[Q] android 2.3 stock browser publishing phone number/websites stealing phone number? - General Questions and Answers

Hi, I have a question concerning "security" of internet browsing from android smartphones.
I hope that this is the right place to post.
Yesterday I was browsing the internet from a friend's android 2.3 samsung i8150 stock rom, and followed an "apparently normal" link on a webpage - it was not a link, I later realized that it was a "form button".
Suddenly after clicking it, I received an sms on the same smartphone from JAMBA, which stated that "my subscription was successfull" and from that moment on, I had to pay weekely 5€ (they took their first 5€ instantly, and of course there was no info about any "service" or subscription near the link).
I immediately called my phone operator (wind mobile) and asked to disable the subscription (which I hope they did - at least they refunded me), but they also said that this kind of "scam" is frequent: these services just need a click and a phone number to be subscribed to.
My question is simple: how could I "make safe" a browser which is publishing my personal phone number to any masked sms/ringtone/wallpaper/and whatever possible unwanted "service"?
I found these 2 topics, and made a check in the urls provided to see if it was wind's fault, but I couldn't find my phone number there.. so I assume it's another "trick" they are using to get my phone number..
http://forum.xda-developers.com/showthread.php?t=1463638
http://forum.xda-developers.com/showthread.php?t=1463530
Should I use a different browser (which one?) and consider the stock one "unsafe"?
Do you know anything about this behaviour and how to be "protected"?
Thank you in advance

Related

[Completed] Identify, locate, eliminate and prevent malware on several devices.

