<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog</title>
	<atom:link href="http://blog.fortinet.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>Thus spoke the Beninese: scammers hijacking Facebook chat</title>
		<link>http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/</link>
		<comments>http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 11:59:33 +0000</pubDate>
		<dc:creator>Karine</dc:creator>
				<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=4046</guid>
		<description><![CDATA[Wasn&#8217;t it to my surprise when a friend&#8217;s son hit me up yesterday on Facebook chat. We don&#8217;t usually chat so I was curious as to what was going on. Although he 1st asked how I was, he quickly said he needed help to post an ad on a popular french classifieds website, leboncoin.fr. Although [...]]]></description>
			<content:encoded><![CDATA[<p>Wasn&#8217;t it to my surprise when a friend&#8217;s son hit me up yesterday on Facebook chat. We don&#8217;t usually chat so I was curious as to what was going on.</p>
<p>Although he 1st asked how I was, he quickly said he needed help to post an ad on a popular french classifieds website, <a title="leboncoin.fr" href="http://www.leboncoin.fr" target="_blank">leboncoin.fr</a>. Although suspicion rose immediately, as a security researcher, I was very curious to see where this was going to lead.</p>
<p style="text-align: left">The ad is for a car, and although he tells me to list the required fields so that he can give me all the requested information, my friend seems to have his text all prepared. He seems to be rather pasting chunks of text, with fields I haven&#8217;t even mentionned.</p>
<p> </p>
<p><div id="attachment_4049" class="wp-caption aligncenter" style="width: 514px"><a rel="attachment wp-att-4049" href="http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/indy-champs/"><img class="size-full wp-image-4049" src="http://blog.fortinet.com/wp-content/uploads/2012/01/indy-champs.png" alt="" width="504" height="142" /></a><p class="wp-caption-text">Giving me fields I haven&#39;t mentionned.</p></div>
<p> </p>
<p style="text-align: left">When I ask why the car is being sold in a totally different area from ours (800km away), he says it is for his aunt. I don&#8217;t want to question him too much, so I just keep on copying the information he is giving me. He gives me an email address, a phone number, links to pictures of the car, and a password for the ad. At this point, I&#8217;m not sure what his motives are. It is probably a false ad with hopes of getting the money for this non-existent car, but why would he need me to post it for him? Is his IP address blocked from the website? Or is this a way of trying to hide his traces? As he&#8217;s given me a password, it is certainly not a way to try to get any of the passwords I might commonly use on the Internet.</p>
<p> </p>
<p><div id="attachment_4055" class="wp-caption aligncenter" style="width: 521px"><a rel="attachment wp-att-4055" href="http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/indy-coord/"><img class="size-full wp-image-4055" src="http://blog.fortinet.com/wp-content/uploads/2012/01/indy-coord.png" alt="" width="511" height="81" /></a><p class="wp-caption-text">The classified&#39;s vendor details.</p></div>
<p> </p>
<p style="text-align: left">When I validate the ad, an email with a confirmation link is sent to the address I have provided. My friend copy/pastes the url into Facebook chat so that I can confirm. He asks me to copy/paste the message from the website to ensure I have really validated.</p>
<p> </p>
<p><div id="attachment_4056" class="wp-caption aligncenter" style="width: 516px"><a rel="attachment wp-att-4056" href="http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/indy-confirmation/"><img class="size-full wp-image-4056" src="http://blog.fortinet.com/wp-content/uploads/2012/01/indy-confirmation.png" alt="" width="506" height="224" /></a><p class="wp-caption-text">Asking me to prove I have validated the ad.</p></div>
<p> </p>
<p style="text-align: left">This guy seems to not want to waste much time. He is giving short and clear directions on what to input, how to download the pictures. Not once does he say &#8220;please&#8221; or &#8220;thanks&#8221;, or tries to make a bit of conversation. When I ask why he needs me to post the ad for him, he first eludes the question, but when I insist he eventually says it&#8217;s because the website won&#8217;t show on his computer. Then out of nowhere he asks whether I&#8217;ve seen the &#8220;new Facebook&#8221;. It&#8217;s pretty obvious I have as I have the new Timeline on my profile, and oh, so does he!</p>
<p> </p>
<p><div id="attachment_4057" class="wp-caption aligncenter" style="width: 517px"><a rel="attachment wp-att-4057" href="http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/indy-newfb/"><img class="size-full wp-image-4057" src="http://blog.fortinet.com/wp-content/uploads/2012/01/indy-newfb.png" alt="" width="507" height="85" /></a><p class="wp-caption-text">Link to the &quot;new Facebook&quot;.</p></div>
<p> </p>
<p style="text-align: left">Of course, it is a phishing site to steal user credentials so that he can later hijack more Facebook profiles. This site does not even try to look like the real Facebook. It is called &#8220;Facebook L0ve&#8221;, and yes, with a &#8217;0&#8242; instead of a capital &#8216;O&#8217;.</p>
<p> </p>
<p><div id="attachment_4058" class="wp-caption aligncenter" style="width: 760px"><a rel="attachment wp-att-4058" href="http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/newfb/"><img class="size-full wp-image-4058" src="http://blog.fortinet.com/wp-content/uploads/2012/01/newfb.png" alt="" width="750" height="447" /></a><p class="wp-caption-text">The new Facebook L0ve.</p></div>
<p> </p>
<p style="text-align: left">Now at the lab we&#8217;re curious to find out where this guy is. So we lure him into a &#8220;hot&#8221; MSN chat while we quickly set-up a webserver with photos for him to visit so that we can get his IP address and geolocalize it. Needless to say the MSN ID he gives me is another different email address, one he most probably uses to pass as a pretty girl to lure men into a fake romance!</p>
<p style="text-align: left">As it turns out, our foe is in Benin, and <a href="http://www.blog-note.com/msn-peux-tu-mettre-une-annonce-pour-moi-sur-le-bon-coin-arnaque/" target="_blank">it is not the 1st recorded scam of this type coming from there</a>. So if a &#8220;friend&#8221; hits you up to post an ad for him/her, or asks you to click on a link:</p>
<ul>
<li>Make sure it is really your friend, by asking for example if it is sunny in Alaska (and they normally live in Florida)</li>
<li>Tell your real friend their profile has been hijacked and they need to inform Facebook about it</li>
<li>Report the scam to your local Internet Complaint Center (USA: <a title="IC3" href="http://http://www.ic3.gov" target="_blank">http://www.ic3.gov</a>, France: <a title="Internet-Signalement" href="//www.internet-signalement.gouv.fr" target="_blank">﻿https://www.internet-signalement.gouv.fr</a>)</li>
<li>Report the fake ad to the website (<a title="leboncoin.fr" href="http://www.leboncoin.fr" target="_blank">leboncoin.fr</a>)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/thus-spoke-the-beninese-scammers-hijacking-facebook-chat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSL VPN with FortiClient Lite for Android</title>
		<link>http://blog.fortinet.com/ssl-vpn-with-forticlient-lite-for-android/</link>
		<comments>http://blog.fortinet.com/ssl-vpn-with-forticlient-lite-for-android/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 18:17:22 +0000</pubDate>
		<dc:creator>DManky</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3936</guid>
		<description><![CDATA[The following video clip instructs users how to setup FortiClient Lite on Android devices. The video includes explanations of the features of FortiClient Lite and how set the software up on both the Android and FortiGate devices. FortiClient Lite Android was released from beta in December 2011 and features SSL VPN connectivity. A question and [...]]]></description>
			<content:encoded><![CDATA[<p>The following video clip instructs users how to setup FortiClient Lite on Android devices.</p>
<p><iframe width="420" height="315" src="http://www.youtube.com/embed/hZHeRAr4H2I" frameborder="0" allowfullscreen></iframe></p>
<p>The video includes explanations of the features of FortiClient Lite and how set the software up on both the Android and FortiGate devices. FortiClient Lite Android was released from beta in December 2011 and features SSL VPN connectivity.</p>
<p>A question and answer forum can be found at:<br />
<br />
<a href="http://support.fortinet.com/forum/tt.asp?appid=6">http://support.fortinet.com/forum/tt.asp?appid=6</a></p>
<p>Alternatively, users may ask questions directly from their Android device using the “Report a Problem” feature located in FortiClient Lite&#8217;s menu. </p>
<p>Stay tuned for more updates on our mobile products!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/ssl-vpn-with-forticlient-lite-for-android/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Posts of 2011 from Fortinet&#8217;s FortiGuard Blog</title>
		<link>http://blog.fortinet.com/top-10-posts-of-2011-from-fortinets-fortiguard-blog/</link>
		<comments>http://blog.fortinet.com/top-10-posts-of-2011-from-fortinets-fortiguard-blog/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 16:24:31 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3927</guid>
		<description><![CDATA[It was a busy year in the world of network security. The threat landscape is constantly changing and we try to keep you posted on what&#8217;s going on with our FortiGuard blog. We&#8217;ve compiled our top 10 FortiGuard blog posts throughout 2011. Carrier IQ on Android &#8211; FAQ Android Malware Surges in 2011 Fortinet Security [...]]]></description>
			<content:encoded><![CDATA[<p>It was a busy year in the world of network security. The threat landscape is constantly changing and we try to keep you posted on what&#8217;s going on with our FortiGuard blog. We&#8217;ve compiled our top 10 FortiGuard blog posts throughout 2011. </p>
<p><a href="http://blog.fortinet.com/carrier-iq-on-android-faq/">Carrier IQ on Android &#8211; FAQ </a><br />
<a href="http://blog.fortinet.com/android-malware-surges-in-2011/">Android Malware Surges in 2011 </a><br />
<a href="http://blog.fortinet.com/fortinet-security-minute-for-september-2011/">Fortinet Security Minute for September 2011 </a><br />
<a href="http://blog.fortinet.com/threat-landscape-midyear-in-review/">Threat Landscape Midyear in Review </a><br />
<a href="http://blog.fortinet.com/apple-plays-cat-and-mouse-game-with-mac-malware-makers/">Apple Plays Cat-and-Mouse Game with Mac Malware Makers </a><br />
<a href="http://blog.fortinet.com/world-ipv6-day/">World IPv6 Day </a><br />
<a href="http://blog.fortinet.com/phishing-101/">Phishing 101</a><br />
<a href="http://blog.fortinet.com/stop-your-computer-from-becoming-a-zombie/">Stop Your Computer From Becoming a Zombie! </a><br />
<a href="http://blog.fortinet.com/40th-anniversary-of-the-computer-virus/">40th Anniversary of the Computer Virus </a><br />
<a href="http://blog.fortinet.com/whats-not-going-to-happen-in-2011-anti-predictions/">What&#8217;s Not Going to Happen in 2011: Anti-Predictions </a></p>
<p>Have you subscribed to the FortiGuard blog&#8217;s RSS feed?<br />
<a href="http://blog.fortinet.com/feed/">Subscribe Now.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/top-10-posts-of-2011-from-fortinets-fortiguard-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Minute December 2011 edition</title>
		<link>http://blog.fortinet.com/security-minute-december-2011-edition/</link>
		<comments>http://blog.fortinet.com/security-minute-december-2011-edition/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 23:10:54 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3914</guid>
		<description><![CDATA[In this edition of Security Minute, Derek Manky, Fortinet’s senior security strategist, wraps up 2011 with his predictions of the type of network security threats we might see in 2012. Here’s a link to the full report for more detailed info: http://blog.fortinet.com/2012-threat-predictions/]]></description>
			<content:encoded><![CDATA[<p><iframe width="560" height="315" src="http://www.youtube.com/embed/qq45-bID1G0" frameborder="0" allowfullscreen></iframe></p>
<p>In this edition of Security Minute, Derek Manky, Fortinet’s senior security strategist, wraps up 2011 with his predictions of the type of network security threats we might see in 2012. Here’s a link to the full report for more detailed info: <a href="http://blog.fortinet.com/2012-threat-predictions/">http://blog.fortinet.com/2012-threat-predictions/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/security-minute-december-2011-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security risks of BYOD policies (podcast interview)</title>
		<link>http://blog.fortinet.com/security-risks-of-byod-policies-podcast-interview/</link>
		<comments>http://blog.fortinet.com/security-risks-of-byod-policies-podcast-interview/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 16:59:16 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Threat Landscape]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3896</guid>
		<description><![CDATA[Now that the holidays are over, many users will be bringing their new devices and gadgets into the workplace in the new year. Fortinet's Derek Manky and Network World's Keith Shaw discuss some of the risks associated with these devices, and how companies need to update their BYOD (Bring Your Own Device) policies to make sure end users understand the risks and consequences. ]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-3897" href="http://blog.fortinet.com/security-risks-of-byod-policies-podcast-interview/keith-shaw-12/"><img class="alignleft size-full wp-image-3897" title="Keith Shaw" src="http://blog.fortinet.com/wp-content/uploads/2012/01/Keith-Shaw1.jpg" alt="" /></a>Now that the holidays are over, many users will be bringing their new devices and gadgets into the workplace in the new year. <a href="http://www.networkworld.com/podcasts/secthreat/2011/122011securitylandscape.html">Fortinet&#8217;s Derek Manky and Network World&#8217;s Keith Shaw discuss some of the risks associated with these devices, and how companies need to update their BYOD (Bring Your Own Device) policies to make sure end users understand the risks and consequences.</a> (12:41)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/security-risks-of-byod-policies-podcast-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security threat predictions for 2012 (Podcast interview)</title>
		<link>http://blog.fortinet.com/security-threat-predictions-for-2012-podcast-interview/</link>
		<comments>http://blog.fortinet.com/security-threat-predictions-for-2012-podcast-interview/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 16:53:05 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3888</guid>
		<description><![CDATA[Network World looks back at their security predictions from 2011 to see how they did, and look forward to 2012 to see what threats lie on the security threat landscape horizon. ]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-3889" href="http://blog.fortinet.com/security-threat-predictions-for-2012-podcast-interview/keith-shaw-11/"><img class="alignleft size-full wp-image-3889" title="Keith Shaw" src="http://blog.fortinet.com/wp-content/uploads/2012/01/Keith-Shaw.jpg" alt="" /></a>Network World looks back at their security predictions from 2011 to see how they did, and look forward to 2012 to see what threats lie on the security threat landscape horizon. <a href="http://www.networkworld.com/podcasts/secthreat/2012/010312securitylandscape.html">Fortinet&#8217;s Derek Manky and Network World&#8217;s Keith Shaw chat about upcoming threats, including mobile device ransomware, Android worms, SCADA under the microscope and whether hactivists will turn vigilante to hack for a good cause.</a> (21:26)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/security-threat-predictions-for-2012-podcast-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing CarrierIQ&#8217;s defense</title>
		<link>http://blog.fortinet.com/analyzing-carrieriqs-defense/</link>
		<comments>http://blog.fortinet.com/analyzing-carrieriqs-defense/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 13:38:59 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[carrier]]></category>
		<category><![CDATA[ciq]]></category>
		<category><![CDATA[manufacturer]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[spy]]></category>
		<category><![CDATA[threat]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3851</guid>
		<description><![CDATA[A few days ago, CarrierIQ published a 19-page report detailing their software and business. I read the 19 pages, and in case you were wondering, the statements of my previous blog post still stand, even more, they are confirmed so I have updated the FAQ with extra data. Some my comments on the report below. [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, CarrierIQ published a <a href="http://www.carrieriq.com/PR.20111212.pdf">19-page report</a> detailing their software and business. I read the 19 pages, and in case you were wondering, <a title="Carrier IQ on Android – FAQ" href="http://blog.fortinet.com/carrier-iq-on-android-faq/">the statements of my previous blog post still stand</a>, even more, they are confirmed so I have updated the FAQ with extra data. Some my comments on the report below.</p>
<p><strong>&#8220;The IQ Agent uploads diagnostic data once per day, at a time when the device is not being used&#8221; (page 4)</strong></p>
<p>This is hardly a defense to me. People do not like that their phone is being used without their consent, even if it is for good reasons.<br /> When I buy a car, I pay for it, and I don&#8217;t expect anybody to drive it without asking my permission. This is still the case if that person is kind enough to use the car while I don&#8217;t need it. It is even still the case if that person pays for the fuel.<br /> It&#8217;s my car, you ask if you want to borrow it. Right?<br /> It&#8217;s the same for my phone. I bought a phone, I paid for it, it&#8217;s my phone. I don&#8217;t expect anybody to use it (call, SMS, Internet whatever) without asking my permission. And this is still the case even if my phone is used when I don&#8217;t need it. And even if I don&#8217;t pay for the communication.</p>
<p><strong>&#8220;Carrier IQ&#8217;s software has access to no more data than any other application on a device&#8221; (page 5)</strong></p>
<p>On Android devices, access to data is regulated by asking for specific permissions.<br /> <strong><em>True</em></strong>, CarrierIQ has to request those permissions like any other application, but <strong>the difference is that CarrierIQ gets those permissions without asking for end-user&#8217;s consent</strong>, whereas other applications do.<br /> Indeed, CarrierIQ is already installed on the device when the end-user gets it. He/she is never prompted with any screen asking whether he/she agrees to such permissions. Probably even worse, the end-user is not even aware of the presence of CIQ.</p>
<p>&#8220;<strong>&#8230; [in bold] what is actually gathered by a Network Operator is based on their business requirements and the agreements they form with their</strong> <strong>consumers on data collection.</strong>&#8220;<strong> (page 7)</strong></p>
<p>Besides I wonder how operators react to this line of defense &#8220;it&#8217;s not my fault, it&#8217;s theirs&#8221;, I believe end-users do not really care <em><strong>who</strong></em> is to blame &#8211; CarrierIQ, manufacturers and network operators &#8211; as long as the situation never happens again.<br /> At a second thought, actually, Carrier IQ&#8217;s sentence <strong>acknowledges someone should have asked for end-users agreement.</strong></p>
<p><strong>&#8220;The IQ Agent does not use the Android log files to acquire or output metrics&#8221; (page 8)</strong></p>
<p>I don&#8217;t think anybody ever suggested they were using log files to acquire data.<br /> As to using them to output data, I disagree.  CarrierIQ actually acknowledges on the next page using a &#8220;secure temporary location on the device&#8221; (page 9). It should be noted than on Android, which is a Unix-based system, everything is, by design, a file. So, this &#8220;secure temporary location&#8221; is a file (if ever this is important). And it contains metrics gathers by the IQ agent. <strong>This is logging</strong>. The fact the log is not directly human readable is irrelevant to the definition of logging.<br /> Anyway, the debate is not over &#8220;using human-readable files or not&#8221; but over &#8220;is somebody reading and eventually storing data&#8221;.<br /> <a title="Carrier IQ on Android – FAQ" href="http://blog.fortinet.com/carrier-iq-on-android-faq/">As I already said</a>, CarrierIQ does not provide any detail on how this temporary location is secured. Let&#8217;s hope it&#8217;s good.</p>
<p><strong>&#8220;The embedded version of IQ Agent metrics allows for the collection of URLs [..] the IQ Agent cannot read or copy the content of a website&#8221; (page 9)</strong></p>
<p>Ok. How would you react to this claim: &#8220;I did not spy on your readings, I only got the titles and reference of the books<br /> you read, not their content!&#8221;?<br /> It&#8217;s exactly the same here. CarrierIQ does not get the content of the pages I visited, but the URLs. The problem is that leaking a URL is already significant. It will say which pages we are visiting. In several cases, the URL also contains additional arguments which will for instance state our login name, session id etc.</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/analyzing-carrieriqs-defense/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2012 Threat Predictions</title>
		<link>http://blog.fortinet.com/2012-threat-predictions/</link>
		<comments>http://blog.fortinet.com/2012-threat-predictions/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 21:45:36 +0000</pubDate>
		<dc:creator>RPopko</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3867</guid>
		<description><![CDATA[Looking back on 2011, FortiGuard Labs saw a number of landmark developments in the world of network security. Huge botnets such as DNS Changer and Coreflood were permanently taken off line, 64-bit rootkits advanced (TDSS), source code was leaked for the Zeus and SpyEye botnets , and Anonymous hacktivists raised their profile by taking down [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="attachment wp-att-3868" href="http://blog.fortinet.com/2012-threat-predictions/fortune_teller/"><img class="alignleft size-full wp-image-3868" title="fortune_teller" src="http://blog.fortinet.com/wp-content/uploads/2011/12/fortune_teller.jpg" alt="" width="213" height="268" /></a> Looking back on 2011, FortiGuard Labs saw a number of landmark developments in the world of network security. Huge botnets such as DNS Changer and Coreflood were permanently taken off line, 64-bit rootkits advanced (TDSS), source code was leaked for the Zeus and SpyEye botnets , and Anonymous hacktivists raised their profile by taking down major banks offline and threatening to go after a critical infrastructure.</p>
