|
Skrevet af Jerri Christiansen
|
|
Mandag, 07. marts 2011 11:43 |
|
Google annoncerede på deres mobile blog, at de har brugt Androids indbyggede kill switch til at fjernstyre og lave en clean up på baggrund af de nyligt opdagede 58 malware apps. Disse applikationer benyttede sig af sårbarheder i systemet, men som ikke påvirker Android 2.2.2 eller højere. Google mener angriberne sandsynligvis kun var i stand til at fange enhedsspecifikke data som IMEI / IMSI, altså entydige koder der bruges til at identificere mobile enheder, og den version af Android der kører på enheden.
Google siger, at de har taget følgende skridt for at beskytte Android-brugere:
"1. We removed the malicious applications from Android Market, suspended the associated developer accounts, and contacted law enforcement about the attack.
2. We are remotely removing the malicious applications from affected devices. This remote application removal feature is one of many security controls the Android team can use to help protect users from malicious applications.
3. We are pushing an Android Market security update to all affected devices that undoes the exploits to prevent the attacker(s) from accessing any more information from affected devices. If your device has been affected, you will receive an email from
Denne emailadresse er beskyttet mod programmer som samler emailadresser. Du skal aktivere javascript for at kunne se adressen.
over the next 72 hours. You will also receive a notification on your device that “Android Market Security Tool March 2011” has been installed. You may also receive notification(s) on your device that an application has been removed. You are not required to take any action from there; the update will automatically undo the exploit. Within 24 hours of the exploit being undone, you will receive a second email.
4. We are adding a number of measures to help prevent additional malicious applications using similar exploits from being distributed through Android Market and are working with our partners to provide the fix for the underlying security issues."
Kilde dvhardware.net |