LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2015, 04:13 AM   #1
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,292

Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
Hack Attack: Firmware Compromised? Pipo P1


I have a new Pipo P1 tablet with Android 4.4.2 and the much(Overly?) vaunted RK3288 chip. I used it last night as an e-reader. Afterwards, I opened the browser, which loads the last url (http://www.jw.org - as squeaky clean a website as they come)

I typed in something innocuous - google, I think, and was redirected through zh.zerodirect1.com to this (long) url:
http://www.google-playstore.com/zero...__var5..DOMAIN

The screen is attached as a jpeg. It bothers me how nearly I went for it! It seemed forceful for Google's way of expressing things (more like m$ . I started checking
* No updates from the "Settings / About Tablet / Check for Updates)."
* No CVE number referred to in the text (as I might expect).
* The phrase "kill your phone's internet speed" is bad grammar.
* Hitting the back button allowed me to see the zh.zerodirect1.com url.
* The playstore is actually play.google.com, not google-playstore.com.
* No similar behaviour on another Android system.
* Once I decided to ask, and saw the whole url, the whole thing became obvious. My next move is to look for a rootkit checker in the play store.

NOW MY QUESTION: Where the <expletive deleted> did that come from? Is there a rootkit fitted as from new?

My only apps are all known apps used previously on another tablet without issue. The only odd thing is an app totally in Chinese, which came with the tablet. I mean to get a chinese speaker to explain it to me.
Attached Thumbnails
Click image for larger version

Name:	20150113_221817.jpg
Views:	54
Size:	254.1 KB
ID:	17353  
 
Old 01-14-2015, 08:56 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,292

Original Poster
Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
Well, I got that link up on an x86_64 linux box and clicked on it, with noscript functional. It sent me here.
http://ezte8.redirectvoluum.com/redi...oZ5Q7U%3D&rm=D

Another piece of hard work by someone - but nowhere near the playstore :-P.
 
Old 01-15-2015, 10:59 AM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
"The Play Store," just like Apple Software Update, is an application, not a site. (That is to say, you should only update through the application, not through any site.) Only the application for software-updating the machine, that comes with the machine, should ever be trusted to update anything whatsoever on the machine.

Tablets, like mobile phones, should (IMHO) always be treated as inherently insecure devices. For instance, I'd never use one to do my banking, nor "tap" it against anything at Starbucks or anywhere else. (Sorry, Apple.)
 
Old 01-15-2015, 12:59 PM   #4
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,292

Original Poster
Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
Agreed completely on the security.

It does not seem to be repeating, and I am a wary owner at this stage. I was surprised to run into a hack attempt for Android, when I am in communication with nothing suspicious. Maybe I checked Ebay - that might have done it.
 
Old 01-18-2015, 08:43 AM   #5
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
Maybe it isn't your device, but rather something hinky with your ISP? Given the number of ISPs that like to redirect traffic (particularly mistyped URLs) or insert their own code into web pages, I wouldn't rule them out as a suspect. Your browser probably identifies you as using Android, and the re-direct took over from there.
 
Old 01-18-2015, 11:02 AM   #6
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,292

Original Poster
Rep: Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322Reputation: 2322
OK, In summary

1. I really don't know where that suspicious url came from. As I get a provider IP address, it could have been an attack from outside.
2. Nothing major went wrong, fortunately.
3. I can be pretty certain only the browser and base system was running.
4. Nobody recognised this approach, which is a sign it is not too widespread.
5. No repeat occurred. I may not even have the same IP now.
So I am marking this one solved, because it's as near solved as it's ever going to be.

Last edited by business_kid; 01-19-2015 at 04:57 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sony's PlayStation hit by hack attack Jeebizz Linux - News 3 12-20-2014 10:41 AM
LXer: My Moto RAZR V3 wants a firmware hack. Where do I begin? LXer Syndicated Linux News 0 06-23-2013 12:30 PM
possible hack attack? spycxamaican Linux - Security 7 01-13-2009 01:57 PM
LXer: Hack Attack : Run Linux Apps Natively On Windows, OSX LXer Syndicated Linux News 0 03-23-2008 09:50 PM
Tools to hack/attack windows ErEn Linux - Security 1 01-10-2008 08:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration