Page 1 of 2 12 LastLast
Results 1 to 20 of 28

Thread: Malware for android creates a 3d map of your home.

  1. #1
    Plutonium sonatine's Avatar
    Reputation
    7376
    Join Date
    Mar 2012
    Posts
    33,435
    Load Metric
    68114418

    Malware for android creates a 3d map of your home.

    http://nakedsecurity.sophos.com/2012...s-of-your-home



    Researchers say that they have created a malicious Android application that uses the phone’s embedded camera and other spatial sensors to create 3D visual maps of the owner’s home and other spaces.

    The proof of concept malware, dubbed PlaceRaider, was designed by researchers working for the U.S. Navy and the University of Indiana.

    Running on Android mobile devices, it was designed to call attention to the ways that rapidly evolving mobile platforms might enable new forms of virtual theft.

    Writing in a paper (pdf) published Thursday, the researchers said more powerful phones have created an opening for what they dub “sensory malware” that leverages the growing number of on-board sensors in the latest model mobile phones like the iPhone 5 and Android devices.

    To prove their point, the researchers created PlaceRaider to demonstrate how remote hackers could construct “rich three-dimensional (3D) models of the smartphone’s owner’s personal indoor spaces”.

    The malware uses a phone’s embedded sensors such as its GPS and accelerometer to determine when the victim was moving within the space. The onboard camera was then used to opportunistically snap shots of interior spaces and transfer them to a remote server which then assembles them to form a 3D model of the space.

    Placeraider image

    Androids were particularly well-suited for the task. The authors noted, with surprise, that the Android API doesn’t require any special permissions for an application to access sensor data on the phone, such as the accelerometer or gyroscope.

    And users could easily be tricked into granting those permissions that were needed – such as to access the camera or write to local storage – by bundling PlaceRaider into a camera app, the authors said.

    In a test, the researchers installed PlaceRaider on a subject’s phone and tracked their movements and the spaces they occupied.

    Researchers tested the ability of the application to export large quantities of data, and of the test subjects to then use that data to snoop on occupants: zooming in to observe the content of information displayed on computer screens or papers in the target’s home or workplace, according to the research report.

    PlaceRaider and other malicious “sensory” applications like it are well within the capabilities of modern phones and modern malware authors.

    Eye spy, courtesy of ShutterstockHowever, they did have to clear some technical hurdles in implementing it. Heuristic sensors were needed to weed out junk photos that didn’t reveal any new information about a space and the volume of data collected by the malware is large enough that it could overwhelm a phone. That required the authors to create a way for PlaceRaider to automatically compress the data it was transmitting.

    In addition to the malware, the authors also created tools to exploit the data the application collects. For example: they built a tool that would allow attackers to visually navigate a victim’s 3D space and zoom in on areas that might contain sensitive information. The phone could then be instructed to retrieve new, high resolution images of those spaces.

    The authors recommend a number of changes to smartphones to make malware like PlaceRaider harder to implement.

    Android and iOS devices could require permissions to access sensor data, and could alert users when applications appear to be using sensors – including the camera – in surreptitious ways.

    Even small changes would have made it harder for PlaceRaider to achieve its goals. For example: phone makers might require physical interaction with the phone to operate the camera, or make it impossible to take a photo without the shutter sound.

  2. #2
    Gold LLL's Avatar
    Reputation
    203
    Join Date
    Mar 2012
    Location
    Karen Ave.
    Posts
    2,354
    Load Metric
    68114418
    How effective would any malware like this be if GPS is off 99% of the time?
    "You run into an asshole in the morning, you ran into an asshole; you run into assholes all day, you're the asshole."

  3. #3
    Gold 408Mike's Avatar
    Reputation
    7
    Join Date
    Mar 2012
    Location
    Own a dying world
    Posts
    2,333
    Load Metric
    68114418
    Quote Originally Posted by LLL View Post
    How effective would any malware like this be if GPS is off 99% of the time?
    I dunno, by all means be the first guinee pig if your curiosity is so insatiable.

