection but is not completely secure.
4. There are devices available in the market which can capture a Bluetooth signal from the air and analyze. At present cost is prohibitive for casual hackers to acquire some of these devices but still a professional hacker can use those devices and hack vital information.
5. Many owners leave the Bluetooth device in the discoverable mode after actual use due to ignorance or simply forget to turn off “discoverable” mode which gives hackers easy opportunity to pair with their device and hack.
6. Pairing two Bluetooth devices usually does not require any authentication, however using a service like file transfer or data/video/voice exchange require some authentication by entering PIN. Once PINs are entered a link key is generated and stored in the device’s memory. This process is not required for next time onwards.
7. Many vendors do not implement authentication and authorization process correctly allowing hackers to steal information or use one’s phone or use it for making calls or SMS.

BLuebugging:Can Breach YOUR Mobile Security



BLuebugging was somewhat like bluesnarfing but the difference is that it is more harmful to your mobile from the prospective of security of your mobile. It was first invented in 2004 by German scientist. In the initial phase, it was necessary to pair devices via Bluetooth before the security breacher  try to breach your mobile with the bugger, but now a days its not needed to pair up the devices.[sintuhack]. It can also possible to break you mobile security via the Bluetooth enabled headset which is used to take call as per to free your hands.[sintuhack]

At early stage it was done with laptop but now a days such powerful PDA and mobile phones are available  in the market that it can be done without laptops .[sintuhack]. you may be happy that your mobile Bluetooth has only a small range so its not easy to pair up your device hence you mobile is secured. But did you know that in market antenna’s are available which can send and receive weak signal s and hence data can be transferred from range of even 200 meters.[sintuhack]

Bluesnarfing:Mobile Security Breach

Bluesnarfing refers to a the method in which one has gained access to data, which is stored on a Bluetooth enabled phone of other people.
Literally Bluesnarfing can be described as unauthorized access of information from a wireless device through a Bluetooth connection. The level of access depends from case to case, but, in general, it involves pretty much anything that's stored on the user's mobile device.
Bluesnarfing allows the using person to make phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations, and connect to the Internet. he can also download the material in his mobile from the victim mobile.
The good news is, bluesnarfing requires advanced equipment and much advanace expertise


In this field. As bluejacking can be done at the range of 10 meters, in bluesnarfing the intruder must be present within a 30 ft. range.
If the phone is in non-discoverable mode, then its not true that you cant be a victim of this.
Its adds only some problem and makes it little bit more difficult for intruders to bluesnarf your phone.


It can be possible from phone and laptop both to bluesnarf a mobile. By just using some bluesnarfing tools (Bluesnarfer, Blooover)

on mobile phone or laptop, anyone can detect and access those vulnerable mobile phones to view and download entire phonebook, calendar, real time clock, business card and other important private data without alerting the phone owner(you).




There's little info on whether Bluesnarfing is possible without the targeted phone being paired with the computer running the aforementioned software application, but anyone cannot completely rule out this possibility, either.


So that’s all about bluesnarfing. Wait till next post to know about other mobile security breach methods………….

Mobile hacking via blutooth

In this post i will tell  you how actually  mobile phones are get hacked  . i will describe it step by step that how mobile get hacke but plz don’t utilize it and try . If you will try then it will your responsibility.


I mainly describe the process  of Bluejacking .
  
Friends there is a bluetooth hacking software , using bluetooth hacking software anyone can “hack any cell phones”
 the latest version of this software is Bluetooth Hack v 1.07.
anyone can easly download it from any file sharing site.
Like  Download via RapidSahre: http://rapidshare.com/files/XXXXXXX/Superbluetoothhack.zip






Disadvantages of this software.


if  anyone get connected to your phone via bluetooth :
- he can read your messagess
- he can read your contactss
-he can play your songs from your mobile 

- he can also play his/her ringtones even your phone is in silent
- he can switch off your mobile –

-he can change your profile
-he can restart his/her mobile
-he can restore your factory setings
- he can also change ringing volume of your mobile..

  - the worst  part of it is he can call from your mobile which also includes all call functions like hold on etc etc..



