<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; premium rate</title>
	<atom:link href="http://blog.m-sec.net/tag/premium-rate/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>avast Mobile Security is sending SMS without user knowledge</title>
		<link>http://blog.m-sec.net/2012/avast-mobile-security-is-sending-sms-without-user-knowledge/</link>
		<comments>http://blog.m-sec.net/2012/avast-mobile-security-is-sending-sms-without-user-knowledge/#comments</comments>
		<pubDate>Sat, 15 Sep 2012 17:54:45 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[Phone]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[avast]]></category>
		<category><![CDATA[premium rate]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[sms]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=132</guid>
		<description><![CDATA[UPDATE: I have been contacted by Avast to clarify this SMS issue and I&#8217;m working with them to fix this. I think I found the bug and, if proven, it&#8217;s something really funny. I hope I&#8217;ll be able to update you soon as I am leaving to EUSecWest conference. UPDATE2: It was not the bug [...]]]></description>
			<content:encoded><![CDATA[<p>UPDATE: I have been contacted by Avast to clarify this SMS issue and I&#8217;m working with them to fix this. I think I found the bug and, if proven, it&#8217;s something really funny. I hope I&#8217;ll be able to update you soon as I am leaving to EUSecWest conference.</p>
<p>UPDATE2: It was not the bug I was thinking of. After having a few communication messages with Avast, who actually were very helpful, I have to agree with them that <span style="text-decoration: underline;"><strong>this was NOT something they did on purpose</strong></span> &#8211; and I didn&#8217;t think so at all -  and also &#8220;<span style="text-decoration: underline;"><strong>it does not affect a lot of users as it requires special order of tasks to occur</strong></span>&#8220;. Indeed I was able to reproduce the bug by recording my steps and performing them on different devices. Maybe it was bad luck for me to discover these steps, but I am happy that I discovered the bug so that Avast&#8217;s customers will feel safer. Another thing I want to note is that Avast has issued a test update (only available to few until it will go into production), I applied the fix and <span style="text-decoration: underline;">I can confirm the issue is fixed now</span>. Great work Avast! Really fast response and much interest showed in solving the problem.</p>
<p>&nbsp;</p>
<p>A couple of days ago, I have installed on a test Android based phone the <a title="Avast mobile security" href="https://play.google.com/store/apps/details?id=com.avast.android.mobilesecurity&amp;feature=search_result#?t=W251bGwsMSwxLDEsImNvbS5hdmFzdC5hbmRyb2lkLm1vYmlsZXNlY3VyaXR5Il0." target="_blank">avast Mobile Securit</a>y solution from Google Play &#8211; the free version. After a few days when this antivirus solution was turning on the WiFi or the mobile data plan by itself, during the night, I chose to uninstall it.</p>
<p>Now something new came to my attention: I was checking my balance on the phone and noticed that 0.12 EUR were missing. Hmm, maybe I have sent a message to some of my Roaming SIM cards. I logged on to my account to check why I have been billed. I noticed that indeed a message was sent to a number outside my country, but after checking the number I realized this number was not mine.</p>
<p>See the below screenshot from my account:</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/avast_sms.png"><img class="alignnone  wp-image-133" title="avast_sms" src="http://blog.m-sec.net/wp-content/uploads/2012/09/avast_sms.png" alt="Avast sends SMS" width="601" height="255" /></a></p>
<p>&nbsp;</p>
<p>So I looked for the country code: this number - <strong>420720001669</strong> &#8211; is from Czech Republic. Searching for this number on the web revealed that avast is actually sending this message. First occurrence from <a title="AVAST SMS" href="http://forum.universfreebox.com/viewtopic.php?t=37978" target="_blank">here</a>:</p>
<blockquote><p>Même problème, je viens de voir sur mon suivi un SMS vers le 420720001669 facturé à 19cts envoyé le 27 aout.</p>
<p>Il me semble que ça coïncide avec l&#8217;installation d&#8217;Avast Anti-Theft qui a l&#8217;autorisation d&#8217;envoyer des SMS. Et comme de par hasard AVAST software est une compagnie Tchèque &#8230;</p></blockquote>
<p>which translated would mean:</p>
<blockquote><p>Same problem, I just saw on my monitor SMS to 420720001669 charged 19cts sent on August 27.</p>
<p>It seems to me that it coincides with the installation of Avast Anti-Theft that has permission to send SMS messages. And as coincidence AVAST Software is a Czech company &#8230;</p></blockquote>
<p>Second result from <a title="Avast SMS" href="http://foros.orange.es/showthread.php?31265-SMS-que-aparece-en-mi-lista-de-llamadas" target="_blank">here</a></p>
<blockquote><p>Buenos días, esta mañana al consultar mi lista de llamadas me aparece lo siguiente:</p>
<p>24/08/2012 420720001669 ENVÍO SMS 08:12:02 1 MENSAJE</p>
<p>A esa hora no he enviado ningún SMS me pueden decir a q corresponde dicha numeración? El SMS tiene un coste de 60 cent.</p></blockquote>
<p>.. and translated:</p>
<blockquote><p>Good morning, this morning to check my call list I get the following:</p>
<p>08/24/2012 8:12:02 420 720 001 669 1 MESSAGE SENDING SMS</p>
<p>At this time I have not sent any SMS I can say that numbering corresponds aq? The SMS is charged at 60 cent.</p>
<p>Thank you.</p></blockquote>
<p>There was even a result from Google Play store, but couldn&#8217;t find in full so here is the screenshot along with the translation:</p>
<p>September 4, 2012 &#8211; &#8230; took a printout of the operator found to send an SMS to number 420720001669, struck on the forums that this number was Avast &#8230;</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/avast_gplay_sms.png"><img class="alignnone size-full wp-image-136" title="avast_gplay_sms" src="http://blog.m-sec.net/wp-content/uploads/2012/09/avast_gplay_sms.png" alt="" width="516" height="121" /></a></p>
<p>To me it&#8217;s pretty clear that it&#8217;s <strong>Avast</strong> fault for this. There was only one message sent from my number, but I haven&#8217;t used their software for more than 3 days so I can&#8217;t say for sure if the message is sent each week for example. I&#8217;ll try to contact them and see what they have to say about this.</p>
<p>However, this is something that it shouldn&#8217;t happen at all.</p>
<p>In case you have noticed this behavior also, please leave a comment here.</p>
<p>&nbsp;</p>
<div id="tweetbutton132" class="tw_button" style=""><a href="http://twitter.com/share?url=http%3A%2F%2Fblog.m-sec.net%2F2012%2Favast-mobile-security-is-sending-sms-without-user-knowledge%2F&amp;via=msecnet&amp;text=avast%20Mobile%20Security%20is%20sending%20SMS%20without%20user%20knowledge&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=http%3A%2F%2Fblog.m-sec.net%2F2012%2Favast-mobile-security-is-sending-sms-without-user-knowledge%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('http://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.m-sec.net/2012/avast-mobile-security-is-sending-sms-without-user-knowledge/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
	</channel>
</rss>
