The only magazine devoted exclusively to penetration testing.
May 24, 2013, 3:50 am

Launching Phishing and Spam attacks on Android with Customized Notifications – Free Artcile 11/2012

Launching Phishing and Spam attacks on Android with Customized Notifications - Free Artcile 11/2012

Launching Phishing and Spam attacks on Android with Customized Notifications – Free Artcile 11/2012


Launching Phishing and Spam attacks on Android with Customized Notifications

by Sencun Zhu and Zhi Xu

Existing notification service on Android is lack of view authentication information. Any installed app could abuse the notification service to launch phishing and spam notification attacks. Further, by customizing the displayed notifications carefully, the sender app can prevent being tracked by victim smartphone users.

Notification service is a popular system service provided by Android platform to third party apps. To facilitate the app development, Android allows the installed third party apps to send customized notifications while running in the background.

In this article, we show that it is feasible for an installed trojan app to launch both phishing and spam attacks using notification services while hiding it from being noticed by the phone user. For example, an installed trojan app may generate a fraudulent notification that mimics the Facebook notification and leads the user to a fraudulent login view that steals the Facebook account and passwords. Also, it can send annoying unsolicited ads anonymously without exposing its identity.

Free Artcile 11/2012Free Artcile 11/2012 - Free Article
Free Artcile 11/2012

Follow the steps below to download the magazine:
  1. Register, accept the Disclaimer and choose subscription option.
    Attention!
    By choosing the Free Account option you will only be able to download the teaser of each issue.
  2. Verify your account using the verification link sent to your email address.
  3. Check the password sent on your email address and use it to log in.
  4. Click the download button to get the issue.

IMPORTANT: the registration on the website includes subscription to our newsletter.
Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • LinkedIn
  • Facebook
  • MySpace
  • Google Bookmarks
  • BlinkList
  • MisterWong
  • Y!GG
  • Webnews
  • Digg
  • del.icio.us
  • StumbleUpon
  • YahooBuzz
  • Reddit
  • Wikio UK

Comments are closed.


Advertisement




Software Press Sp. z o.o. Sp. Komandytowa 02-682 Warszawa, ul. Bokserska 1, NIP 9512279582, REGON 141804060, KRS: 0000327578