  4. #4
    Welcher jsearles22's Avatar
    Reputation
    561
    Join Date
    Mar 2012
    Posts
    6,690
    Load Metric
    68114418
    Quote Originally Posted by 408Mike View Post
    Quote Originally Posted by LLL View Post
    How effective would any malware like this be if GPS is off 99% of the time?
    I dunno, by all means be the first guinee pig if your curiosity is so insatiable.

    Someone shop Mike FTW:

    It's hilarious that we as a society think everyone can be a dr, a lawyer, an engineer. Some people are just fucking stupid. Why can't we just accept that?

  5. #5
    Diamond shortbuspoker's Avatar
    Reputation
    863
    Join Date
    Mar 2012
    Posts
    5,047
    Load Metric
    68114418
    sounds familiar just achieved by different technology


  6. #6
    Bronze realchaser74's Avatar
    Reputation
    15
    Join Date
    Apr 2012
    Posts
    125
    Load Metric
    68114418
    While it is true that Android apps do not need permissions granted to access the gyro and such you will always need to grant permissions to have it access other items like the data connection as well as the camera. For those that have android take a look at your youtube app and if it is update unistall the update the goo back in and update the app this time stopping at the permission screen and see that you need to grant it access.

    Name:  SC20121002-185554.png
Views: 480
Size:  68.4 KB
    Here is a screen shot of the permission you grant it. now I for one read the permission since I work in the industry and i never grant permission like this as well as letting apps have access to the data and personal info without knowing why

  7. #7
    Plutonium sonatine's Avatar
    Reputation
    7376
    Join Date
    Mar 2012
    Posts
    33,435
    Load Metric
    68114418
    Quote Originally Posted by realchaser74 View Post
    While it is true that Android apps do not need permissions granted to access the gyro and such you will always need to grant permissions to have it access other items like the data connection as well as the camera. For those that have android take a look at your youtube app and if it is update unistall the update the goo back in and update the app this time stopping at the permission screen and see that you need to grant it access.

    Name:  SC20121002-185554.png
Views: 480
Size:  68.4 KB
    Here is a screen shot of the permission you grant it. now I for one read the permission since I work in the industry and i never grant permission like this as well as letting apps have access to the data and personal info without knowing why

    any device that requires user interaction via software might as well have no safeguard at all. once administrative controls are breached, emulating an "ok" click is trivial.

    see the bottom few sentences where they address exactly that weakness and suggest how a hardware switch is necessary to suppress any component.

  8. #8
    Gold gauchojake's Avatar
    Reputation
    584
    Join Date
    Mar 2012
    Location
    Zipolite
    Posts
    2,450
    Load Metric
    68114418
    odds 408 gets this malware -10000000000000000000000000000000000000000000



    This actually sounds like something the government would like to have it's grubby little hands on.

  9. #9
    *** SCAMMER *** Jasep's Avatar
    Reputation
    2
    Join Date
    Mar 2012
    Location
    @VegasPokerRadio
    Posts
    1,630
    Load Metric
    68114418
    Sonatine, do you think we will have surrogates style technology in the next 50 years?

  10. #10
    Gold 408Mike's Avatar
    Reputation
    7
    Join Date
    Mar 2012
    Location
    Own a dying world
    Posts
    2,333
    Load Metric
    68114418
    Quote Originally Posted by gauchojake View Post
    odds 408 gets this malware -10000000000000000000000000000000000000000000



    This actually sounds like something the government would like to have it's grubby little hands on.
    Not in this lifetime pal.

    Now, odds that I will use something like this on someone, eh, whose to say?

    I wouldn't bet against it personally.

  11. #11
    Platinum Muck Ficon's Avatar
    Reputation
    532
    Join Date
    Mar 2012
    Posts
    3,721
    Load Metric
    68114418
    Quote Originally Posted by 408Mike View Post
    Quote Originally Posted by gauchojake View Post
    odds 408 gets this malware -10000000000000000000000000000000000000000000



    This actually sounds like something the government would like to have it's grubby little hands on.
    Not in this lifetime pal.

    Now, odds that I will use something like this on someone, eh, whose to say?

