Vulnerabilities / Threats
1/10/2013
08:58 AM
50%
50%

Apple Targets App Store Bait And Switch Scammers

Apple will lock down app screenshots after approval to stem a spate of sellers hawking fake apps.

Apple iTunes 11: Visual Tour
Apple iTunes 11: Visual Tour
(click image for larger view and for slideshow)
Apple has revised its app-submission rules to help block scammers who submit an app for approval, then later upload fake screenshots or alter descriptions to make the software appear to be more fully featured than it really is, or even a clone of another, well-known app.

In a developer note titled "Updating Screenshots in iTunes Connect" posted Wednesday, Apple said that "app screenshots will be locked in iTunes Connect once your app has been approved," and that the change is effective immediately. "New screenshots may be uploaded when you submit a binary for an update to an existing app or a new app."

The change affects all book, music, TV show, movie and app sellers, across iTunes Direct, the App Store, iBookstore and Mac App Store.

Bait-and-switch scams are commonplace in the real world, for example in restaurants that advertise one type of wine but replace it with a cheaper substitute, or via emails that promise free iPads, but simply lead to endless online surveys. "But switching out an actual application in the iOS world is much harder, because Apple vets each app first, then digitally signs it and only then makes it available for download," said Paul Ducklin, head of technology for Sophos in the Asia Pacific region, in a blog post. "Nevertheless, you can still run a scam, even with vetted and digitally signed apps."

[ Successful crimeware toolkit author is going on a $100,000 vulnerability shopping spree. See Blackhole Botnet Creator Buys Up Zero Day Exploits. ]

Indeed, over the past year, multiple scammers have submitted an app to Apple, gotten it approved and then later altered the screenshots or listing details. In February, for example, scammers placed a clone of Nintendo's "Pokemon Yellow" game in the App Store. They sold an unknown number of copies before users complained and Apple yanked the application, reported iOS gaming site TouchArcade. The scammers knew their target market well: Nintendo doesn't sell any apps via the Apple App Store, which would have made the app immediately attractive to Pokemon fans.

The Pokemon app was completely non-functional, reported TouchArcade. Even so, "people have been scrambling over the thousand or so one-star reviews in order to give it a spin," it said at the time, noting that it quickly became the third most popular paid app. "Money is being made here, and it's the significant variety," said TouchArcade.

Another scam, meanwhile, involved Minecraft clones, including one titled "Mooncraft." Scammers apparently "used different screenshots to get past Apple reviewers, and then later changed the game information," substituting actual screenshots from the real Minecraft game, reported MacRumors. It noted that Apple, in the past, has reimbursed people who purchased scam apps.

Why scam iOS app buyers? Given the number of people who download iOS apps, attackers could arguably turn a quick profit. On the other hand, Apple only pays developers once per month, meaning that a successful scammer would have had to game not only Apple's app-approval process, but also payment timetable.

Still, those hurdles haven't deterred every would-be scammer, which led Ducklin to praise Apple's changes. "Looks like this particular bait-and-switch game is up. Good," he said. "Of course, one wonders why Apple, a company that is so punctilious about the actual software it lets into the App Store, hasn't enforced a corresponding precision in App Store advertising all along."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
1/21/2013 | 3:03:53 AM
re: Apple Targets App Store Bait And Switch Scammers
This seems like such a simple solution, why was this not thought of earlier before Apple accounts were compromised due to fake apps? There are way to many scams out there in the digital world for a consumer to not be weary of every purchase they make and how it will effect their digital world.

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2208
Published: 2014-12-28
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

CVE-2014-2209
Published: 2014-12-28
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory.

CVE-2014-5386
Published: 2014-12-28
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initial...

CVE-2014-6228
Published: 2014-12-28
Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split ...

CVE-2014-6229
Published: 2014-12-28
The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key string uses '\0' for termination, which allows remote attackers to obtain sensitive information by leveraging read access beyond the end of the string,...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.