Strict Standards: Only variables should be assigned by reference in /home/noahjames7/public_html/modules/mod_flexi_customcode/tmpl/default.php on line 24

Strict Standards: Non-static method modFlexiCustomCode::parsePHPviaFile() should not be called statically in /home/noahjames7/public_html/modules/mod_flexi_customcode/tmpl/default.php on line 54

Strict Standards: Only variables should be assigned by reference in /home/noahjames7/public_html/components/com_grid/GridBuilder.php on line 29

SAN FRANCISCO — Hackers have found their way into Apple’s App Store.

Apple confirmed on Sunday that a tool used by software developers for the company’s devices was copied and modified by hackers to put bad code into apps available on the App Store.

So far about 40 apps with malicious code, or malware, have made it into the App Store, said researchers at Palo Alto Networks, an online security company that is investigating the incident. In a blog post, the security company said the breach could potentially affect hundreds of millions of users.

The list includes some of the most popular apps in China, like the ride-hailing app Didi Kuaidi. Many of the apps are popular elsewhere as well, like the messaging app WeChat, which has about 500 million users, and the business card scanner CamCard. The Chinese online security company Qohoo said it has found more than 300 infected apps.

The fake developer code “was posted by untrusted sources,” said Christine Monaghan, an Apple spokeswoman. “To protect our customers, we’ve removed the apps from the App Store that we know have been created with this counterfeit software.”

It was unclear on Sunday how many people had downloaded the apps based on the hacked developer tool. Security researchers at the giant Chinese e-commerce company Alibaba, Palo Alto Networks, the app makers and Apple are working to assess the damage, said Ryan Olson, who leads a threat research team Palo Alto Networks.

Chatter about modified versions of the developer code, called Xcode, started to surface last week on Weibo, China’s version of Twitter.

Researchers found that some copied versions of Xcode had been modified to embed malicious software into apps. As app makers checked to see whether their products had been infected, Apple and security researchers worked to find and get rid of the bad versions of Xcode, which were all on a cloud hosting service owned by the Chinese Internet company Baidu. Mr. Olson said Baidu has removed them.

Apple said on Sunday that it was working with developers to make sure they were using the proper version of Xcode, the tool used to create the apps.

Once the infected apps are downloaded, researchers said, the malicious code can open particular websites designed to infect the device with more viruses. It can also open innocuous-looking pop-up screens that ask users for more information, like passwords to their Apple account.

“Since the dialogue is a prompt from the running application, the victim may trust it and input a password without suspecting foul play,” Palo Alto Networks said in its blog post.

Researchers said only the most recent versions of the apps created with the counterfeit version of Xcode were at risk.

This security breach illustrates the lengths to which hackers will go to break into Apple’s hardware and software, which has long been thought of as having superior security.

“Apple has been extremely successful at keeping malware out of the App Store,” Mr. Olson said.

Mr. Olson said that even in this case, hackers did not crack Apple’s software. Instead they took advantage of the fact that many Chinese developers use copies of Xcode that are held on Chinese servers, since they load faster than the version of the code that’s available from Apple.

The bad Xcode was available only to those developers who had disabled Apple’s safety features. Otherwise Apple would have presented a warning that something was wrong with Xcode, Mr. Olson said.

Many of the websites that were receiving stolen information have been discovered and shut down, according to researchers.

Mr. Olson said versions of Xcode from Apple should be safe.

Read more http://rss.nytimes.com/c/34625/f/640387/s/4a04b0b1/sc/28/l/0L0Snytimes0N0C20A150C0A90C210Cbusiness0Capple0Econfirms0Ediscovery0Eof0Emalicious0Ecode0Ein0Esome0Eapp0Estore0Eproducts0Bhtml0Dpartner0Frss0Gemc0Frss/story01.htm


Strict Standards: Only variables should be assigned by reference in /home/noahjames7/public_html/modules/mod_flexi_customcode/tmpl/default.php on line 24

Strict Standards: Non-static method modFlexiCustomCode::parsePHPviaFile() should not be called statically in /home/noahjames7/public_html/modules/mod_flexi_customcode/tmpl/default.php on line 54

Find out more by searching for it!

Custom Search







Strict Standards: Non-static method modBtFloaterHelper::fetchHead() should not be called statically in /home/noahjames7/public_html/modules/mod_bt_floater/mod_bt_floater.php on line 21