Mobile phone hacking work according to following   steps .
  • He will Go to Contacts.
  •  And will Create a new contact.
  • He will Write the short message he want to send on the line next to 'Last name'
  • And Save this contact.
  • Now he will Select your contact and send via Bluetooth because your bluetooth is on and you donot know about it.
  • His  phone will search for devices and that software will found your mobile.
  • He will Select any one  like you  and will  send.
  • Now Your phone  have been  bluejacked by someone.


This software is very much suitable for sony ericcsson and few Nokia mobiles.
So user of it be aware..
Warning this is only For educational purposesif any one use it it will totaly his resposiblity.




In next post i will describe others methods of  bluethooth hacking.

MOBILE HACKING:BLUTOOTH HACKING

Bluetooth is a very common thing for mobile technology and used frequntly by user to tranfer data. But as frequent they transfer the data , less they put attention on security . Even most of them donot think about  that their mobile can be hacked via blutooth.
So now from today i am going to describe about blutooth hackings and security and it will continue in upcoming post.

Bluejacking, Bluesnarfing, Bluebugging and Bluetoothing are the main type of bluetooth hacks.


Bluejacking is the simplest of the four.  It is an attempt to send a phone contact or business card to another nearby phone. The ‘name' field of the contact can be misused by replacing it with a suggestive text so that the target device reads it as a part of intimation query displayed on its screen. Tis is somewhat equivalent to spam e-mail because both are unsolicited messages displayed on recipients' end without consent, and by exploiting the inherent nature of communication.
These are the softwares available in the market which help in bluetooth hacking.


BlueScanner - It hunts out for Bluetooth devices and dig out much amount of information of the newly discovered device.

BlueSniff - Utility for discovering hidden Bluetooth devices.

BlueBugger -It simply exploits the BlueBug vulnerability of the bluetooth enabled devices. By exploiting these vulnerabilities and leakes, you can gain access to the phone-book, calls lists and other information of the bluetooth device.

BTBrowser - Is a Bluetooth Browser is a J2ME app. which can browse and explore all the surrounding Bluetooth devices.

BTCrawler -It is a Bluetooth scanner for Windows Mobile based devices. It can implement BlueJacking and BlueSnarfing attacks.


In the next post i will describe how hackers actually  use these softwares for the hacking..........

How does anti-virus software work?The Working mechanism of antivirus

An anti-virus software program is a computer program that can be used to scan files to identify and eliminate computer viruses and other malicious software (malware).......................

    * Examining files to look for known viruses by means of a virus   dictionary
    * Identifying suspicious behavior from any computer program    which might indicate infection


Most commercial anti-virus software uses both of these approaches, with an emphasis on the virus dictionary approach.

Virus dictionary approach
In the virus dictionary approach, when the anti-virus software examines a file, it refers to a dictionary of known viruses that have been identified by the author of the anti-virus software. If a piece of code in the file matches any virus identified in the dictionary, then the anti-virus software can then either delete the file, quarantine it so that the file is inaccessible to other programs and its virus is unable to spread, or attempt to repair the file by removing the virus itself from the file.

To be successful in the medium and long term, the virus dictionary approach requires periodic online downloads of updated virus dictionary entries. As new viruses are identified "in the wild", civically minded and technically inclined users can send their infected files to the authors of anti-virus software, who then include information about the new viruses in their dictionaries.

Dictionary-based anti-virus software typically examines files when the computer's operating system creates, opens, and closes them; and when the files are e-mailed. In this way, a known virus can be detected immediately upon receipt. The software can also typically be scheduled to examine all files on the user's hard disk on a regular basis.

Although the dictionary approach is considered effective, virus authors have tried to stay a step ahead of such software by writing "polymorphic viruses", which encrypt parts of themselves or otherwise modify themselves as a method of disguise, so as to not match the virus's signature in the dictionary.

Suspicious behavior approach
The suspicious behavior approach, by contrast, doesn't attempt to identify known viruses, but instead monitors the behavior of all programs. If one program tries to write data to an executable program, for example, this is flagged as suspicious behavior and the user is alerted to this, and asked what to do.

