Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

If a listener nods his head when you're explaining your program, wake him up.


computers / comp.mobile.android / Malware?

SubjectAuthor
* Malware?db
+- Re: Malware?KenW
+* Re: Malware?Andy Burns
|`* Re: Malware?Andy Burnelli
| `- Re: Malware?db
+- Re: Malware?Michael
`* Re: Malware?db
 `* Re: Malware?Andy Burns
  +- Re: Malware?db
  `- Re: Malware?Andy Burnelli

1
Malware?

<ttl157$3k8lb$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38086&group=comp.mobile.android#38086

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dieterha...@gmail.com (db)
Newsgroups: comp.mobile.android
Subject: Malware?
Date: Tue, 28 Feb 2023 14:55:51 +0100
Organization: A noiseless patient Spider
Lines: 8
Message-ID: <ttl157$3k8lb$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 28 Feb 2023 13:55:51 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="3a7b473d88768eb69eaaa299e32be185";
logging-data="3809963"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+UpgNbJToX/eH3f4w8YkGEzE4NKtpw1rU="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.7.1
Cancel-Lock: sha1:LQMj/msjym1GvzfRzyIbY8ccxAQ=
Content-Language: en-US
 by: db - Tue, 28 Feb 2023 13:55 UTC

My phone went completely dead today after I installed, and uninstalled
again, a terminal emulator and a news group reader. Can this be malware
from these? My wife got it going again after some time, but it was
totally unresponsive for some hours.
Is there a virus checker I can install?

--
Dieter Britz

Re: Malware?

<5r3svht9hojhtfsir93ati16rfo883itgd@4ax.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38091&group=comp.mobile.android#38091

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.uzoreto.com!peer02.ams4!peer.am4.highwinds-media.com!peer03.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx16.iad.POSTED!not-for-mail
From: ken1...@invalid.net (KenW)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Organization: Home
Message-ID: <5r3svht9hojhtfsir93ati16rfo883itgd@4ax.com>
References: <ttl157$3k8lb$1@dont-email.me>
User-Agent: ForteAgent/8.00.32.1272
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Lines: 13
X-Complaints-To: abuse(at)newshosting.com
NNTP-Posting-Date: Tue, 28 Feb 2023 14:28:25 UTC
Date: Tue, 28 Feb 2023 07:28:24 -0700
X-Received-Bytes: 1080
 by: KenW - Tue, 28 Feb 2023 14:28 UTC

On Tue, 28 Feb 2023 14:55:51 +0100, db <dieterhansbritz@gmail.com>
wrote:

>My phone went completely dead today after I installed, and uninstalled
>again, a terminal emulator and a news group reader. Can this be malware
>from these? My wife got it going again after some time, but it was
>totally unresponsive for some hours.
>Is there a virus checker I can install?

What news group reader ?

KenW

Re: Malware?

<k66hkgFr1o3U1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38092&group=comp.mobile.android#38092

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Tue, 28 Feb 2023 14:32:48 +0000
Lines: 6
Message-ID: <k66hkgFr1o3U1@mid.individual.net>
References: <ttl157$3k8lb$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net ThlN9fttoclxjVW1cUrFbwPom/Njg+eDpz/3Tgk33D5fcS30X/
Cancel-Lock: sha1:34/ix5ow0ms4JGdmaTzC9lzRnMA=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.8.0
Content-Language: en-GB
In-Reply-To: <ttl157$3k8lb$1@dont-email.me>
 by: Andy Burns - Tue, 28 Feb 2023 14:32 UTC

db wrote:

> Is there a virus checker I can install?

virus checkers on android are smoke & mirrors, given that no app
(including so called virus scanner) can see or touch another app's files.

Re: Malware?

<ttlqh4$16sk3$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38116&group=comp.mobile.android#38116

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: nos...@nospam.net (Andy Burnelli)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Tue, 28 Feb 2023 21:09:03 +0000
Organization: To protect and to server
Message-ID: <ttlqh4$16sk3$1@paganini.bofh.team>
References: <ttl157$3k8lb$1@dont-email.me> <k66hkgFr1o3U1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 28 Feb 2023 21:08:53 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1274499"; posting-host="g/Is2TmYbQYkEu6sQ3Mzyg.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
Cancel-Lock: sha256:FBppBSW51wBcLgRPzJLuK3yXlGR99+iLO3cVV6kmvhY=
X-Notice: Filtered by postfilter v. 0.9.3
Content-Language: en-GB
 by: Andy Burnelli - Tue, 28 Feb 2023 21:09 UTC

Andy Burns wrote:

>> Is there a virus checker I can install?
>
> virus checkers on android are smoke & mirrors, given that no app
> (including so called virus scanner) can see or touch another app's files.