    I wouldn't bet against it personally.
    I can't believe a guy like you is single.
    Quote Originally Posted by Baron Von Strucker View Post
    Quote Originally Posted by kmksmkn View Post
    Does anybody know if u can get a work visa for playing online poker in the UK
    I have had Issues with credit cards in Europe
    Quote Originally Posted by Tyde View Post
    you're more consumed with accumulating wealth than achieving spiritual enlightenment
    Quote Originally Posted by tgull View Post
    Getting a little surf and turf tonight. In my world that is Sea Bass with a nice lobster tail on the side. And grilled asparagus. It's nice having money.

  12. #12
    Gold gauchojake's Avatar
    Reputation
    584
    Join Date
    Mar 2012
    Location
    Zipolite
    Posts
    2,450
    Load Metric
    68114418

  13. #13
    Gold Anal_Hershiser's Avatar
    Reputation
    67
    Join Date
    Jul 2012
    Posts
    2,099
    Load Metric
    68114418
    Quote Originally Posted by 408Mike View Post
    Quote Originally Posted by gauchojake View Post
    odds 408 gets this malware -10000000000000000000000000000000000000000000



    This actually sounds like something the government would like to have it's grubby little hands on.
    Not in this lifetime pal.

    Now, odds that I will use something like this on someone, eh, whose to say?

    I wouldn't bet against it personally.
    You mean "who's". Not quite sure why you think you are some expert computer hacker or malware expert. I wouldn't trust you with a sack of potatoes, let alone allow you to work on my computer. Please leave these discussions to people like Sonatine. Your room temperature IQ comments simply clutter up the thread, and make it difficult for people to get information because they are are constantly bukkaked with your gibberish.
    Quote Originally Posted by 408Mike View Post
    Vegas is there any chance I can buy you some steaks and mail them to you or something?
    Quote Originally Posted by Lord of the Fraud View Post
    I do believe Iraq was a huge mistake
    Quote Originally Posted by Lord of the Fraud View Post
    Why the fuck is the world (cough US) allowing these backward fuckers have nukes.

  14. #14
    Gold 408Mike's Avatar
    Reputation
    7
    Join Date
    Mar 2012
    Location
    Own a dying world
    Posts
    2,333
    Load Metric
    68114418
    Quote Originally Posted by Anal_Hershiser View Post
    Quote Originally Posted by 408Mike View Post

    Not in this lifetime pal.

    Now, odds that I will use something like this on someone, eh, whose to say?

    I wouldn't bet against it personally.
    You mean "who's". Not quite sure why you think you are some expert computer hacker or malware expert. I wouldn't trust you with a sack of potatoes, let alone allow you to work on my computer. Please leave these discussions to people like Sonatine. Your room temperature IQ comments simply clutter up the thread, and make it difficult for people to get information because they are are constantly bukkaked with your gibberish.
    My faithful sidekick, I have something special lined up for you

    oh yes I do...

  15. #15
    Gold 408Mike's Avatar
    Reputation
    7
    Join Date
    Mar 2012
    Location
    Own a dying world
    Posts
    2,333
    Load Metric
    68114418
    tine check pm's

  16. #16
    Gold Anal_Hershiser's Avatar
    Reputation
    67
    Join Date
    Jul 2012
    Posts
    2,099
    Load Metric
    68114418
    Quote Originally Posted by 408Mike View Post
    Quote Originally Posted by Anal_Hershiser View Post

    You mean "who's". Not quite sure why you think you are some expert computer hacker or malware expert. I wouldn't trust you with a sack of potatoes, let alone allow you to work on my computer. Please leave these discussions to people like Sonatine. Your room temperature IQ comments simply clutter up the thread, and make it difficult for people to get information because they are are constantly bukkaked with your gibberish.
    My faithful sidekick, I have something special lined up for you

    oh yes I do...
    I'm paralyzed with fear.
    Quote Originally Posted by 408Mike View Post
    Vegas is there any chance I can buy you some steaks and mail them to you or something?
    Quote Originally Posted by Lord of the Fraud View Post
    I do believe Iraq was a huge mistake
    Quote Originally Posted by Lord of the Fraud View Post
    Why the fuck is the world (cough US) allowing these backward fuckers have nukes.