<p>Many of these events the team predicted in their “<a href="http://blog.fortinet.com/top-5-security-predictions-for-2011/">Top 5 Security Predictions for 2011</a>,” while others, such as legislation to potentially jail and fine individuals who had malicious code stored on computer systems were more surprising.</p>
<p>2012 promises to be even more worrisome. After gazing into FortiCrystalball this month, FortiGuard Labs saw eight network security trends that could happen in the coming year.  In short, the Labs are predicting a rise of mobile malware (with new worms and polymorphism) , increased crackdowns on network run money laundering operations,  renewed and successful collaboration between government and the private sectors, discoveries of exploitable SCADA vulnerabilities, an increase in sponsored attacks, and Anonymous hacktivists using their powers for good over evil.  The full report is outlined below.</p>
<p>1.	Ransomware to Take Mobile Devices Hostage<br />
Over the past few years, FortiGuard Labs has witnessed the evolution and success of “ransomware” (an infection that holds a device “hostage” until a “ransom” payment is delivered) on the PC. Mobile malware that utilize exploits have also been observed, along with social engineering tricks that lead to root access on the infected device. With root access comes more control and elevated privileges, suitable for the likes of ransomware. FortiGuard predicts the team will see the first instances of ransomware on a mobile device in the coming year.</p>
<p>2.	 Worming into Android<br />
Worms, i.e., malware that is able to quickly propagate from one device to another, have by and large remained absent from the Android operating system, but FortiGuard Labs believes that will change in 2012. Unlike Cabir, the first Symbian worm discovered in 2004, Android malware developers most likely won’t be using Bluetooth or computer sync to spread out because of their limited ranges. Instead, the team believes the threat will come from either poisoned SMS messages that include a link that contains the worm or through infected links on social networks, such as Facebook and Twitter.</p>
<p>3.	Polymorphism Want a Cracker?<br />
There’s no denying that Android-based malware has gotten more diverse and complex. In the last year: FortiGuard Labs has seen Android malware use encryption, embed exploits, detect emulators and implement botnets. But what they haven’t seen yet is an example of polymorphism in action. Polymorphism is malware that is capable of automatically mutating, making it extremely difficult to identify and thus destroy. The team has previously encountered polymorphism on Windows Mobile phones and believes it’s only a matter of time before the malware appears on Android devices.</p>
<p>4.	Clampdown on Network-Based Money Laundering<br />
Money mules, which typically consist of third party individuals electronically transferring money from one person or service to another and illegitimate payment processors, are critical components to a successful money laundering and fraud operation. Using anonymous fund transferring services, human networks and payment processor safe havens, cybercriminal syndicates have pretty much operated with impunity for years. How do you catch someone when you don’t even know where they’re located?  FortiGuard believes that will change in 2012 [By this, are you saying in 2012 we expect to be able to catch these people?]. The recent arrest of ChronoPay CEO Pavel Vrublevsky&#8217;s on the grounds of hacking Aerfolot&#8217;s Website and preventing visitors from buying tickets, is a good example of the type of takedowns the team expects to see in the coming year.</p>
<p>5.	Public-Private Relationships in Security<br />
Last year FortiGuard Labs predicted they’d see an increase in global collaborative botnet takedowns. And they were right not only with botnet takedowns, but global collaboration period. Among globally-supported botnet takedowns were Rustock and DNS Changer while other international efforts helped take a massive scareware operation offline that siphoned $72 million in bank funds. Meanwhile, arrests were made against international members of Anonymous and LulzSec hacktivist groups. This crackdown will continue in 2012, and the team believes that much of it will be aided by Defense Advanced Research Projects Agency’s (DARPA’s) public defense initiative.  DARPA was recently granted $188 million budget and plans to use part of the money on initiatives to build a cyber defense team in the private sector. With recent movement, it seems likely that in 2012 we will start to see similar relationships formed worldwide.</p>
<p>6.	SCADA Under the Scope<br />
For over a decade, Supervisory Control and Data Acquisition- (SCADA) based threats have been a concern, because they are often connected to critical infrastructure such as power and water grids that would have  serious consequences if they were ever breached. This last year FortiGuard saw two examples of this in the form of Stuxnet, which compromised Iran’s nuclear program and Duqu, a Stuxnet-like virus that used similar attack methods and stolen certificates. While Iranian officials confirmed the latter had infected systems in the region, no hostile industrial code has been found to date. However, it&#8217;s clear the building blocks are now in place. The reality today is that critical infrastructure systems are not always operating on a closed circuit. New human machine interface (HMI) devices that interact with these systems are being developed by a number of different software and hardware manufacturers, and many have Web interfaces for logging in. And the FortiGuard team has seen historically that Web-based interfaces that interact with back end systems can many times be circumvented. Even more concerning is the migration to cloud-based SCADA services. This allows data storage and potential control of critical systems on a public cloud server – hence the security concern. Groups like Anonymous have already found an assortment of Web-based vulnerabilities simply by picking targets and scouring code.  In 2012, FortiGuard predicts a number of SCADA vulnerabilities will be discovered and exploited with potentially devastating consequences.</p>
<p>7.	Sponsored Attacks<br />
The FortiGuard team often talks about Crime as a Service (CaaS), which is just like Software as a Service (SaaS), but instead of offering legal and helpful services though the Internet, criminal syndicates are offering illegal and detrimental services, such as infecting large quantities of computers, sending spam and even launching direct denial of service (DDoS) attacks. If you’ve got the money, there’s a good chance you can find a CaaS provider to help you out. What FortiGuard sees evolving in 2012, is that instead of hiring a CaaS outfit for blanket attacks, they’re going to see more strategic and targeted attacks on companies and individuals.  This scope would include state or corporate sponsorship. Admittedly, this prediction will be tough to monitor because without “freedom of information” legislation in place, many of these discovered cases will be settled out of court with verdicts not being released publicly.  For example, Russian payment processor ChronoPay allegedly hired a hacker to attack a direct competitor (Assist) in 2011.</p>
<p>8.	Hacking a Good Cause<br />
While Anonymous has been alive and kicking in one capacity or another since its formation on 4Chan.org in 2003, only in the last year have the loosely organized anarchists started using their power to attack large, high profile targets such as Sony.  More hacktivist groups were formed in 2011 (most notably LulzSec), and more will likely rise in 2012. What FortiGuard found interesting about Anonymous towards the end of the year, was how the group started to use their power for “good.” Case in point, they’ve recently threatened to unmask Mexican drug cartel members and they recently helped authorities break up a child porn ring. FortiGuard expects to see more examples of “hacktivist” justice meted out throughout 2012 along with a mix of attacks that border or cross the line of justice.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/2012-threat-predictions/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Android/Foncy emanating and propagating in France</title>
		<link>http://blog.fortinet.com/androidfoncy-emanating-and-propagating-in-france/</link>
		<comments>http://blog.fortinet.com/androidfoncy-emanating-and-propagating-in-france/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 15:02:39 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[mobile malware]]></category>
		<category><![CDATA[premium]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[suiconfo]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3824</guid>
		<description><![CDATA[It doesn&#8217;t happen that often altogether that mobile malware specifically come from France and propagate in France. It however seems to be the case this time for an Android malware named Foncy &#8211; not that there should be any national pride in creating malware. Foncy has first been spotted by Denis Maslennikov. It is a [...]]]></description>
			<content:encoded><![CDATA[<p>It doesn&#8217;t happen that often altogether that mobile malware specifically come from France and propagate in France. It however seems to be the case this time for an Android malware named <a href="http://www.fortiguard.com/latest/mobile/3320403">Foncy</a> &#8211; not that there should be any national pride in creating malware.</p>
<p>Foncy has first been spotted by <a href="http://www.securelist.com/en/blog/208193261/SMS_Trojans_all_around_the_world">Denis Maslennikov.</a> It is a dialer, i.e it sends SMS messages to premium numbers, without user&#8217;s consent. It does not spread by itself: victims are infected when they download and install the malware, likely from an alternate marketplace. They probably just wanted to try out an application, which happened to be the malware.</p>
<p>The application&#8217;s name (SuiConFo) &#8211; which is a French abbreviation for tracking mobile plans &#8211; immediately rang a bell in our French anti-virus labs. Since then, Karine de Ponteves and I, have been able to track information on this malware.</p>
<p>The malware looks like former versions of a legitimate application named <a href="https://market.android.com/details?id=com.aloudroid.suiviforfait">Track Your Plan</a>. The code and signing certificate bear however <em>absolutely no similarity</em>.</p>
<table border="0">
<tbody>
<tr>
<td>
<p> </p>
<p> </p>
<p> </p>
<p><div id="attachment_3828" class="wp-caption aligncenter" style="width: 158px"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/suiconfo-legitimate.jpg"><img class="size-full wp-image-3828  " title="suiconfo-legitimate" src="http://blog.fortinet.com/wp-content/uploads/2011/12/suiconfo-legitimate.jpg" alt="" width="148" height="381" /></a><p class="wp-caption-text">Contents of the legitimate plan tracking application</p></div></td>
<td>
<p> </p>
<p> </p>
<p> </p>
<p><div id="attachment_3829" class="wp-caption aligncenter" style="width: 146px"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/suiconfo-infected.jpg"><img class="size-full wp-image-3829 " title="suiconfo-infected" src="http://blog.fortinet.com/wp-content/uploads/2011/12/suiconfo-infected.jpg" alt="" width="136" height="115" /></a><p class="wp-caption-text">Contents of the malicious plan tracking application</p></div></td>
</tr>
</tbody>
</table>
<p> </p>
<p> </p>
<p>In France, <strong>the malware sends 4 SMS to short number 81001, with body &#8220;STAR&#8221;</strong>. <strong>Each SMS costs <em>4.50</em> euros</strong>. The short number is a SMS+ number, rented to a French company, who in turn rents it to its customers and other intermediaries. Searching the web, <strong>we found several French users complaining about their bill and obviously infected by the malware</strong>.</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/complaint-l1.jpg"><img class="aligncenter size-full wp-image-3831" title="complaint-l" src="http://blog.fortinet.com/wp-content/uploads/2011/12/complaint-l1.jpg" alt="" width="461" height="167" /></a></p>