Hi Andy,

The OP is likely one of those apple trolls but to your point, then how does
the Google scan work if "no app can see or touch another app's files"?

I'm not sure if Google Play Protect is "really" part of the Google Play
Store app itself, but inside the Google Play Store app is the Google Play
Protect settings GUI that controls that heuristic scanner which runs, by
default on every app install (even apps which are sideloaded) AFAIK.

In addition, by default, I believe the Google Play Protect runs once a day.
If no app can see another app's files, how does that scanner work then?

<https://i.postimg.cc/1tPHPWpK/gpprotect01.jpg> Google Play Protect setup
<https://i.postimg.cc/vBzvmWhw/gpprotect02.jpg> Turn on Play Protect scan
<https://i.postimg.cc/fyRfSJqt/gpprotect03.jpg> Google Play App Updates
<https://i.postimg.cc/3xvCGM1B/gpprotect04.jpg> Turn on Play Protect?
<https://i.postimg.cc/1tQ9tPHG/gpprotect05.jpg> Manual GPProtect scan
<https://i.postimg.cc/ZKM4N6HK/gpprotect06.jpg> Change your defaults!
<https://i.postimg.cc/xd97fJ9j/gpprotect07.jpg> Find my phone location?

Re: Malware?

<ttls65$1k5d$1@nnrp.usenet.blueworldhosting.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38121&group=comp.mobile.android#38121

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!feed1.usenet.blueworldhosting.com!nnrp.usenet.blueworldhosting.com!.POSTED!not-for-mail
From: mich...@spamcop.com (Michael)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Tue, 28 Feb 2023 14:37:21 -0700
Organization: BlueWorld Hosting Usenet (https://usenet.blueworldhosting.com)
Message-ID: <ttls65$1k5d$1@nnrp.usenet.blueworldhosting.com>
References: <ttl157$3k8lb$1@dont-email.me>
Injection-Date: Tue, 28 Feb 2023 21:37:10 -0000 (UTC)
Injection-Info: nnrp.usenet.blueworldhosting.com;
logging-data="53421"; mail-complaints-to="usenet@blueworldhosting.com"
User-Agent: MT-NewsWatcher/3.5.3b3 (Intel Mac OS X)
Cancel-Lock: sha1:jUhCQdGD/p0s2XbT9vsRlvLW7Qc= sha256:4ipR9z50oubErw6PyjeoDyz+v7IY0LjENJ6MUrWluFw=
sha1:RIkS6+gFtREsHW8tC31hHDrD25Y= sha256:NtPp71Zhwi7yWREmfVDnOXsHyIW0HFCGkZ0D56BhU9U=
X-Face: f.J8qnmRe<;"4)7zy{Go(8&lzd02x&@O58vucE*DVlNh5,hE"i9}]a0r__<N!-IzKgndSA, p=pKnv@Z%qG:L*AFis_SL$l~NO!c_k10fHmF!:%Z)s
 by: Michael - Tue, 28 Feb 2023 21:37 UTC

On Tue, 28 Feb 2023 14:55:51 +0100, db wrote:

> Is there a virus checker I can install?

Kaspersky Security & VPN
https://play.google.com/store/apps/details?id=com.kms.free
--
[I filter out all Google Groups posts so if I don't reply, that may be why]

Re: Malware?

<ttmv8a$3t3cc$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38173&group=comp.mobile.android#38173

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dieterha...@gmail.com (db)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Wed, 1 Mar 2023 08:35:38 +0100
Organization: A noiseless patient Spider
Lines: 16
Message-ID: <ttmv8a$3t3cc$1@dont-email.me>
References: <ttl157$3k8lb$1@dont-email.me> <k66hkgFr1o3U1@mid.individual.net>
<ttlqh4$16sk3$1@paganini.bofh.team>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 1 Mar 2023 07:35:39 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="3d28862335319ec8427e418a87e1f197";
logging-data="4099468"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18QyPPhMqhMpdgSnSDbJAz+/oNha3QGVqk="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.7.1
Cancel-Lock: sha1:z7SF4Xh9IwQKWHr+ynmAOIdQoOY=
In-Reply-To: <ttlqh4$16sk3$1@paganini.bofh.team>
Content-Language: en-US
 by: db - Wed, 1 Mar 2023 07:35 UTC

On 28.02.2023 22.09, Andy Burnelli wrote:
> Andy Burns wrote:
>
>>> Is there a virus checker I can install?
>>
>> virus checkers on android are smoke & mirrors, given that no app
>> (including so called virus scanner) can see or touch another app's files.
>
> Hi Andy,
>
> The OP is likely one of those apple trolls but to your point, then how does
> the Google scan work if "no app can see or touch another app's files"?[...]
The only apples I get near are those off my tree.
--
Dieter Britz

Re: Malware?