Hey guys!
This is my first post here, and I come with a problem that affects 2/3 android devices and possibly one desktop PC (Windows).
The problem:
I have malware on my devices and said malware redirects my current page to a russian advertising one. Most of the time i'm redirected to one that activates the vibration, knows the device i'm currenty using and says that I should run a virus scan with AVG.
If I hit return, the page just reloads, If I hit it enough times, I lose the page I was visiting as if I hadn't visited it in the first place.
Here
Code:
imgur.com/a/5dvVR
are some of the URLs I'm redirected to and sometimes, I happen to suffer the problem on the last page, where an ad sits in the middle of the page I'm visiting and If I close it, another tab opens and leads me to the addresses above.​
Symptoms:
This problem happens with Google Chrome, Mozilla Firefox and the built-in browser of "Reddit is fun".
This problem happens with and without a WiFi connection. It is more common to happen while on WiFi vs on mobile.
Sites like knowyourmeme.com, foxtrotalfa.jalopnik.com and albums on imgur.com can trigger the malware.​
Devices:
Definitively affected:
Lg G2 D-802 , Android 4.4.2
Galaxy Tab S 10.5" SM-T800, Android 5.0.2
Probably affected but not 100% proven:
Huawei Y600 (another carrier, but the problem happened on my GF's WiFi rarely on mobile), workphone
A desktop PC (the ad blocking the page happened just once)
Networks
This desktop PC is my GF's. It's in her WiFi signal that I usually connect and update the apps on my devices. In my house's WiFi the problem seems to happen as well on my devices but not on my Desktop PC (or perhaps it does, but I have ublock origin on my browsers).
However, I can trigger this problem on my G2's carrier Movistar and not on the Huawei's Carrier Telcel.​
Working on the problem:
Disabling scripts
The very first thing I did was testing disabling scripts (as suggested by one page I found on google), It did work, to some extent. However, I knew that this wasn't a solution but a workaround.​
Suspicious APPs
I know that apps are the main entrance for malware and since the problem DID happened on both devices (G2 and Galaxy Tab) It.HAD to be a common app, so I made a list of common apps and started by the less trustworthy.
I uninstalled and tested Advice animal creator, BS player free, zooper pro, Days counter widget, Disk Usage,electrodroid, ****ing weather, Google tasks organizer lite, GPS test, meme generator, system info for android,reddit is fun , add watermark and Think.
Keep in mind that these apps fill the criteria in which both are present on the phone and tablet and are suspicious to me (a very ambiguous term), however, I'm not stating that any of these have malware on them.
Sadly, after uninstalling and testing on the phone, the problem persisted.​
G2's Factory restoration (Through options menu, not recovery menu)
After going through a factory restoration on the phone, the problem persisted. The only things I had installed were Reddit is fun, facebook and whatsapp.​My request to you guys:
After all ofthis wall of text (in which I show the symptoms, what I've done, etc) , here comes my request.
Can you guys point me to the right direction?
I just don't want to wipe my devices without knowing what is the problem, how to eliminate it and, MOST IMPORTANTLY, how to prevent it.
What I want to discard is if the problem comes from my GF's network (If that is the case, a factory-through-recovery restoration would be useless), an app or just random malvertising.
I would hate to wipe my cellphone and tablet everytime I jump into this problem and that is not practical for me, I prefer a head-on approach.
Thanks in advance guys!​
Hi!
First, here is a little info on avoiding Malware, http://forum.xda-developers.com/general/general/guide-simple-steps-to-avoid-installing-t3000682
And another, http://forum.xda-developers.com/nexus-6/general/guide-little-guide-to-security-privacy-t3042460
As far as Malware you already have....there are malware removal tools on the Play Store...many of them to try.
And if all else fails, here are the device sections or the mobile devices you have.....you could ask for help in the Q&A sections...
http://forum.xda-developers.com/lg-g2
http://forum.xda-developers.com/galaxy-tab-s
Now, if you want to ask about all in one, and the PC....you could try asking or help here...http://forum.xda-developers.com/android/help
Good luck!
Darth said:
Hi!
First, here is a little info on avoiding Malware, http://forum.xda-developers.com/general/general/guide-simple-steps-to-avoid-installing-t3000682
And another, http://forum.xda-developers.com/nexus-6/general/guide-little-guide-to-security-privacy-t3042460
As far as Malware you already have....there are malware removal tools on the Play Store...many of them to try.
And if all else fails, here are the device sections or the mobile devices you have.....you could ask for help in the Q&A sections...
http://forum.xda-developers.com/lg-g2
http://forum.xda-developers.com/galaxy-tab-s
Now, if you want to ask about all in one, and the PC....you could try asking or help here...http://forum.xda-developers.com/android/help
Good luck!
Click to expand...
Click to collapse
Thanks Darth!
But as I said, I tried several apps and didn't find anything wrong.
However, I switched my focus to the possibility of a router infection, and oh surprise it seems to be the rootcause.
Here are some links that report being redirected on several devices to ads pages (I use code since I can't post links in a new account), in this case adsmatte.com:
Code:
http://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/how-to-get-rid-of-adsmattecom-adware-opening/06b20667-586a-4ebd-9876-6d28c8528a1f?page=1
https://discussions.apple.com/thread/7052365
http://forums.androidcentral.com/moto-g-2014/528571-adware-redirects-most-websites-how-can-i-get-rid.html
http://www.asus.com/zentalk/forum.php?mod=viewthread&tid=8189&extra=&page=1
Then I tried searching for the page I get redirected to, somethingsomething.epara.ru, so I searched that last common part epara.ru (I thought I had done this before ):
Code:
http://forum.kaspersky.com/index.php?showtopic=334600
https://warosu.org/g/thread/S50749199
http://www.xataka.com/respuestas/malware-adware-en-todos-mis-dispositivos (SPANISH)
What is VERY suspicious is that many of the results, suggest downloading "Spy hunter".
Here are some examples:
Code:
http://solvepcproblem.com/remove-359198-epara-ru/
http://removevirusvideo.com/stop-epara-ru-from-redirecting-epara-ru-removal-tips/
Now, how do you solve it?
Simple:
Disconnect from any WiFi, clear your browser's cache (and even your OS's). CCleaner does a pretty good job for this.
Then go to your suspicious router and factory reset it (or ask your ISP to do that remotely) and update its firmware. After all thosesteps, you can connect again.
What the malware does is change your DNS towards a malicious one.
I haven't done that reset to my GF's router, but that should solve the problem.
Thansk for everything, and I hope this works for somebody else!
Glad you got it sorted. If you want to find further help on anything, use the links I suggested... And if you want to post info to help others, you could post here, http://forum.xda-developers.com/general/general
I'll close this thread now.
:good:

Mystery SMS to China?

