[Q] Security audit of custom ROMs - Optimus One, P500, V General

Has anyone conducted security audits of the major custom ROMs that are available? I imagine it would be trivial to install a backdoor of some sort deep inside a custom ROM that only seasoned developers poring through the code would be able to find. Just to be clear, I'm not accusing anyone of anything. I'm just asking if this has been done and by whom, and if so, what the findings are.

I ran shark for root once, for 24 hours with data connection enabled but didn't find anything fishy in the dump. On one of the leading rom. I think devs have better things to do than spy on us.
Sent from my LG-P500 using XDA Premium App

wtf so paying with credit card on mobile is dangerous???

ccdreadcc said:
wtf so paying with credit card on mobile is dangerous???
Click to expand...
Click to collapse
Can't deny the possibility. But so is it with anywhere on internet.
Sent from my LG-P500 using XDA Premium App

Related

[Q] What security apps are you using?

Am curious as to what security app you guys use to protect your phone from malware etc.
There are so many out there such as Lookout, Avg, GuardX etc. so would like to know what you recommend and why, especially something with low battery consumption.
I was going to try Lookout but have read something about them passing your info to 3rd parties!!!
Sent from my GT-I9100 using Tapatalk
Common sense.
Sent from my Transformer TF101 using XDA Premium App
TheGhost1233 said:
Common sense.
Sent from my Transformer TF101 using XDA Premium App
Click to expand...
Click to collapse
yep, me too!
(get it free from the market )
kersey said:
Am curious as to what security app you guys use to protect your phone from malware etc.
There are so many out there such as Lookout, Avg, GuardX etc. so would like to know what you recommend and why, especially something with low battery consumption.
I was going to try Lookout but have read something about them passing your info to 3rd parties!!!
Sent from my GT-I9100 using Tapatalk
Click to expand...
Click to collapse
I am fairly certain lookout does NOT do anything like that, but if you have a link to what you saw, I will certainly look into it and speak to my contact there.
I use lookout myself, and I can assure you that AVG isn't a proper AV app...
It simply looks at the package name to decide if it's harmful... So if you take the hello world sample, and name it org.example.malicious.app (you'd need to use one in their database), the hello world sample would show as malicious...
They classified superuser app as malicious... So take a look at http://androidsu.com/2011/06/a-word-about-superuser-and-security/
By extension of this, a malicious app can simply be renamed, and it gets past AVG... I could write a script that would serve up an APK purporting to be something, which would have a different random name each time (dictionary words perhaps), and which would get past AVG...
Lookout certainly appears to me to be scanning the applications correctly. I am pretty sure I've tried renaming the malware internally (reverse engineering a virus sample) and it was detected fine...
I use LBE Privacy Guard (rooted with the stock rom) to control permissions on a per app basis.
That and not pirating apps goes a long way.
leftovermagic said:
I use LBE Privacy Guard (rooted with the stock rom) to control permissions on a per app basis.
That and not pirating apps goes a long way.
Click to expand...
Click to collapse
I use this as well.
Pulser what do you think about it?
Sent from my GT-I9100 using XDA Premium App
Is the AVG used on Android different from that used on Windows apart from the different operating system that is ?
I use androids own security software
Thanks guys for your input.
Thankfully the common sense app is available in my area and is also a non-piracy zone (you've got to be a real tight arse to begrudge paying a few pounds for such great apps).
Will try and find where i read about Lookout but in the meantime may give it a go from pulser_g2's recommendation or try LBE.
Sent from my GT-I9100 using Tapatalk
MaBlo said:
I use this as well.
Pulser what do you think about it?
Sent from my GT-I9100 using XDA Premium App
Click to expand...
Click to collapse
I am not too keen on the way in which it goes about doing what it does... I ain't a fan of injecting code before the dalvik layer...
If you have utmost trust in whoever made it, fair enough. But I am not certain it's the best way to do it technically... I don't have enough trust in something to let it hook in early like that tbh...
So there's got to be some app which does the job properly? Or is there none? Are you telling me there is not a single antivirus/internet security app for android mobile phones out there???
Come on, fellas......give some meaningful recommendations. Straight question......What's the best app out there for guarding your phone on the internet?
What about Kaspersky mobile security, Netquin anti virus, McAfee wavesecure, Webroot security anti virus???
Has anyone used them? What's the opinion of the senior tech gurus here about them? Honest answers would be appreciated so that we can arrive at a consensus "best antivirus/internet security" app out there.
pulser_g2 said:
I am not too keen on the way in which it goes about doing what it does... I ain't a fan of injecting code before the dalvik layer...
If you have utmost trust in whoever made it, fair enough. But I am not certain it's the best way to do it technically... I don't have enough trust in something to let it hook in early like that tbh...
Click to expand...
Click to collapse
Yeah that's the problem, I don't trust him at all. It's some chinese guy who don't answer questions on xda. But apparently someone from Lookout checked the app out, and it's clean. But I guess it's unnecessary if you use common sense anyway.
Sent from my GT-I9100 using XDA Premium App

Paid to root

Hey all...I'm VERY new to all of this rooting stuff...still reading about it and I can't seem to wrap my head around it....Not sure if I'd be crossing a line by asking this, but here it goes....are there people on here that would actually root a phone for someone if they (ie..me) are to stupid to do so?
Of course there would be compensation involved.
Thanks for any info!!!
If you are new to the point that you are not comfortable following the steps needed to root your phone then I would say that you should not be worrying about rooting your phone at this point.
Why do I say this? It is because you will want to flash a myriad of Roms after your phone is rooted, which I guarantee will cause issues that you will not be able to figure out on your own.
You also need to ask yourself what it is that you hope to gain from rooting your phone. The stock Thunderbolt has bloat no doubt, but it is generally compatible with apps and is about to receive the Gingerbread OTA (non-root users theorize) fairly soon.
What do you want that can only be accomplished by rooting your phone at this point? If you cannot answer that question, then I hope you will take my advice and do some reading on this site, and one or two other sites, until you are ready to root your phone without paying someone to do it for you.
One other thing. Please do not create posts asking about the proverbial 'Best Rom'. There is no such thing.
Just my .02 cents!
I appreciate the info....Thanks!!!
Rich U said:
I appreciate the info....Thanks!!!
Click to expand...
Click to collapse
You're very welcome. I hope that I did not scare you off of rooting, but it is something that should not be done without some careful thought before hand.
For $100 I'll root your phone.
Sent from my Synergized Thunderbolt via XDA Premium App
I've rooted several devices for friends that have no intention of using clockworkmod. They simply want the advantages of root and to run a new ROM like CM7. I'd be happy to do it for money, and I don't think the end user of a rooted devices needs to know jack about it rooting it to enjoy the benefits. In short, I'm happy to root a device for someone as long as I know they aren't going to get in there and brick the thing somehow and come to me to fix it like it's my problem. Most people are decent enough to do that.
if you look online(or in your local yellow pages), you can find shops locally that will fix, root, etc your cell phone.
just here in San Diego there's about a dozen places that offer these services.
although i will tell you... the first time you figure out you have a problem with your carb and it's bad enough that you can't drive your car... then a "friend" tells you, just bring the carb over here & we'll fix it for you... then you're just standing there looking at the carb and thinking "uhhh..."
now that's rooting a phone x 10 difficultly.
I'll do it for free, teach you how i did it, and give you the basic knowledge of how not to brick. Where are you located?
Sent from my SHIFTAO5P using xda premium
jpa77 said:
I'll do it for free, teach you how i did it, and give you the basic knowledge of how not to brick. Where are you located?
Sent from my SHIFTAO5P using xda premium
Click to expand...
Click to collapse
Good man. There is a one touch root available.. more like several clicks but its easy.
Sent from my ADR6400L using XDA App
jpa77 said:
I'll do it for free, teach you how i did it, and give you the basic knowledge of how not to brick. Where are you located?
Sent from my SHIFTAO5P using xda premium
Click to expand...
Click to collapse
My offer still stands. Pm me if you're interested.
Sent from my SHIFTAO5P using xda premium
^^^
You sir are a gentleman. I can honestly say that just about everyone who uses Droid theory 's roms are helpful nice individuals.
Sent from my BURNTH3ORYX using XDA App
Archmarine said:
^^^
You sir are a gentleman. I can honestly say that just about everyone who uses Droid theory 's roms are helpful nice individuals.
Sent from my BURNTH3ORYX using XDA App
Click to expand...
Click to collapse
I didn't have anybody to guide me when i first started and i know how frustrating it can be. And you never know, he may be the next great developer with the right start. I have been the "tech support" for my entire family who I converted to android. It would be nice to teach someone who will want to learn as opposed to my family who just says here you do it...
And you are right on the money when you say ppl who use Th3orys roms are nice and helpful. I have learned a great deal from that community.
I am not a dev, just someone who knows how to implement the awesome features created by the community here at XDA.
Sent from my SHIFTAO5P using xda premium
I know we are going off topic but I feel the same way. If people did not get smart with other users and just be helpful people would have a great time learning.
Sent from my BURNTH3ORYX using XDA App
Dang if I was near my laptop which my dad has webx on I would do it for you. I have rooted a bunch of phones for friends and family and I find it especially fun teaching them what root, roms, etc. can help them achieve. Today I rooted my friends sensation so he would have the sensation xe (beats audio) options and speed. If you feel that your stock phone seems slow rooting, overclocking and debloating or changing the ROM can definitely help you!
Sent from my Thunderbolt!
I would do it for 30 and make sure your phone gets back to you with lots of extra programs you will need. Plus 5 bucks shipping back.
Sent from my Synergized BOLT VIA XDA app
"If i helped you please thank me"

[Q] Is this malware? And if it is, how do I block it

I haven't used an AntiVirus for this yet, just because I don't know which ones work the best or if any will slow my phone. Any suggestions?
Sent from my HTC_Amaze_4G using xda premium
glacierguy said:
I haven't used an AntiVirus for this yet, just because I don't know which ones work the best or if any will slow my phone. Any suggestions?
Sent from my HTC_Amaze_4G using xda premium
Click to expand...
Click to collapse
Any app you've recently installed as what i see that ad is causing the problems..
Try to figure it out what app is causing the problems..
If you can't see what is causing the problems try to download air push detector on the market and it will scan your apps whose doing that ads on your notification..
Solved... I think it was a fake 4shared app or another couple of apps that I already forgot... Thanks
Sent from my HTC_Amaze_4G using xda premium
Speaking of this subject, what IS the best anti virus if any for this phone? I did a search on here, but nothing came up... Odd, I think.
Sent from my HTC Amaze 4G using XDA App
Acroft311 said:
Speaking of this subject, what IS the best anti virus if any for this phone? I did a search on here, but nothing came up... Odd, I think.
Sent from my HTC Amaze 4G using XDA App
Click to expand...
Click to collapse
I think it's because androids don't catch viruses... But idk. I've never had an AntiVirus catch a virus or malware even so I decided against one for this phone
Sent from my HTC_Amaze_4G using xda premium
you dont really need internet security on your phone. if anything bad happens u can always re flash the rom or back it up
Koushik Dutta (developer of ROM Manager, and many other amazing things we all use on our phones) posted and interesring article about how antivirus programs on our phones don't really do anything for us. Its on his G+ if u scroll through his feed
Sent from my NRGized Amaze...
via xda premium
aj_2423 said:
Koushik Dutta (developer of ROM Manager, and many other amazing things we all use on our phones) posted and interesring article about how antivirus programs on our phones don't really do anything for us. Its on his G+ if u scroll through his feed
Sent from my NRGized Amaze...
via xda premium
Click to expand...
Click to collapse
Don't have g+
Sent from my HTC_Amaze_4G using xda premium
First off don't ever think that android is invulnerable to malware, viruses etc.
That's like misinformed Mac users who think the same.
Android in fact is diferent. Being open source I can promise you people are working on ways to hack your phone.
ALSO because there is so much opportunity to market stuff, moreso than pc or iPhone/mac android is probably lookin like a big open playground.
The fact is, most anti virus is complete bs, viruses are generaly picked up by ignorant people. Not to be harsh, but mist people just click/tap away on everything they see, or just open up links, or email attachments.
General rule: if you don't know what it is freaking delete that shizzle....
I got a txt from what appears to be a tmo message... Except it was from "tmo"
And not "t-mobile". I deleted it before opening because all the other txts were from t-mobile not t-mo.
Eventually were gonna start seeing a lot of viruses, malware etc, for android.
Don't bother with anti virus software just a waste of memory.
Also try and stick with ad free spa or just suck it up and by the paid ad free version.
Hope this helps
Sent from my HTC_Amaze_4G using xda premium
freakboy13 said:
First off don't ever think that android is invulnerable to malware, viruses etc.
That's like misinformed Mac users who think the same.
Android in fact is diferent. Being open source I can promise you people are working on ways to hack your phone.
ALSO because there is so much opportunity to market stuff, moreso than pc or iPhone/mac android is probably lookin like a big open playground.
The fact is, most anti virus is complete bs, viruses are generaly picked up by ignorant people. Not to be harsh, but mist people just click/tap away on everything they see, or just open up links, or email attachments.
General rule: if you don't know what it is freaking delete that shizzle....
I got a txt from what appears to be a tmo message... Except it was from "tmo"
And not "t-mobile". I deleted it before opening because all the other txts were from t-mobile not t-mo.
Eventually were gonna start seeing a lot of viruses, malware etc, for android.
Don't bother with anti virus software just a waste of memory.
Also try and stick with ad free spa or just suck it up and by the paid ad free version.
Hope this helps
Sent from my HTC_Amaze_4G using xda premium
Click to expand...
Click to collapse
I never click on any internet ads. Every app I own that has a paid version, I've bought it (I've spent $100s on apps in my day). I don't have any non-market apps (only because I don't know of any good ones). I've uninstalled about 10 apps that were relatively new and possible malware apps and rebooted a few times and haven't gotten the spam again. This is the first time it's happened to a phone of mine. I get it on my tablet, but I have non market apps on that.

[Q] Security Bypass

Is it possible to creat an app or to develop a program that would temporarily defeat a security system including but not limited to a motion/heat sensor. If so where would one find more information on this? This is for purely business purposes.
Hack the Gibson
mdelouis said:
Is it possible to creat an app or to develop a program that would temporarily defeat a security system including but not limited to a motion/heat sensor. If so where would one find more information on this? This is for purely business purposes.
Click to expand...
Click to collapse
Sure strictly business. Why we're at it can an app that can generate debt card pin numbers in under 1 minute.
I don't think there is an app like you want and if there was this is probably the wrong place to find it.
Sent from my VS920 4G using xda app-developers app
Security Bypass
I actually work for a security division and we are trying to find all thew possible wqays to defeat a preiously installed motion detector. I know little to nothing about programming or developing and am wondering if a program could be made to disable an alarm system briefly.
kintwofan said:
Sure strictly business. Why we're at it can an app that can generate debt card pin numbers in under 1 minute.
I don't think there is an app like you want and if there was this is probably the wrong place to find it.
Sent from my VS920 4G using xda app-developers app
Click to expand...
Click to collapse
mdelouis said:
I actually work for a security division and we are trying to find all thew possible wqays to defeat a preiously installed motion detector. I know little to nothing about programming or developing and am wondering if a program could be made to disable an alarm system briefly.
Click to expand...
Click to collapse
Why wouldn't the owner just call and cancel the monitoring service?
Sent from my SCH-I605 using Tapatalk 2
I think hes asking if one exists or is possible to create so they can take preventative measures . If this is what youre asking. I dont think so. Not anymore than a computer. Im sure where there is a will theres a way.
Sent from my SCH-I605
Unfortunately even if it's true that you work for a security company there's no way to verify it and even then any information shared here on a public forum could easily be used by people with the wrong intentions so I highly doubt you'll find anything.
Sent from my SCH-I605 using xda app-developers app

Root for MJ7?

