<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>fantom-stranger.com &#187; Mobile</title>
	<atom:link href="http://www.fantom-stranger.com/tag/mobile/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fantom-stranger.com</link>
	<description>$here = new site (&#039;blogs&#039;,&#039;reviews&#039;,&#039;discussions&#039;,&#039;image editor&#039;,&#039;image dump&#039;,&#039;text dump&#039;,&#039;specialized humor&#039;,&#039;crap!&#039;);</description>
	<lastBuildDate>Wed, 24 Mar 2010 05:09:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Bot-vector analysis: Android OS comes pre-installed with malware</title>
		<link>http://www.fantom-stranger.com/2010/03/09/bot-vector-analysis-android-os-preinstalled-malware/</link>
		<comments>http://www.fantom-stranger.com/2010/03/09/bot-vector-analysis-android-os-preinstalled-malware/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 23:05:13 +0000</pubDate>
		<dc:creator>Andy</dc:creator>
				<category><![CDATA[Andriod]]></category>
		<category><![CDATA[Computers & Technology]]></category>
		<category><![CDATA[Internet Culture]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cell phone]]></category>
		<category><![CDATA[confliker]]></category>
		<category><![CDATA[HTC]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[smart phone]]></category>
		<category><![CDATA[t-mobile]]></category>
		<category><![CDATA[vodaphone]]></category>

		<guid isPermaLink="false">http://www.fantom-stranger.com/?p=1429</guid>
		<description><![CDATA[Apparently, there has been a compromise at HTC or Vodaphone. There are rumors on the web that a Vodaphone &#8220;HTC Magic&#8221; came pre-installed with multiple malware programs. How would someone slip a file onto a phone before it enters an end user&#8217;s hands? Any way you look at it, this seems like a hack. A [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.fantom-stranger.com/wp-content/uploads/2010/03/htc-magic.png" rel="shadowbox[sbpost-1429];player=img;"><img class="aligncenter size-full wp-image-1430" title="htc-magic" src="http://www.fantom-stranger.com/wp-content/uploads/2010/03/htc-magic.png" alt="" width="174" height="281" /></a>Apparently, there has been a compromise at HTC or Vodaphone. There are rumors on the web that a Vodaphone &#8220;<a href="http://en.wikipedia.org/wiki/HTC_Magic">HTC Magic</a>&#8221; came <a href="http://research.pandasecurity.com/vodafone-distributes-mariposa/">pre-installed with multiple malware programs</a>. How would someone slip a file onto a phone before it enters an end  user&#8217;s hands? Any way you look at it, this <strong>seems</strong> like a hack.</p>
<blockquote><p>A quick analysis of the malware reveals that it is in fact a Mariposa bot client.</p></blockquote>
<p>Every android phone *<em>can</em>* be plugged into any PC or Mac via USB. Under windows it works just like any other insert digital medium (CD, DVD, Flash Drive). Upon being plugged in, it opens the folder and executes the file specified in autorun.ini. This would be the vector a bot herder/malware researcher would use to launch it&#8217;s &#8220;spread&#8221; and stay infected. As long as nobody notices the files on the phones, users would just keep getting <strong>re-infected</strong> every time they plug in their phone to download their photos. One speculation that may be responsible is: &#8220;the SD card&#8221; since all that  someone would need  to do is put &#8220;files&#8221; in the root of the SD card for  them to execute. So the question might be instead be: &#8220;How would someone slip a file onto a flash card before it&#8217;s inserted into a phone?&#8221;.</p>
<blockquote><p>Interestingly enough, the Mariposa bot is not the only malware I found on the Vodafone HTC Magic phone. There’s also a Confiker and a Lineage password stealing malware.</p></blockquote>
<p>Why did it  take so long for a person to notice malware on the phone? The HTC Magic is one of the most popular smart-phones in the UK. In the US,  T-mobile branded this product as the &#8220;<strong>myTouch 3G</strong>&#8220;, and  that phone has a massive pop. Where is the supporting evidence on the phone? The only &#8220;proof&#8221; we have so far is a few windows screen shots. I&#8217;m intrigued by this and it will be interesting to see what comes to  light. I&#8217;ll keep you updated when I hear more.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.fantom-stranger.com/2010/03/09/bot-vector-analysis-android-os-preinstalled-malware/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