<p>Actually, the French short number 81001 seems to be involved in several scams. For example, an end-user below reports he received an e-mail telling him he had won an iPhone 4 and was being asked to send an SMS to 81001 with body &#8220;STAR&#8221;. The e-mail looks like it comes from a Fabrice Andre from Orange. Actually, a Fabrice Andre of Orange does exist, but certainly hasn&#8217;t sent this e-mail. The operator Orange is aware of this scam.</p>
<p><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/Voila_Capture17.jpg.resize.jpeg"><img class="aligncenter size-full wp-image-3833" title="Voila_Capture17.jpg.resize" src="http://blog.fortinet.com/wp-content/uploads/2011/12/Voila_Capture17.jpg.resize.jpeg" alt="" /></a></p>
<p>We also acknowledged a discussion on a French forum where<strong> a member was boasting about a new method to make easy money using 81001</strong>. He explained he opened a <a href="http://www.starpass.fr/">StarPass</a> account (StarPass is a micro-payment system &#8211; via SMS), and then would ask his Facebook contacts to send a SMS to 81001.</p>
<p> </p>
<p> </p>
<p> </p>
<p><div id="attachment_3841" class="wp-caption aligncenter" style="width: 543px"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/wayne-truc.jpg"><img class="size-full wp-image-3841" title="wayne-truc" src="http://blog.fortinet.com/wp-content/uploads/2011/12/wayne-truc.jpg" alt="" width="533" height="389" /></a><p class="wp-caption-text">WeeyWayne explains how he makes money out of 81001</p></div>
<p> </p>
<p> </p>
<p style="text-align: center;"> </p>
<p>For each 4.50 euro SMS received, StarPass pays back the author 2 euros.</p>
<p> </p>
<p> </p>
<p> </p>
<p><div id="attachment_3834" class="wp-caption aligncenter" style="width: 568px"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/btuye.png"><img class="size-full wp-image-3834" title="btuye" src="http://blog.fortinet.com/wp-content/uploads/2011/12/btuye.png" alt="" width="558" height="77" /></a><p class="wp-caption-text">For each SMS &quot;A&quot; (client cost 4.5 euros), you receive 2.00 euros (in French)</p></div>
<p> </p>
<p> </p>
<p style="text-align: center;"> </p>
<p>Additionally, Android/Foncy listens to incoming responses from 81001 and <strong>forwards the answers by SMS to a French mobile number 06xxxxxxxx</strong>. This mobile number belongs to SFR, who has been notified.</p>
<p><strong>French mobile phone subscribers should be particulary wary of abnormal SMS bills</strong>, as the short number 81001 and the mobile line 06xxxxxxxx are still active at the time of writing this blog, and <strong>Android/Foncy is still in the wild</strong>. End-users should complain to their operator and/or report any unsollicited spam to the French service <a href="www.33700-spam-sms.fr">33700</a>.</p>
<p>To this date, we do not know the amount of French victims, and will keep you informed.</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/androidfoncy-emanating-and-propagating-in-france/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Carrier IQ on Android &#8211; FAQ</title>
		<link>http://blog.fortinet.com/carrier-iq-on-android-faq/</link>
		<comments>http://blog.fortinet.com/carrier-iq-on-android-faq/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 15:24:05 +0000</pubDate>
		<dc:creator>Axelle</dc:creator>
				<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ciq]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[spy]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=3806</guid>
		<description><![CDATA[Q1- The basics. What is Carrier IQ? CarrierIQ is a controversial piece of code which was intentionally placed on several mobile phones by their vendors or carriers. It has the capability of monitoring and/or collecting various information &#8211; without user&#8217;s consent. Q2- What is Carrier IQ exactly doing? Precisely, CarrierIQ (CIQ) has developed a series [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Q1- The basics. What is Carrier IQ?</strong></p>
<p><a href="http://www.carrieriq.com">CarrierIQ</a> is a controversial piece of code which was intentionally placed on several mobile phones by their vendors or carriers.<br />
It has the capability of monitoring and/or collecting various information &#8211; without user&#8217;s consent.</p>
<p><strong>Q2- What is Carrier IQ exactly doing?</strong></p>
<p>Precisely, CarrierIQ (CIQ) has developed a series of hooks to monitor plenty of metrics such as:</p>
<ul>
<li>HT01: HTTP request URI</li>
<li>AL15: browser&#8217;s URL</li>
<li>MG01: SMS recipient and SMS center</li>
<li>MG03: SMS originator</li>
<li>MG11: MMS version, sender, recipient and relay URL</li>
<li>HW10: min and maximum battery voltage, capacity, model</li>
<li>HW11: battery&#8217;s voltage and temperature</li>
<li>LC18: altitude, latitude, longitude, uncertainty, velocity&#8230;</li>
</ul>
<p>See for instance the MG11 metric below:</p>
<div id="attachment_3808" class="wp-caption aligncenter" style="width: 374px"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/ciq-mg.png"><img class="size-full wp-image-3808 " title="ciq-mg" src="http://blog.fortinet.com/wp-content/uploads/2011/12/ciq-mg.png" alt="" width="364" height="305" /></a><p class="wp-caption-text">MG11 metric used by CarrierIQ</p></div>
<p style="text-align: center;">&nbsp;</p>
<p>A broader view of available metrics is available <a href="http://androidsecuritytest.com/wp-content/uploads/2011/11/metric_categories1.png">here</a> and <a href="http://androidsecuritytest.com/wp-content/uploads/2011/11/metrics.png">here</a>.</p>
<p>Then, OEMs and carriers pick up which metrics they are interested in, and integrate it to the phone. The data goes to remote portals which are controlled by the OEMs or carriers.</p>
