Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

June 5th, 2012, 09:26 GMT · By

Experts Bypass Android Bouncer to Slip Malicious Apps into Google Play

SHARE:

Adjust text size:

Jon Oberheide
Enlarge picture
Researchers Charlie Miller and Jon Oberheide have made available a teaser of their presentation at this week’s SummerCon conference in New York. They plan on demonstrating how they have been able to bypass the Android Bouncer and slip malicious apps into Google’s official app market.

Android Bouncer is a system recently introduced by Google, which automatically scans Google Play for malicious software. Its advantages are that the detection process doesn’t disrupt user experience and app developers are allowed to post their programs without too much hassle.

However, as the experts state, the system can be tricked, allowing wrongdoers to upload their malicious elements.

“We’re going to submit an application to the Android Market and get a connect-back shell on the Bouncer instance when it attempts its runtime dynamic analysis of our mobile application. This allows us to explore the Bouncer environment with an interactive remote shell,” Oberheide said.

After they upload their “malicious” APK to Google Play, they await the connect-back. Once the callback is received, they are able to run a remote interactive shell on an emulated Android device.

Apparently, this allows them to obtain the Bouncer environment’s kernel version, filesystem contents, and other data.

The method presented by Oberheide in the video is only one of the techniques that can be used to fingerprint the Bouncer environment.

The demonstration shows that cybercriminals can easily upload their malicious elements and make them appear as being harmless, while in reality they’re capable of causing serious damage to the user’s phone.

However, the experts are closely collaborating with Google's security team and they’re confident that this relatively new scanning system will be considerably improved.

So, without further ado, here’s the video:




1,672 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


F-Secure: New Zsone Android Malware May Be Developed

Shady Fortune Teller Android App Found on Google Play

Hack in the Box 2012 Amsterdam Video Overview

Fake Facebook Dating Apps Redirect Android Users to Potentially Malicious Sites

Android.Opfake: Free Apps Come at a Price

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM