Stranica 1 od 1

Novi tip virusa - ne samo za smartphone!

Poslato: Pet, 03. Mar 2006. 10:02
od Sasa_NS
RedBrowser sends SMS to premium rate numbers

Kaspersky Lab, a leading developer of secure content management solutions, has detected a new piece of mobile malware. Trojan-SMS.J2ME.RedBrowser.a is the first malicious program which infects not only smartphones, but any mobile phone capable of running Java (J2ME) applications.

The Trojan spreads in the guise of a program called "RedBrowser", which allegedly enables the user to visit WAP sites without using a WAP connection. According to the Trojan's author, this is made possible by sending and receiving free SMSs. In actual fact, the Trojan only sends SMSs to premium rate numbers. The user is charged $5 - $6 per SMS.

The Trojan is a Java application, a JAR format archive. The file may be called "redbrowser.jar", and is 54482 bytes in size. The Trojan can be downloaded to the victim handset either via the Internet (from a WAP site) or via Bluetooth or a personal computer. The archive contains the following files:

FS.class - auxiliary file (2719 bytes in size)
FW.class - auxiliary file (2664 bytes in size)
icon.png - graphics file (3165 bytes in size)
logo101.png - graphics file (16829 bytes in size)
logo128.pnh - graphics file (27375 bytes in size)
M.class - interface file (5339 bytes in size)
SM.class - Trojan application which sends SMS messages (1945 bytes in size)

The Trojan can be easily removed from the victim handset using standard utilities already installed on the telephone.

So far, Kaspersky Lab has only received one sample of RedBrowser, which clearly targets subscribers of Beeline, MTS, and Megafon, Russia’s major mobile service providers. However, other versions of RedBrowser, or similar programs, may well be circulating on the Internet. RedBrowser is a sign that virus writers are extending their reach, and no longer only targeting smart phones.

Mobile phone users are recommended to be cautious and not to download or launch unknown programs via the Internet.


Slika tog Red Browsera
http://www.mycity.co.yu/phpbb/uploads/1 ... 0virus.jpg

Izvor:
http://www.mycity.co.yu/phpbb/viewtopic.php?t=32859

Poslato: Pet, 03. Mar 2006. 19:04
od Lobachewsky
Hm... Evo sad mi pade na pamet nesto: Kog su tipa (kako su napravljene, sta sadrze) SMS poruke koje ti salje operater za konfiguraciju aparata? Jer operater ti samo posalje sms, ti kliknes yes (obicnim sms-om to ne moze da se izvede), i onda se telefon sam konfigurise (opet obicnim sms-om to ne moze da se izvede, valjda:)). I to moze da bude neki virus...

Poslato: Pet, 03. Mar 2006. 22:25
od Sasa_NS
Sigurno nije reč o virusu. Verovatno su te poruke istog tipa kao i "vizit karte" koje se mogu takođe poslati SMS-om (ekstenzija .vcf, a šalju se kada želiš da neki kontakt iz adresara, zajedno sa svim popunjenim podacima, pošalješ SMS-om na drugi telefon). Laički objašnjeno, verovatno sadrže određena, unapred definisana polja u koja su unete neke vrednosti, pa kada takva poruka stigne u telefon, te vrednosti se samo presnime (uz tvoju dozvolu, naravno) u ista takva polja u softveru telefona... I, voala, sve bude "automatski" podešeno... :)

Virus je nešto drugo, pravi mali (destruktivni) program... :x

Pojava ovog virusa koji napada i "obične telefone", dakle, ne samo smartphone, je interesantna jer konačno izbija jedan od "argumenata" za nekupovinu smartphona nekim skepticima - kao, ne treba ih kupovati jer su podložni virusima... Glupost. Kao što neko napravi virus, drugi napiše antivirus...
Evo, sada i obični telefoni izgleda počinju da "pate" od istih "boljki"... :P

Poslato: Sub, 04. Mar 2006. 13:39
od Brainwashed
slazzem se sa sashom da je paranoja nepotrebna...
missim, koliko treba da budesh nezainteresovan za tehnologiju pa da ti se desi da sluchajno skinesh virus sa nekog sajta?! :) ...ili da prihvatish neki fajl preko blututa, a da ne znash ko ti ga shalje... :D

bajdvej, konfiguracione poruke su obichni textualni fajlovi koji se kopi-pejstuju u one opcije koje bi ti sam kucko slovo po slovo...so, don't worry about it... ;)

cya...