Vulnerable Mobile Application in Google Store, Spoofs your identity & makes fake calls
By MYBRANDBOOK
Cybersecurity Researchers, GIS Consulting says, during their examination of several android mobile applications found that there are some free applications available on google play and app store which provide the facility to establish free calls over internet to users. Anyone possessing an android mobile phone can download this application for free and make free calls.
An application called "Call India - IntCall" provides the same service, and this application is available on google play as well as app store. Now, you might be thinking, what's strange in that. But this application has a very serious and dangerous flaw in it.
Application Does Not Require Any User Authentication Permission
As per Mr. Naveen Dham CEO & Founder of GIS Consulting, any person can simply download this application from google play store or app store, after getting downloaded, the application asks for registration, in which we can simply register by entering anyone’s phone number whom you want to spoof.
This is where the biggest flaw exists. As this application does not require any user permission from the owner of the phone number, a person can enter any 10-digit mobile number of anyone and get registered successfully without entering any OTP or any verification code.
.
The application can be used to make fraud calls to anyone using someone else’s caller identity number, as one can use any valid or invalid number to call someone without getting caught.With this the criminals can spoof your phone number to call your family members, friends, colleagues, employees, employers or bankers etc. to extort money or get critical information pertaining to you.
These type of applications should have been thoroughly checked by Google before putting them on play store which raises a big question on Google’s procedures followed to allow any new application to get uploaded on play store.
The strange thing is that the application is still not reported by anyone and freely available on internet.The application developers should implement OTP based authentication or any other type of user verification which verifies that the user is genuine.
This application can be used by not only hackers but also by fraudsters, extortionists and terrorists etc. for their benefit and can harm the society.
Immediate actions should be taken to remove this app from Google Store and remediation actions to be taken to restrict these kind of applications to be uploaded on play store.
InterGlobe’s Rahul Bhatia and C.P. Gurnani together announce
In a move that is set to transform the AI landscape, Rahul Bhatia, Group M...
Download masked Aadhaar to improve privacy
Download a masked Aadhaar from UIDAI to improve privacy. Select masking w...
Sterlite Technologies' Rs 145 crore claim against BSNL rejecte
An arbitrator has rejected broadband technology company Sterlite Technolog...
ID-REDACT® ensures full compliance with the DPDP Act for Indi
Data Safeguard India Pvt Ltd, a wholly-owned subsidiary of Data Safeguard ...
INFOSYS TECHNOLOGIES PVT. LTD.
TVS ELECTRONICS LTD.
MICROMAX INFORMATICS LTD.
DRUVA SOFTWARE PVT. LTD.
Technology Icons Of India 2023: B.V.R. Subrahmanyam
B.V.R. Subrahmanyam belongs to Andhra Pradesh. He is a 1987-batch IAS ...
Technology Icons Of India 2023: Hari Om Rai
Hari Om Rai is the Co-founder, Chairman & Managing Director of Lava In...
Technology Icons Of India 2023: Deepinder Goyal
Deepinder Goyal is the Founder and CEO of Zomato. Deepinder, or Deepi,...
PGCIL transforming India with its wide power transmission network
Engaged in power transmission, POWERGRID or PGCIL is a stated owned In...
GSTN aims to integrate indirect tax ecosystem on a shared IT infrastructure
Goods and Services Tax Network (GSTN) has built Indirect Taxation plat...
New defence PSUs will help India become self-reliant
MIL, India’s biggest manufacturer and market leader is engaged in Pr...
SONATA INFORMATION TECHNOLOGY LIMITED
Sonata Software Limited is a leading Modernization engineering company...
BEETEL TELETECH LTD.
: Beetel is one of the oldest and most reputed brands in the Industry,...
SATCOM INFOTECH PVT. LTD.
Satcom Infotech Pvt. Ltd is a distribution houses in security in India...