Pages: [1]   Go Down
  Print  
Author Topic: Researchers Show How Apple's App Approval Process Can Be Beaten by Malicious Apps  (Read 253 times)
HCK
Global Moderator
Hero Member
*****
Posts: 79425



« on: August 16, 2013, 11:00:40 pm »

Researchers Show How Apple's App Approval Process Can Be Beaten by Malicious Apps

Researchers from Georgia Tech submitted to the App Store and received approval for a malicious app, according to Technology Review. The researchers submitted an innocuous app that included inactive malware-type code hidden from Apple's app approval system.  When downloaded onto a test device after the app was approved, the app 'phoned home' and gained a variety of abilities that compromised the host phone. This malware, which the researchers dubbed Jekyll, could stealthily post tweets, send e-mails and texts, steal personal information and device ID numbers, take photos, and attack other apps. It even provided a way to magnify its effects, because it could direct Safari, Appleā€™s default browser, to a website with more malware.The researchers, including Long Lu, a Stony Brook University researcher who was part of the team at Georgia Tech, only put the app on the App Store very briefly and it was not downloaded by anyone other than research team members.  The team said that using monitoring code built into the app, they determined that Apple's app approval team only ran the app for a few seconds and that malicious code was not discovered by Apple's team. "The message we want to deliver is that right now, the Apple review process is mostly doing a static analysis of the app, which we say is not sufficient because dynamically generated logic cannot be very easily seen," said Lu.  Apple spokesman Tom Neumayr told Technology Review that the company made some changes to the iOS operating system in response to the paper, though he did not specify what the changes were.   Recent Mac and iOS Blog Stories • Upcoming iPhone-Compatible Sony Lens Attachment Detailed in Leaked Manual • Apple Said to Be Working with Foxconn, Corning and Innolux on 'iTV' for 2014 Launch • 2K and Lucid Games Announce '2K Drive', a New Racing Title Exclusively for iOS • Geekbench 3 with 15 New Benchmark Tests Released for Mac, iOS, and More  • 'Syfy Now' Launches for iOS with Greater Access to Content, iCloud Syncing • iPhone Display Supplier Japan Display Begins Focusing Production Efforts on iPhone 5S • Launch of 'Automatic Link' Smart Driving Assistant Further Delayed • Markdown Text Editor 'Editorial' Launches for iPad with Workflow Automation Features    
 


http://www.macrumors.com/2013/08/16/researchers-show-how-apples-app-approval-process-can-be-beaten-by-malicious-apps/
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: