Can Hackers get access to your phones via backdoor?
By MYBRANDBOOK
Researchers of cybersecurity have discovered that a large number of mobile phone applications contain hard coded 'backdoor secrets' that allow hackers to access private data or block content provided by users.
“The research claims that the apps on mobile phones might have hidden or harmful behaviours about which end users know little to nothing," said study author Zhiqiang Lin from the Ohio State University in the US.
"Typically, mobile apps engage with users by processing and responding to user input. For instance, users often need to type certain words or sentences or click buttons and slide screens. Those input prompt an app to perform different actions," Lin added.
For this study, the team evaluated 150,000 apps. They selected the top 100,000 based on the number of downloads from the Google Play store, the top 20,000 from an alternative market, and 30,000 from pre-installed apps on Android smartphones.
They discovered that 12,706 of those apps, about 8.5%, contained something the research team labelled "backdoor secrets" - hidden behaviours within the app that accept certain types of content to trigger behaviours unknown to regular users.
They also found that some apps have built-in "master passwords," which allow anyone with that password to access the app and any private data contained within it. And some apps, they found, had secret access keys that could trigger hidden options, including bypassing payment.
"Both users and developers are all at risk if a bad guy has obtained these 'backdoor secrets,'. In fact, motivated attackers could reverse engineer the mobile apps to discover them," Lin said. According to the study, developers often wrongly assume reverse engineering of their apps is not a legitimate threat. "A key reason why mobile apps contain these 'backdoor secrets' is because developers misplaced the trust," said study lead author Qingchuan Zhao.
To truly secure their apps developers need to perform security-relevant user-input validations and push their secrets on the backend servers. In addition, the research team have developed an open-source tool, named InputScope, to help developers understand weaknesses in their apps and to demonstrate that the reverse engineering process can be fully automated. The study was accepted for publication by the 2020 IEEE Symposium on Security and Privacy in May. The conference has been moved online because of the global coronavirus (COVID-19) outbreak.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
VERSA NETWORKS INDIA PVT. LTD.
NUMERIC INDIA, A Group Brand Legrand
PDRL - Passenger Drone Research Pvt. Ltd.
LAVA INTERNATIONAL LTD.
ICONS OF INDIA : ROSHNI NADAR MALHOTRA
Roshni Nadar Malhotra is the Chairperson of HCLTech, a leading global ...
SHAKTIKANTA DAS
Shaktikanta Das is serving as the current & 25th governor of the Reser...
Icons Of India : Dilip Asbe
At present, Dilip Asbe is heading National Payments Corporation of Ind...
C-DAC - Centre for Development of Advanced Computing
C-DAC is uniquely positioned in the field of advanced computing...
IOCL - Indian Oil Corporation Ltd.
IOCL is India’s largest oil refining and marketing company ...
BSE - Bombay Stock Exchange
The Bombay Stock Exchange (BSE) is one of India’s largest and oldest...
Indian Tech Talent Excelling The Tech World - Rajiv Ramaswami, President & CEO, Nutanix Technologies
Rajiv Ramaswami, President and CEO of Nutanix, brings over 30 years of...
Indian Tech Talent Excelling The Tech World - Steve Sanghi, Executive Chair, Microchip
Steve Sanghi, the Executive Chair of Microchip Technology, has been a ...
Indian Tech Talent Excelling The Tech World - NIKESH ARORA, Chairman CEO - Palo Alto Networks
Nikesh Arora, the Chairman and CEO of Palo Alto Networks, is steering ...