<ttmvjf$3t3cc$2@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38175&group=comp.mobile.android#38175

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dieterha...@gmail.com (db)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Wed, 1 Mar 2023 08:41:35 +0100
Organization: A noiseless patient Spider
Lines: 21
Message-ID: <ttmvjf$3t3cc$2@dont-email.me>
References: <ttl157$3k8lb$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 1 Mar 2023 07:41:35 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="3d28862335319ec8427e418a87e1f197";
logging-data="4099468"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18i4MJISzRr+kP1fjqXzmWQueLZOFkEuW0="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.7.1
Cancel-Lock: sha1:EUHt+35/D5rIzbvb/RE6cOe78LQ=
Content-Language: en-US
In-Reply-To: <ttl157$3k8lb$1@dont-email.me>
 by: db - Wed, 1 Mar 2023 07:41 UTC

On 28.02.2023 14.55, db wrote:
> My phone went completely dead today after I installed, and uninstalled
> again, a terminal emulator and a news group reader. Can this be malware
> from these? My wife got it going again after some time, but it was
> totally unresponsive for some hours.
> Is there a virus checker I can install?
>

Maybe I set the number of displayed posts too low, but my
one on terminal emulators is gone now (for me), so I'll
continue here.
Someone suggested Termux and I searched for it under
Play Butik (that's Danish, not sure what it would be
in English, Shop?) Anyway, I find a number of apps,
but none seems to be the Termux app itself. Like,
Learn Termux, .. Tools and Comm.., Andronix (??).
How do I get hold of the Termux app itself? Some
other emulators I found want payment.
--
Dieter Britz

Re: Malware?

<k68f74F5lacU1@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38177&group=comp.mobile.android#38177

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: use...@andyburns.uk (Andy Burns)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Wed, 1 Mar 2023 08:03:47 +0000
Lines: 6
Message-ID: <k68f74F5lacU1@mid.individual.net>
References: <ttl157$3k8lb$1@dont-email.me> <ttmvjf$3t3cc$2@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net IYOnXwvIvJ1YOgDS7ssOIARl07ZnwuYhVba71BSmdKX/YA5jMg
Cancel-Lock: sha1:gHl/QYM/3KePNy/xgJuLaL8PXYI=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.8.0
Content-Language: en-GB
In-Reply-To: <ttmvjf$3t3cc$2@dont-email.me>
 by: Andy Burns - Wed, 1 Mar 2023 08:03 UTC

db wrote:

> How do I get hold of the Termux app itself?

I don't use it, but why would you download from somewhere other than
<https://packages.termux.dev>

Re: Malware?

<ttnk6n$3v5gf$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38184&group=comp.mobile.android#38184

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dieterha...@gmail.com (db)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Wed, 1 Mar 2023 14:33:11 +0100
Organization: A noiseless patient Spider
Lines: 17
Message-ID: <ttnk6n$3v5gf$1@dont-email.me>
References: <ttl157$3k8lb$1@dont-email.me> <ttmvjf$3t3cc$2@dont-email.me>
<k68f74F5lacU1@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 1 Mar 2023 13:33:11 -0000 (UTC)
Injection-Info: reader01.eternal-september.org; posting-host="3d28862335319ec8427e418a87e1f197";
logging-data="4167183"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19j9mRq6IhpbImZXxMRGC93Dyj4Bu1lZYE="
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.7.1
Cancel-Lock: sha1:bkLopYuH8mu2Q3FGIV7XLoAS43A=
In-Reply-To: <k68f74F5lacU1@mid.individual.net>
Content-Language: en-US
 by: db - Wed, 1 Mar 2023 13:33 UTC

On 01.03.2023 09.03, Andy Burns wrote:
> db wrote:
>
>> How do I get hold of the Termux app itself?
>
> I don't use it, but why would you download from somewhere other than
> <https://packages.termux.dev>

Because Play Store (I now know the English name for it) is the
only way I knew how to install apps. I see that termux is
"deprecated" there. So, I googled the link, and get a lot of
text, but no clear instructions for how to install it on my
phone, which is not like my trusty Linux.