<p>Interesting to read: <a href="http://vulnfactory.org/blog/2011/12/05/carrieriq-the-real-story/">Dan Rosenberg, &#8220;Carrier IQ: the Real Story&#8221; </a></p>
<p>&nbsp;</p>
<p><strong>Q3- So in spite of what their executives are <a href="http://allthingsd.com/20111201/carrier-iq-speaks-our-software-monitors-service-messages-ignores-other-data/">claiming</a>, CarrierIQ &#8220;logs&#8221; my personal data?</strong></p>
<p>The short answer is yes, it does: Some of your actions on your phone are being silently reported to a third-party without your knowledge, and this is what we call logging.</p>
<p>Now indeed, it is true that CIQ may not log <strong>all</strong> our actions, and that it does not do so for itself: indeed,  although it constantly monitors<strong> </strong>everything, some actions may not be reported (and thus, simply dropped) to the  carrier and/or vendor, depending on which metrics (see Q2 above) the  latter cared to enable. As of this writing, we do not know which  vendors/carriers enable which metrics.</p>
<p><strong>Q4- Does it hamper my phone&#8217;s security?</strong></p>
<p>In short: yes. But if you have time for more details, read the reasons below.</p>
<ol>
<li>CIQ is no more no less than a rootkit &#8211; even if it was (perhaps) designed for benign usage. Like rootkits, CIQ&#8217;s service runs as root on the phone. Like rootkits, CIQ hooks basic functionalities on the phone (keys pressed, opened applications, SMS received etc). Finally, like rootkits, CIQ tries to hide itself, and as a matter of fact, end-users weren&#8217;t aware of its existence. CIQ does not display any application icon, it is not listed in installed application, and does not come with any policy.</li>
<li>As <a href="http://androidsecuritytest.com/features/logs-and-services/loggers/carrieriq/carrieriq-part2/">Trevor Eckart&#8217;s video shows</a>, each time we press a key, this is shown as a new line of Android&#8217;s logcat. Logcat is a system feature &#8211; it does not belong to CIQ &#8211; which is the first reason CIQ argues it does not log anything. True. But<strong> if someone has access to logcat, he/she can still monitor all our actions</strong> &#8211; which is a threat to your privacy and confidentiality.</li>
<li>Moreover, actually, there is a log file: Carrier IQ has still admitted keeping <strong>a temporary log, and there are no details of how that temporary file is secure</strong>. The answer <a href="http://www.theverge.com/2011/12/3/2608995/carrier-iq-denies-responsiblity-insecure-log-files-blames-manufacturers">&#8220;it&#8217;s not readable if you don&#8217;t have our tools&#8221;</a> does not sound good to me. It sounds like some hand-made obfuscation or crypto, and over years, this has never proven to be secure.</li>
</ol>
<p>Interesting to read: Trevor Eckart, <a href="http://androidsecuritytest.com/features/logs-and-services/loggers/carrieriq/">What is Carrier IQ?</a>.</p>
<p><strong>Q5- Do I have CIQ on my phone?</strong></p>
<p>Carrier IQ has been found on several Android phones, but it actually also exists on other platforms, <a href="http://blog.chpwn.com/post/13572216737">such as iPhone</a>.</p>
<p>Fortinet detects it as Riskware/CarrierIQ!Android.</p>
<p>Alternatively, you may install an application to check if your phone has CIQ or not. There are Android apps for that, such as <a href="https://market.android.com/details?id=com.lookout.carrieriqdetector">Lookout&#8217;s Carrier IQ Detector</a> or  <a href="https://market.android.com/details?id=org.projectvoodoo.simplecarrieriqdetector">Project Voodo</a> (not tried).</p>
<p style="text-align: center;"><a href="http://blog.fortinet.com/wp-content/uploads/2011/12/SC20111208-114954.png"><img class="size-full wp-image-3810 aligncenter" title="SC20111208-114954" src="http://blog.fortinet.com/wp-content/uploads/2011/12/SC20111208-114954.png" alt="" width="173" height="288" /></a></p>
<p>If you are a phone geek, you can do this manually by searching for one of the following files:</p>
<pre>/system/app/com.htc.android.iqagent.apk
/system/app/com.carrieriq.tmobile.apk
/system/app/com.carrieriq.iqagent.apk
/system/app/com.carrieriq.attrom.apk
/system/app/HtcLoggers.apk
/system/app/HTCIQAgent.apk
/system/bin/iqfd
/system/bin/iqd
/system/lib/libciq_client.so
/system/lib/libciq_htc.so
/system/lib/libhtciqagent.so
/system/etc/iqprofile.pro</pre>
<p>Interesting to read: Trevor Eckart, <a href="http://forum.xda-developers.com/showthread.php?t=1247108">[DEV|APPv7] CIQ / HTC &amp; Google Checkin / HTC loggers / Tell HTC Info &amp; Removal</a></p>
<p><strong>Q6- How to get rid of Carrier IQ?</strong></p>
<p>Unfortunately, it is difficult to get rid of CIQ because it has been built directly into the OS of the device, or packaged in the OEM&#8217;s/carrier&#8217;s ROM.</p>
<p>Consequently, you need to first root the phone and then</p>
<ol>
<li>either you flash the ROM with a custom ROM that does not contain Carrier IQ.</li>
<li>or you use Trevor Eckart&#8217;s <a href="http://forum.xda-developers.com/showpost.php?p=17612559&amp;postcount=110">tool</a> (1 USD)</li>
<li>or you try the <a href="http://androidforums.com/evo-4g-all-things-root/458012-ciq-strip-down.html">Remove CIQ script</a>, that removes CIQ files on the phone.</li>
</ol>
<p>We haven&#8217;t tried any of these, so beware.</p>
<p><strong>UPDATE Dec 16, 2001:</strong></p>
<p>CarrierIQ does not leak SMS bodies<strong> in the general case</strong>. Actually, CIQ leaks the SMS in some cases only because of a design level bug: if CIQ is capturing GSM network traffic, at at the same time the phone receives a SMS, of course, the contents of the SMS will be included in the network capture&#8230;</p>
<p>&#8211; the Crypto Girl</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/carrier-iq-on-android-faq/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