So I get my phone bill, and note that there are 4 sms messages to Chinese phone number 8615012811576 all on one day.
I don't remember intentionally texting a phone number in China, so am wondering if an app would do this for some sort of sign-in or somesuch, a trojan, or what.
Searching the internet tells me nothing about this number so I guess it's not happening to others.
A week before there was an sms to a UK number, but it was easy to learn online that MIUI Cloud account does that when one installs MIUI, which I did then, for a few minutes of trial run.
The Chinese numbers were texted while I used a recent LOS N derivative, so unlikely it was the ROM--I'm more wondering if one of my apps would have done it, and perplexed that the number isn't already spoken of on the web.
Oh..., I remember reading that QuickPic started sending data after they were bought by Cheetah Mobile. I wonder if that has something to do with it. Maybe I uninstalled it/installed Piktures/uninstalled Piktures/reinstalled QuickPic right about then. That would have been because QuickPic can Wifi Direct with itself on other devices, and I don't know any other gallery that will do that, among some other nice features.
So now installed the "Pre" Cheetah version. Dunno if that was the case, but will keep eyes open.
pbergonzi said:
So I get my phone bill, and note that there are 4 sms messages to Chinese phone number 8615012811576 all on one day.
I don't remember intentionally texting a phone number in China, so am wondering if an app would do this for some sort of sign-in or somesuch, a trojan, or what.
Searching the internet tells me nothing about this number so I guess it's not happening to others.
A week before there was an sms to a UK number, but it was easy to learn online that MIUI Cloud account does that when one installs MIUI, which I did then, for a few minutes of trial run.
The Chinese numbers were texted while I used a recent LOS N derivative, so unlikely it was the ROM--I'm more wondering if one of my apps would have done it, and perplexed that the number isn't already spoken of on the web.
Oh..., I remember reading that QuickPic started sending data after they were bought by Cheetah Mobile. I wonder if that has something to do with it. Maybe I uninstalled it/installed Piktures/uninstalled Piktures/reinstalled QuickPic right about then. That would have been because QuickPic can Wifi Direct with itself on other devices, and I don't know any other gallery that will do that, among some other nice features.
So now installed the "Pre" Cheetah version. Dunno if that was the case, but will keep eyes open.
Click to expand...
Click to collapse
By phone bill you meant Carrier bill,right?
Mr.Ak said:
By phone bill you meant Carrier bill,right?
Click to expand...
Click to collapse
No, I meant "phone bill." That's what a bill from a carrier is typically called in the states. It's a carry-over from days of yore, when these things were called "phones", and the people that provided the services through the long wires were called "phone companies." It was much like having one's own private telegraph system in one's home, but a telegraph that worked with a voice instead of a manually operated electromagnetic switch.
pbergonzi said:
No, I meant "phone bill." That's what a bill from a carrier is typically called in the states. It's a carry-over from days of yore, when these things were called "phones", and the people that provided the services through the long wires were called "phone companies." It was much like having one's own private telegraph system in one's home, but a telegraph that worked with a voice instead of a manually operated electromagnetic switch.
Click to expand...
Click to collapse
It is better to have prepaid than postpaid.
Scan with a reputable anti-malware product (I suggest trend micro premium or Sophos free). Enable Google Play Protect on your phone as well.
iprasad said:
Scan with a reputable anti-malware product (I suggest trend micro premium or Sophos free). Enable Google Play Protect on your phone as well.
Click to expand...
Click to collapse
Way to go with those antiviruses. They must be one of the worsts available.
But the idea was right.
I would suggest F-secure or Malwarebytes for Android.
pahapoika91 said:
Way to go with those antiviruses. They must be one of the worsts available.
But the idea was right.
I would suggest F-secure or Malwarebytes for Android.
Click to expand...
Click to collapse
I just had to laugh at the immaturity and lack of knowledge.
F-Secure had one of the LOWEST scores in the recent android test performed by av-test (one of the leading test institutes).
I recommended trend micro because getting an original premium license is one of the cheapest (in UK atleast) while Sophos is a great choice if one is going for free. Cheetah was tested but had a lower score while Malwarebytes was not tested.
I DONT want to start the "mine is better than yours" type of thread so see for yourself:
https://www.av-test.org/en/antivirus/mobile-devices/
I don't think that on Android any antivirus solutions are necessary. Check your user apps. Which one has the permission to send SMS? A gallery app doesn't need the permission to send SMS to do her job. Most users install apps and don't care about permissions.
Also try to use open source apps (preferable from F-Droid). They are more secure.
The greatest security breach is mostly the user.

Phishing Attack via Google Assistant?