  17. #17
    Bronze realchaser74's Avatar
    Reputation
    15
    Join Date
    Apr 2012
    Posts
    125
    Load Metric
    68114418
    Quote Originally Posted by sonatine View Post


    any device that requires user interaction via software might as well have no safeguard at all. once administrative controls are breached, emulating an "ok" click is trivial.

    see the bottom few sentences where they address exactly that weakness and suggest how a hardware switch is necessary to suppress any component.
    Correct but in order for your system to be breached requires ingornace on the users part.

    If you look at the android software even though it is open source Google has done well to insulate themselves from getting blame from thigns like this. If you keep the phone stock and only install apps from teh playstore (you can sideload and get apps from other source but you have to in settings click 'allow unknow sources") then anything that happens to your personal info or company info is 100% on you.

    When you install the app you are warned about all ther permissions and resources you are allowing the app to control thus you should never worry unless you are a complete idiot which most users i interact with on a daily basis are.

    There is one more thing that google has made it even harder to get an app on your phone. if oyu try and send someone a .apk file, which is the installer for apps, gmail will block it again making the best way to get apps is form the PlayStore

  18. #18
    Gold gauchojake's Avatar
    Reputation
    584
    Join Date
    Mar 2012
    Location
    Zipolite
    Posts
    2,450
    Load Metric
    68114418
    Quote Originally Posted by realchaser74 View Post
    Quote Originally Posted by sonatine View Post


    any device that requires user interaction via software might as well have no safeguard at all. once administrative controls are breached, emulating an "ok" click is trivial.

    see the bottom few sentences where they address exactly that weakness and suggest how a hardware switch is necessary to suppress any component.
    Correct but in order for your system to be breached requires ingornace on the users part.

    If you look at the android software even though it is open source Google has done well to insulate themselves from getting blame from thigns like this. If you keep the phone stock and only install apps from teh playstore (you can sideload and get apps from other source but you have to in settings click 'allow unknow sources") then anything that happens to your personal info or company info is 100% on you.

    When you install the app you are warned about all ther permissions and resources you are allowing the app to control thus you should never worry unless you are a complete idiot which most users i interact with on a daily basis are.

    There is one more thing that google has made it even harder to get an app on your phone. if oyu try and send someone a .apk file, which is the installer for apps, gmail will block it again making the best way to get apps is form the PlayStore
    A lot of people use Amazon for the free app of the day. Amazon App Store requires you to leave your phone vulnerable. I really want to open someone's network sockets.

  19. #19
    Plutonium sonatine's Avatar
    Reputation
    7376
    Join Date
    Mar 2012
    Posts
    33,435
    Load Metric
    68114418
    Quote Originally Posted by gauchojake View Post
    odds 408 gets this malware -10000000000000000000000000000000000000000000



    This actually sounds like something the government would like to have it's grubby little hands on.

    it was developed by the navy.

  20. #20
    Plutonium sonatine's Avatar
    Reputation
    7376
    Join Date
    Mar 2012
    Posts
    33,435
    Load Metric
    68114418
    Quote Originally Posted by Jasep View Post
    Sonatine, do you think we will have surrogates style technology in the next 50 years?
    Explain please, Im drawing a blank.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. 40ape home videos
    By rickastley in forum Flying Stupidity
    Replies: 64
    Last Post: 12-10-2012, 04:26 AM
  2. Shit Android Fanatics Say
    By fluffer in forum Flying Stupidity
    Replies: 3
    Last Post: 10-23-2012, 09:14 PM
  3. 5 easy tricks to boost your home Wi-Fi
    By Rollo Tomasi in forum Flying Stupidity
    Replies: 4
    Last Post: 08-26-2012, 11:27 AM
  4. Did Brandon take his ball and go home again??
    By badguy23 in forum Flying Stupidity
    Replies: 46
    Last Post: 08-15-2012, 04:40 AM
  5. TOR Client for Android
    By JinxedChoker in forum The Hacker's Delight
    Replies: 2
    Last Post: 04-16-2012, 09:14 PM