Unlike the dictionary approach, the suspicious behavior approach therefore provides protection against brand-new viruses that do not yet exist in any virus dictionaries. However, it also sounds a large number of false positives, and users probably become desensitized to all the warnings. If the user clicks "Accept" on every such warning, then the anti-virus software is obviously useless to that user. This problem has especially been made worse over the past 7 years, since many more nonmalicious program designs chose to modify other .exes without regards to this false positive issue. Thus, most modern anti virus software uses this technique less and less.

Other ways to detect viruses
Some antivirus-software will try to emulate the beginning of the code of each new executable that is being executed before transferring control to the executable. If the program seems to be using self-modifying code or otherwise appears as a virus (it immeadeatly tries to find other executables), one could assume that the executable has been infected with a virus. However, this method results in a lot of false positives.

Yet another detection method is using a sandbox. A sandbox emulates the operating system and runs the executable in this simulation. After the program has terminated, the sandbox is analysed for changes which might indicate a virus. Because of performance issues this type of detection is normally only performed during on-demand scans.

Issues of concern

Macro viruses, arguably the most destructive and widespread computer viruses, could be prevented far more inexpensively and effectively, and without the need of all users to buy anti-virus software, if Microsoft would fix security flaws in Microsoft Outlook and Microsoft Office related to the execution of downloaded code and to the ability of document macros to spread and wreak havoc.

User education is as important as anti-virus software; simply training users in safe computing practices, such as not downloading and executing unknown programs from the Internet, would slow the spread of viruses, without the need of anti-virus software.

Computer users should not always run with administrator access to their own machine. If they would simply run in user mode then some types of viruses would not be able to spread.

The dictionary approach to detecting viruses is often insufficient due to the continual creation of new viruses, yet the suspicious behavior approach is ineffective due to the false positive problem; hence, the current understanding of anti-virus software will never conquer computer viruses.

There are various methods of encrypting and packing malicious software which will make even well-known viruses undetectable to anti-virus software. Detecting these "camouflaged" viruses requires a powerful unpacking engine, which can decrypt the files before examining them. Unfortunately, many popular anti-virus programs do not have this and thus are often unable to detect encrypted viruses.

Companies that sell anti-virus software seem to have a financial incentive for viruses to be written and to spread, and for the public to panic over the threat. 

Why You Need Intrusion Detection

Expert Advice on Keeping Your Network Safe by Blocking Dangerous Hacker Attacks
The stories go on and on about another individual having their personal information stolen from their computer by some hacker. While it is true that hackers do get people's information, and they will keep on getting that information,
it is also true that having intrusion detection software can help. And even better, to be hacker safe intrusion prevention system is by the same software.
Why You Need Intrusion Detection
Doors can be opened to hackers in varied ways. Two of the most common ways by which they can gain access to your computer is simply through emails, or Web pages that you visit that have spyware, or trojans (a file which looks innocent, but actually will later open doors to a hacker) attached to them. Other ways are robot spiders sent out over the Internet to find unprotected computers, and open doors. Some say that every computer attached to the Internet may be attacked by such a spider as many as 50 times each day. So, if you do not have an intrusion prevention system in place, up-to-date, then you may have regular unexpected visitors - and you may not even know it. Others say that 9 out of 10 computers have some sort of spyware, or malware on them. Could you be one of them? This article will show you what is available on the market for your protection - and much of it can be obtained for free.

The spider robots work automatically - looking for and identifying computers on the Internet that have doors, or ports, open to them. This information is then reported back to the hacker - knowing which computers to target - and which port to use. For this reason, every now and then, Microsoft will come out with a new patch for Windows, in order to close some faulty door that hackers have discovered and been using.
What Is Intrusion Detection?
Network Intrusion detection software is a must-have these days. Each company's software will vary somewhat (for copyright and originality purposes), but you do need one for your own network, or home computer. It differs from a firewall in that the purpose of a firewall is to stop unauthorized external contacts with your system. These offer hacker prevention largely for contacts from outside the network. Most of these will now notify the owner or network controller of intrusion attempts. Network intrusion detection systems, on the other hand, will give you warnings about events that take place within the network itself.