Hey all and thanks in advance for any help you can provide as I have been racking my brain trying to figure this one out, but keep falling flat. A few days ago I received a Google Assistant notification on my Nexus 5X running the current stock Android (no rooting or modification on this device in any way). It was bringing to my attention an "important" email about one of my credit cards. I was immediately suspicious as this was the first time I had ever gotten a notification of this kind from Google Assistant. Usually it is sports score updates, bill reminders, breaking news, etc... But it did appear to be a legitimate Google Assistant notification so I did click it (I later confirmed this as I checked my notification history and it did show up as a Google App notification). It then opened Google Assistant, but then immediately opened either Chrome itself or a Chrome custom tab. The address that it opened appeared to be the legitimate Gmail domain, and unless it was using non Latin characters then I have no reason to believe otherwise. Not only that but it was showing an already opened email claiming to be from one of my credit card companies stating that there were important changes to their policies and/or my account.
It was at this point that I knew something was amiss. Images were being blocked in the email and just the whole process seemed "off". I opened Inbox/Gmail on my desktop and sure enough there was no such email there, it was at this point that I knew beyond doubt it was a scam. I was very careful not to click anything in the email but I could see that the "To:" label was to my legitimate email address and the "From:" address was typical of a phishing/scam email (eg. the name of the credit card company but with some kind of modifier attached). I wish I would have taken a screenshot of it, but it all caught me off guard. If it happens again believe me I will.
What made this all even weirder was when I tried to access this link on my desktop as I wanted to try and run some tests on the link that it was trying to get me to click on. I went on my Chrome history to track the link down but it was not there. So I checked my Chrome history on my phone and sure enough it showed up there, but not on my desktop. It was the only link not showing up on my desktop's Chrome history, all other links were there and I could see the same two links that were before and after the link in my phone's Chrome history but not that one. I have since factory reset my phone to be on the safe side and sure enough on my new install that link is also not showing up there either.
Now I am fairly well versed in tech, am very disciplined in "think before you click", and pride myself in being able to spot a scam - but I am also no expert and this is where I am needing some help in figuring out what exactly happened. I need to figure out if my device was compromised or if there is any way a malicious actor could have triggered my Google Assistant to open up a link like it did.
There is more to this story though which makes it a bit more complicated. Towards the beginning of the year I had a credit card that got compromised, this credit card was from the same company that the scam email was claiming to be from. Luckily I have alerts turned on and I was able to spot it almost immediately and reported it. The card was cancelled and I received a new one. I had my suspicions about how it was compromised but nothing for sure (I have never had a security problem like this, and I had recently used a website that I had never used before to purchase something - not damning itself but definitely suspicious). A couple months later and it happened again. At this point I was about 95% sure which website had compromised it. I believe the website itself was not malicious but that it's database had been breached, meaning the card only became compromised if it was "stored" in my account as a payment option. Also of note was that I have two cards with this particular company and only the one card I used on this website was compromised, not both cards nor the account itself (no other cards, companies, or payment options either). Further confirmation of my suspicions are that since I narrowed which website I thought that it was and it has not happened again.
My whole reason brining all of that up is that without it, to me anyways it would seem like my device is compromised. But with that story, and the fact that scam email was obviously phishing for my login credentials to that company makes it seem like someone somehow figured out a way to trigger my Google Assistant. Not only that, but triggered it to open up someone else's Gmail in a Chrome tab with an email already opened. Is that even possible? Do third party apps or services have this kind of access to Google Assistant? If not, it would seem to indicate for certain that my device is/was compromised, yeah?
As I already stated, I have since factory reset my phone, and every website and service I use has strong passwords and 2FA with alerts turned on if possible. But without knowing exactly how this attack was possible I still feel vulnerable. I have seen many phishing attacks in my day but this one seemed personalized, not mass targeted like the other which also makes me worry (again, even more so since I am not certain how this one happened). Plus I am worried that if it was my device that was compromised then a factory reset may not be enough. Many, many thanks for anyone who has a more intimate knowledge of Google's developer ecosystem that can help.
[EDIT} I will continue to add some things here that I think may be relevant to diagnosing this issue.
I was not doing anything at the time that this notification was sent. I was not even on my phone - I use Pushbullet to get notifications on my desktop and it was there that I first noticed it. And honestly, I do not even use my phone that much as I am near my desktop almost all the time. The rare times that I do use it, it is for listening to music or podcasts, almost no web browsing at all and very little app usage.
I was at home at the time of the notification, meaning no public or untrusted Wi-Fi. Nor at risk of any bluetooth type attack either.
I do use a VPN at all times.

