FBI發(fā)布安卓安全警告
????希望讓產(chǎn)品進(jìn)入iOS App Store的軟件開(kāi)發(fā)者們經(jīng)常報(bào)怨蘋(píng)果(Apple)在他們頭上強(qiáng)加了各種條條框框,不過(guò)蘋(píng)果這樣做也是有原因的。除了要拿到30%的收入分成之外,還有一個(gè)原因,可以從上周五美國(guó)聯(lián)邦調(diào)查局互聯(lián)網(wǎng)犯罪舉報(bào)中心(FBI’s Internet Crime Complaint Center)發(fā)布的警告中看出來(lái)。 ????警告開(kāi)篇寫(xiě)道:“FBI互聯(lián)網(wǎng)犯罪舉報(bào)中心了解到,近期有大量惡意軟件在攻擊安卓(Android)系統(tǒng)的移動(dòng)設(shè)備。最新為人所知的兩個(gè)此類惡意軟件叫做Loozfon和FinFisher。 ?????Loozfon是一個(gè)盜取信息的惡意軟件。犯罪份子利用這個(gè)軟件的各種偽裝來(lái)欺騙受害者。其中一個(gè)偽裝就是提供一個(gè)在家工作的機(jī)會(huì),稱用戶只需在家里發(fā)發(fā)電子郵件,就能賺到不少錢(qián)。這種虛假?gòu)V告一般都有一個(gè)鏈接,會(huì)自動(dòng)轉(zhuǎn)到一個(gè)惡意網(wǎng)站上,將Loozfon軟件推送到用戶的設(shè)備上。該惡意應(yīng)用會(huì)從用戶的電話簿里竊取聯(lián)系信息,同時(shí)也會(huì)偷到受感染設(shè)備的電話號(hào)碼。 ?????FinFisher是一個(gè)能控制移動(dòng)設(shè)備的間諜軟件。安裝后,無(wú)論目標(biāo)在何處,黑客都可以通過(guò)FinFisher對(duì)該移動(dòng)設(shè)備進(jìn)行遠(yuǎn)程監(jiān)控和控制。FinFisher可以藏身在特定的網(wǎng)頁(yè)鏈接里,也可以偽裝成一條系統(tǒng)升級(jí)短信。只要用戶點(diǎn)開(kāi)它,它就會(huì)輕而易舉地直入到智能手機(jī)里。 ????FBI給三星(Samsung)、摩托羅拉(Motorola)和HTC等運(yùn)行谷歌(Google)安卓系統(tǒng)的智能手機(jī)機(jī)主提出了以下建議: ?????購(gòu)買(mǎi)智能手機(jī)時(shí),要了解這款設(shè)備的功能,包括默認(rèn)設(shè)置。盡量關(guān)閉不必要的功能,將遭受攻擊的可能性降到最小。 ?????根據(jù)手機(jī)的類型,有些操作系統(tǒng)可以進(jìn)行加密。手機(jī)丟失或被盜時(shí),加密程序可以保護(hù)機(jī)主的個(gè)人信息。 ?????移動(dòng)應(yīng)用日益增長(zhǎng),用戶們?cè)谙螺d應(yīng)用前應(yīng)該看看開(kāi)發(fā)者或開(kāi)發(fā)公司的評(píng)測(cè)文章。 ?????下載應(yīng)用的時(shí)候,先看看需要向這個(gè)應(yīng)用開(kāi)放哪些權(quán)限。 ?????密碼可以保護(hù)移動(dòng)設(shè)備,它也是保護(hù)移動(dòng)設(shè)備中的內(nèi)容的第一層實(shí)體堡壘。除了使用密碼之外,還應(yīng)開(kāi)啟自動(dòng)鎖屏功能,讓手機(jī)待機(jī)幾分鐘后就自動(dòng)鎖屏。 ?????用惡意軟件防護(hù)程序來(lái)保護(hù)移動(dòng)設(shè)備。不少專門(mén)的防護(hù)軟件都可以保設(shè)備免遭流氓程序和惡意軟件的侵害。 ?????當(dāng)心那些需要共享地理位置的應(yīng)用,因?yàn)樗鼈儠?huì)追蹤用戶的地理位置。這種應(yīng)用可能被用作營(yíng)銷(xiāo)之用,但也有可能用于違法活動(dòng),比如跟蹤或盜竊。 |
????Developers often complain about the hoops Apple (AAPL) makes them jump through to get their wares into the iOS App Store. But the company has its reasons -- besides its 30% cut of the revenue -- and one of them was illustrated by the warningissued Friday by the FBI's Internet Crime Complaint Center (IC3). ????"The IC3 has been made aware of various malware attacking Android operating systems for mobile devices," it begins. "Some of the latest known versions of this type of malware are Loozfon and FinFisher." ?????Loozfon is an information-stealing piece of malware. Criminals use different variants to lure the victims. One version is a work-at-home opportunity that promises a profitable payday just for sending out email. A link within these advertisements leads to a website that is designed to push Loozfon on the user's device. The malicious application steals contact details from the user's address book and the infected device's phone number. ?????FinFisher is a spyware capable of taking over the components of a mobile device. When installed the mobile device can be remotely controlled and monitored no matter where the Target is located. FinFisher can be easily transmitted to a Smartphone when the user visits a specific web link or opens a text message masquerading as a system update. ????For owners of smartphones running on Google (GOOG) Android platform -- including those made by Samsung, Motorola and HTC -- the Bureau offer these safety tips: ?????When purchasing a Smartphone, know the features of the device, including the default settings. Turn off features of the device not needed to minimize the attack surface of the device. ?????Depending on the type of phone, the operating system may have encryption available. This can be used to protect the user's personal data in the case of loss or theft. ?????With the growth of the application market for mobile devices, users should look at the reviews of the developer/company who published the application. ?????Review and understand the permissions you are giving when you download applications. ?????Passcode protect your mobile device. This is the first layer of physical security to protect the contents of the device. In conjunction with the passcode, enable the screen lock feature after a few minutes of inactivity. ?????Obtain malware protection for your mobile device. Look for applications that specialize in antivirus or file integrity that helps protect your device from rogue applications and malware. ?????Be aware of applications that enable Geo-location. The application will track the user's location anywhere. This application can be used for marketing, but can be used by malicious actors raising concerns of assisting a possible stalker and/or burglaries. |