--
Dieter Britz

Re: Malware?

<ttobce$1jsj2$1@paganini.bofh.team>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=38197&group=comp.mobile.android#38197

  copy link   Newsgroups: comp.mobile.android
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: nos...@nospam.net (Andy Burnelli)
Newsgroups: comp.mobile.android
Subject: Re: Malware?
Date: Wed, 1 Mar 2023 20:08:58 +0000
Organization: To protect and to server
Message-ID: <ttobce$1jsj2$1@paganini.bofh.team>
References: <ttl157$3k8lb$1@dont-email.me> <ttmvjf$3t3cc$2@dont-email.me> <k68f74F5lacU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 1 Mar 2023 20:08:47 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1700450"; posting-host="1ZezmsvzO4X4+U9gDQ00xA.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
Cancel-Lock: sha256:Iv2JExx46Kj+hDYNKjZxHhk6ETETu+lh/+CtDZjcMw8=
Content-Language: en-GB
X-Notice: Filtered by postfilter v. 0.9.3
 by: Andy Burnelli - Wed, 1 Mar 2023 20:08 UTC

Andy Burns wrote:

>> How do I get hold of the Termux app itself?
>
> I don't use it, but why would you download from somewhere other than
> <https://packages.termux.dev>

Hi Andy,
Thanks for that suggestion as I too was unaware of where the "official"
termux resided until you listed _that_ open source archive for Termux.
<https://packages.termux.dev>

Until I went there, in fact, I was unaware of this Termux security warning:
"Security warning: APK files on GitHub are signed with a test key
that has been shared with community. This IS NOT an official
developer key and everyone can use it to generate releases for
own testing. Be very careful when using Termux GitHub builds
obtained elsewhere except https://github.com/termux/termux-app.
Everyone is able to use it to forge a malicious Termux update
installable over the GitHub build. Think twice about installing
Termux builds distributed via Telegram or other social media.
If your device get caught by malware, we will not be able to help you."
<https://github.com/termux/termux-app#github>

For the record, your link provides the preferred Github link:
Home page: https://termux.dev (<https://termux.dev/en/>)
Github: https://github.com/termux

Which says "Get it on Github":
<https://github.com/termux>
<https://github.com/termux/termux-app#github>

And "Get it on F-Droid"
<https://f-droid.org/en/packages/com.termux/>
<https://f-droid.org/repo/com.termux_118.apk>

But not, interestingly so, on Google Play Store!
<https://github.com/termux/termux-app#github>
"Termux and its plugins are no longer updated on Google Play Store
due to android 10 issues and have been deprecated. The last version
released for Android >= 7 was v0.101. It is highly recommended
to not install Termux apps from Play Store any more."

I always have trouble with Github finding the actual APK so it's here for
others to benefit from without having to click around trying to find it.
<https://github.com/termux/termux-app/releases>
<https://github.com/termux/termux-app/releases/tag/v0.118.0>
For example, for arm64 (I'm not sure why it says "debug" in it though)
<https://github.com/termux/termux-app/releases/download/v0.118.0/termux-app_v0.118.0+github-debug_arm64-v8a.apk>

BTW, the F-Droid note says it's more "universal" since it says
"F-Droid does not support architecture specific APKs."
<https://github.com/termux/termux-app#github>

It seems the F-Droid one is more universal from that, but I always have
"issues" updating existing installed F-Droid apps due to some "signing"
problem I don't understand.

Now, as for the termux that is already on my system, I need to look in my
APK manager to figure out _how_ I had installed it in the first place.

Thanks for letting us know that the Google Play Store termux is not the one
we want (there are many there, besides, as it's open source code anyone can
copy it).

My main request for advice is which of the two bona-fide termux download
links would you suggest? The Github architecture-specific or F-Droid
universal?

And how would you suggest auto-updates be set up if that's what folks want?

Actually, let me file this as a separate thread so that others can
find it more easily ten years from now when they run a search.]
*Advice as to where to download & install the correct Android TERMUX APK*
<https://groups.google.com/g/comp.mobile.android/c/aNKK7t6l85w>

Please respond there if you're going to reply as that helps more people
find it because of the keywords I placed into the title to aid searches.
--
Posted out of the goodness of my heart to disseminate useful information
which, in this case, is to discuss the peculiarities of the Termux APK.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor