Risk
2/1/2012
12:01 PM
Connect Directly
RSS
E-Mail
50%
50%

Counterclank Apps To Remain In Android Market

Some security experts call Counterclank apps malware, not adware. But Google says the apps comply with the company's terms of service.

10 Great Android Collaboration Apps
10 Great Android Collaboration Apps
(click image for larger view and for slideshow)
Google said a controversial set of advertising-supported Android apps will remain in its official Android Market, because they comply with the company's terms of service. The 13 apps in question, which Google said have been collectively downloaded up to 5 million times, use adware software known as Counterclank.

Symantec first sounded the alarm over Counterclank last week, labeling the software--which is part of such apps as Counter Strike Ground Force, Balloon Game, and Sexy Girls Puzzle--as malware. But rival mobile security firm Lookout published its own analysis of the Counterclank software, also known as the Apperhand software development kit, and came to a different conclusion, instead labeling it as adware.

Notably, Lookout found that although Apperhand was "aggressive" and perhaps demonstrated "bad form"--for example because it can change a smartphone browser's homepage, add arbitrary bookmarks, and place a search icon on the home screen--the software didn't exhibit signs of actually being malicious. Rather, it had all of the classic signs of being part of an adware platform, which some software developers use to earn money from their applications. In the case of Apperhand, that compensation appears to be largely based on driving the users of their apps to specified search engines.

[ Adware recently plagued Google and Facebook sites. Adware Reborn As Facebook Theme Software. ]

Symantec also said that it had alerted Google to the presence of Counterclank in 13 apps sold via the Android Market. But, it said, "Google replied quickly informing us the applications met their terms of service and they will not be removed."

If the "is it adware, or is it malware?" debate sounds familiar, that's because five years ago, controversy raged over how to classify advertising-supported software on Windows PCs. Although its purveyors often labeled their software as adware, security and antivirus companies more often than not labeled it as malware--in part because some so-called adware was actually malicious--and typically blocked both. Some pundits, meanwhile, helpfully just classifed it all as badware.

Likewise, in response to Lookout's analysis of Counterclank, Symantec this week said that regardless of whether the software counts as malware or adware, the bigger question is: Who wants it on their device?

"The situation we find ourselves in is similar to when adware, spyware, and potentially unwanted applications first made appearances on Windows," read a blog post from the Symantec Security Response Team. "Many security vendors did not initially detect these applications, but eventually, and with the universal approval of computer users, security companies chose to notify users of these types of applications."

"Due to the combined behavior of the applications, negative feedback from users who installed the applications, and the fact that previous applications (Android.Tonclank) using this code were initially suspended from the Google Market, we chose to notify users of Counterclank," said Symantec.

Interestingly, Counterclank is a new version of the Tonclank--aka Plankton--software development kit that first began appearing in Android apps this past summer. Although Google initially suspended apps that contained Tonclank, after further review it reinstated them in the Android Market.

Please join us on Feb. 15 for the InformationWeek & Dark Reading virtual event Clouds, Outsourcing, And Security Services: Making Providers Part of Your IT Security Strategy. When you attend, you will be able to access live and on-demand webcast presentations as well as virtual booths packed with free resources, and you can also be eligible to win great prizes! (Free registration required.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2021
Published: 2014-10-24
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.4.2 and earlier, and 5.0.x through 5.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted XMLRPC API request, as demonstrated using the client name.

CVE-2014-3604
Published: 2014-10-24
Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVE-2014-6230
Published: 2014-10-24
WP-Ban plugin before 1.6.4 for WordPress, when running in certain configurations, allows remote attackers to bypass the IP blacklist via a crafted X-Forwarded-For header.

CVE-2014-6251
Published: 2014-10-24
Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overflow with a mining.notify request.

CVE-2014-7180
Published: 2014-10-24
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by modifying these files.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.