Has vroot been found to be safe to the phone and the computer?
Are thereI any other safer ways to root MJ7?
I know there are other threads with information. But I just want clarification on this.
Sent from my SCH-I545 using xda app-developers app
Swimboy46163 said:
Has vroot been found to be safe to the phone and the computer?
Are thereI any other safer ways to root MJ7?
I know there are other threads with information. But I just want clarification on this.
Sent from my SCH-I545 using xda app-developers app
Click to expand...
Click to collapse
I am wondering the same.. I see this.. http://www.youtube.com/watch?v=K5mCsDyW-TI
But I want clarification from here..
I used vroot to root my gs4 running 4.3 build MJ7 and it worked flawlessly
Sent from my SCH-I545 using xda app-developers app
musicfreak190 said:
I am wondering the same.. I see this.. http://www.youtube.com/watch?v=K5mCsDyW-TI
But I want clarification from here..
Click to expand...
Click to collapse
I wouldn't want to risk it yet.
I used Kingo Root. they have updated their root tool and made (are making) it open source, according to their facebook.
Telling me it works flawlessly tells me nothing.
Sent from my SCH-I545 using xda app-developers app
Swimboy46163 said:
Telling me it works flawlessly tells me nothing.
Sent from my SCH-I545 using xda app-developers app
Click to expand...
Click to collapse
Has it been proven safe? No.
Has it been proven malicious? No.
Currently there are only 2 ways to root. Kingo and vRoot.
All you can do is read and read some more, then make a decision that's best for you.
There is NO definite answer as to whether there is a 100% safe way to root MJ7.
Link?
Sent from my SCH-I545 using xda app-developers app
Is king safer than vroot to your knowledge or guess.
Sent from my SCH-I545 using xda app-developers app
Swimboy46163 said:
Link?
Sent from my SCH-I545 using xda app-developers app
Click to expand...
Click to collapse
Swimboy46163 said:
Is king safer than vroot to your knowledge or guess.
Sent from my SCH-I545 using xda app-developers app
Click to expand...
Click to collapse
There are no links Not allowed on XDA . Use Google.
I have no idea which one is safer. I'm not sure if either one is safe. I don't think anyone has a definitive answer yet.
Sent from my NCC 1701 using Tapatalk 4
I used vroot and had success and I can say I have seen no suspicious activity at all, yes vroot installs a Chinese superuser app but that's easily replaced with the normal su app, and this exploit seems to get around all Samsung's security not triggering anything except a custom lock when you boot up but even that can be faked using xposed framwork and the wanam app which hides it leaving no sign your phones fully roooted !
I guess once its made open source we will know more. Do you know if it leaves any residual stuff on the device from being rooted from the program. Like vroot leaves its Chinese version of Super User.
riker147 said:
There are no links Not allowed on XDA . Use Google.
I have no idea which one is safer. I'm not sure if either one is safe. I don't think anyone has a definitive answer yet.
Sent from my NCC 1701 using Tapatalk 4
Click to expand...
Click to collapse
matt1733 said:
I used vroot and had success and I can say I have seen no suspicious activity at all, yes vroot installs a Chinese superuser app but that's easily replaced with the normal su app, and this exploit seems to get around all Samsung's security not triggering anything except a custom lock when you boot up but even that can be faked using xposed framwork and the wanam app which hides it leaving no sign your phones fully roooted !
Click to expand...
Click to collapse
Are there even any ROMs out that work for MJ7? Is the superuser app that the program installs, is that all it installs. Seems like it might put something in the background of the phone to make it "keep escaping" knox.
Swimboy46163 said:
Are there even any ROMs out that work for MJ7? Is the superuser app that the program installs, is that all it installs. Seems like it might put something in the background of the phone to make it "keep escaping" knox.
Click to expand...
Click to collapse
There are no ROMs for MJ7. No custom recovery. No Safestrap. Just root.
All these questions you're asking have ALL been answered several times. Do a little research. There's plenty of info here on XDA.
If you don't feel comfortable using these exploits, then don't use them. Wait a while. You never now what lies ahead.
Nobody here can tell you if it's 100% safe because we just don't know. All I can tell you is that I haven't seen anyone on these boards say anything "bad" has happened with there PC or phone.
I knew 2 days straight without an "MJ7 root or recovery" thread was too good to be true
Sent from my SCH-I545 using xda app-developers app
I used that video guide and software on my s4 4.3 and then used a another tutorial on here to swap and remove the Chinese super user to the standard super user app and I've not had any problems in the last month of doing this. Everything went great and easy with no issues.
Sent from my SCH-I545 using xda app-developers app
I don't trust the Chinese. From past experiences, they will do whatever it takes to profit and take your money illegally. Just because nothing has happened to anyone YET does not mean it will not happen in the future. You don't know what kind of backdoor might be planted and what sort of information they're collecting or will collect from your device.
Please be patient. Unless you're life depends on root access. Hold off until a trusted developer can provide us with something we can all enjoy.
I would like a senior member to take 5 seconds to tell me why in hell they are getting the idea that they are so superior that being sly and rude to other members is ok!!! That is not how this site had operated in the past its starting kill the reputation of this community!!! So why dont we knock it back a few guys!!!
Charlie115 said:
I would like a senior member to take 5 seconds to tell me why in hell they are getting the idea that they are so superior that being sly and rude to other members is ok!!! That is not how this site had operated in the past its starting kill the reputation of this community!!! So why dont we knock it back a few guys!!!
Click to expand...
Click to collapse
That's obviously a blanket statement. If you see somebody being rude confront them through PM.
Sent from my SCH-I545 using Tapatalk
Charlie115 said:
I would like a senior member to take 5 seconds to tell me why in hell they are getting the idea that they are so superior that being sly and rude to other members is ok!!! That is not how this site had operated in the past its starting kill the reputation of this community!!! So why dont we knock it back a few guys!!!
Click to expand...
Click to collapse
Who was being rude? If you look on Page 1 of the Q&A forums you will see that this thread is titled exactly like the other one that is 3 pages long.
The community was fine with all the senior members. You say it's because of the senior members this community is killing the reputation?
I'm going to say no. It's the junior members "Please give me everything on a silver platter" mentality and entitlement issue that's killing the reputation of this site. The site operated perfectly fine before whiny kids started showing up only to post things that have already been discussed HEAVILY and to post because they know how to hit "Reply".
I'd rather have Senior Members post with logic and experience than Junior Members, such as yourself, talking bad about them and cluttering up an already useless thread with off-topic posts that had nothing but negativity behind it.
Hope you understand.

Categories

Resources