Important: Mobilephone virus : cabir

Pravila foruma
Symbian deo foruma posvećen je uopštenoj priči o svemu vezanom za operativni sistem.
Ukoliko želite da pogledate teme vezane za određeni model telefona, možete to uraditi preko sledećih prečica:
NokiaSamsungSony Ericsson
stevo-makedonac
Slučajni prolaznik
Slučajni prolaznik
Postovi: 1
Pridružio se: Sre, 29. Sep 2004. 20:12
Lokacija: Macedonia
Kontakt:

Important: Mobilephone virus : cabir

Post od stevo-makedonac »

Ko misli da viruse za mobilni ne postoje gadno se vara! Citaj dalje:
:roll:
SymbOS.Cabir is a proof-of-concept worm that replicates on Series 60 phones. This worm repeatedly sends itself to the first Bluetooth-enabled device that it can find, regardless of the type of device. For example, even a Bluetooth-enabled printer will be attacked if it is within range. The worm spreads as a .SIS file, which is installed into the APPS directory.

There is no payload, apart from the vastly shortened battery life caused by the constant scanning for Bluetooth-enabled devices.

Technical Details:

SymbOS.Cabir is transmitted through Bluetooth as a .SIS file.

When the worm arrives at a target device the following may happen:


1.The device displays a message similar to the following; asking the user to accept a message from a particular device.
Recieve message via Bluetooth from ?

2.The user will be notified that they have received a new message.

3.The user will be prompted with a message similar to the following:
Application is untrusted and may have problems. Install only if you trust provider.

4.If the user chooses Yes, the user will be prompted to install the worm.

Install caribe?

5.If the user chooses Install, SymbOS.Cabir is installed and executed, displaying the message below.
Caribe-V2/29a

6.The worm creates the following files on the phone:
\\SYSTEM\\APPS\\CARIBE\\CARIBE.APP
\\SYSTEM\\APPS\\CARIBE\\CARIBE.RSC
\\SYSTEM\\APPS\\CARIBE\\FLO.MDL
\\SYSTEM\\SYMBIANSECUREDATA\\CARIBESECURITYMANAGER\\CARIBE.APP
\\SYSTEM\\SYMBIANSECUREDATA\\CARIBESECURITYMANAGER\\CARIBE.RSC
\\SYSTEM\\SYMBIANSECUREDATA\\CARIBESECURITYMANAGER\\CARIBE.SIS
\\SYSTEM\\RECOGS\\FLO.MDL
\\SYSTEM\\INSTALLS\\CARIBE.SIS

7.The worm attempts to send itself to other Bluetooth-enabled device that it finds, regardless of the type of device.

8.The worm executes every time the device is turned on.

REMOVAL INSTRUCTION:
To remove SymbOS.Cabir:

1.Install a file manager program on the phone.
2.Enable the option to view the files in the system directory.
3.Search the drives, A through Y, for the \\SYSTEM\\APPS\\CARIBE directory.
4.Delete the files CARIBE.APP, CARIBE.RSC, and FLO.MDL from the \\CARIB directory.
5.Go to the C:\\SYSTEM\\SYMBIANSECUREDATA\\CARIBESECURITYMANAGER directory.
6.Delete the files CARIBE.APP, CARIBE.RSC, and CARIBE.SIS.
7.Go to the C:\\SYSTEM\\RECOGS directory.
8.Delete the file, FLO.MDL.
9.Go to the C:\\SYSTEM\\INSTALLS directory.
10.Delete the file, CARIBE.SIS.

Note: You cannot delete the file CARIBE.RSC when the program is running.
If you cannot delete this file in steps 4 and 6, delete all the files that you can, restart the phone, and then delete the CARIBE.RSC file.

Additional information:

Symantec recommends the following to mitigate against this threat:

- If Bluetooth is not required, it should be turned off.
- If you require the use of Bluetooth, ensure that the devices\'s visibility setting is set to \"Hidden\" so that it can not be scanned by other Bluetooth devices.
- Avoid use of device pairing. If it must be used, ensure that all paired devices are set to \"Unauthorized\". This requires each connection request to be authorized by the user.
- Do not accept unsigned applications (no digital signature) or applications sent from unknown sources. Be absolutely sure of the origin of the application before accepting it.
:oops:

http://securityresponse.symantec.com/av ... cabir.html :twisted:

ima dopuski program koji popravlja to:cabir fix to remove cabir
:lol:

TheDunc
Neredovni učesnik
Neredovni učesnik
Postovi: 67
Pridružio se: Čet, 13. Maj 2004. 22:08
Lokacija: ljubljana

Post od TheDunc »

http://securityresponse.symantec.com/av ... cabir.html

kod linka mora biti sve napisano zajedno....
...don't happy, be worry...

Ludak
Mobil stručnjak
Mobil stručnjak
Postovi: 870
Pridružio se: Sub, 07. Avg 2004. 17:15
Lokacija: Zemlja telefona

Post od Ludak »

OK, ovo je kao 3 meseca staro, i ja stvarno ne znam nekoga ko zna da neko drugi ne zna za ovaj samoproglašeni virus, za koji mi znamo, ili barem ja znam, a zbog toga što znam da ne znam ni jednu osobu koja zna da ne zna neku drugu osobu koja ne zna za virus, to znači da svi znaju i da je vest bajata, mada što jes, jes, baš je iscrpan izveštaj. :D :lol: :lol:
U susret novim izazovima...

nbnebojsa
Mobil stručnjak
Mobil stručnjak
Postovi: 993
Pridružio se: Uto, 27. Jul 2004. 13:24
Lokacija: Novi Sad

Post od nbnebojsa »

taj cabir je vec odavno provaljen, ima decabir koji resava problem ako cabir uleti u fon nista strasno :lol:

`Dr. Nick Riviera`
Mobil manijak
Mobil manijak
Postovi: 1159
Pridružio se: Sre, 21. Jul 2004. 21:59
Lokacija: Digital Underground

Post od `Dr. Nick Riviera` »

Ovo sam ja davno okachio (na srpskom) i mislim da je virus istrebljen.
Antivirus mozete dowload-ovati sa wap.kaspersky.com :wink:
¨°o.O Nokia N70! O.o°¨

Miškoni
Administrator
Administrator
Postovi: 4096
Pridružio se: Pet, 30. Jul 2004. 07:08
:: Samsung S7
:: Huawei Y6
Lokacija: Beograd

Post od Miškoni »

Ok, sasvim je dovoljno rečeno i više nema šta da se dodaje, a i tema je već zastarela odavno, prema tome, lock! Ako pojavi neki novi virus ili bilo kakva maliciozna aplikacija, diskutovaće se u novoj temi.

Zaključana tema