Huawei community forums...how to file bugs on Huawei phones?

I've been trying to log into Huawei's community forums for a while, but no matter what I try, it results in an error page. It's the most extraordinarily frustrating experience. I wonder if anyone else has any tips to getting logged in.
My main reason for wanting to log in, apart from having a general look for tips, etc, is to find out how to inform them of a bug in their OS. Does anyone have any recommendations for how best to do that?
In fact, I often log in the community forum as my mobile phone is a Huawei device. I would like to help you report the bug.
You may post your bug description here. You can write in English or in Chinese.
If it is in English, I will translate it by myself before submit to the forum .
James_Watson said:
In fact, I often log in the community forum as my mobile phone is a Huawei device. I would like to help you report the bug.
You may post your bug description here. You can write in English or in Chinese.
If it is in English, I will translate it by myself before submit to the forum .
Click to expand...
Click to collapse
Well, that's very civilised of you. I'll write in English, since that's the only language I know
Actually, I have three bugs - well, I think they're bugs, except, perhaps, for the first one.
1. This one isn't really a bug, but I bet the people on the Huawei forums can help.
FYI, I use a sim card from CMLink - SIM #1 [1], which piggy back off EE in the UK, and CMCC in China, and provide useful roaming plans for use between the two countries. They only provide data plans limited by the month, and I have signed up for their 22GB plan. To track usage, I have a P10 and have been trying to set it up to automatically calibrate the data usage measure on a daily basis. I think it does this by sending an SMS containing simply 'Check' to CMCC's service number '10086', and extracts the data from the response (not 100% sure about that, but hey). There seems to be a 'calibrate' button in the settings to do this manually (under the usage graph), but when I try I get the message 'Incorrect network provider. Reselect and try again.' I'd really like to get this going.
2. Related to above, I've set the setting to show the usage under the notifications when you drag down from the top of the screen. I've configured my plan information - ie 22GB per month, and starts on the 17th of each month. However, while the 'Today' seems to increase appropriately, the 'Left' is stuck at the maximum. I imagine the 'Total' is supposed to stay at 22GB. I expect the 'Left' to go down as I use it throughout the month.
3. This one is unrelated to above. If I open a browser and go to my web mail site, there is an option on the menu to 'Add to Home screen'. As expected, when I select that option, it does add an icon to the homescreen. Since it is something I want on every page of the homescreen, I drag that icon onto the row on the bottom of the screen that is shown on every page. I do that for a couple of web pages - my email and my calendar. At this point, it all works swimmingly. However, if I reboot the phone, then those icons seem to be moved back onto the homescreen, and also are 'greyed out' and placed under the clocks (the clock widget) I have placed there. So, that's not 'expected'.
What do you think?
Max.
Device info:
Model: VTR-AL00
Build number: 9.1.0.201 (C00E75R1P12patch02) GPU Turbo
EMUI version: 9.1.0
Android version: 9
Android security patch: 1 August 2019
Kernel version: 4.9.148
Network (I selected things that might be helpful):
SIM 1 (my UK CMLink SIM): China Mobile, LTE, SMS centre number - a UK number
SIM 2 (my Chinese CMCC SIM): China Mobile, EDGE, SMS centre number - a China number
[1] ...and also a 2nd one, SIM 2, which is a local SIM
James_Watson said:
In fact, I often log in the community forum as my mobile phone is a Huawei device. I would like to help you report the bug.
You may post your bug description here. You can write in English or in Chinese.
If it is in English, I will translate it by myself before submit to the forum .
Click to expand...
Click to collapse
You could also, if you would be so kind, help me fix my problems logging into the Huawei community forums...
davidmaxwaterman said:
You could also, if you would be so kind, help me fix my problems logging into the Huawei community forums...
Click to expand...
Click to collapse
What's your question about logging into that forum?
But as I found, it seems a community forum in Chinese. Almost all posts there are in Chinese. So, will you get any effective response even if you can log in it?
Maybe it's better to contact a local Huawei customer service center in order to get some helps. Do you think so?
---------- Post added at 04:55 AM ---------- Previous post was at 04:34 AM ----------
davidmaxwaterman said:
Well, that's very civilised of you. I'll write in English, since that's the only language I know
Actually, I have three bugs - well, I think they're bugs, except, perhaps, for the first one.
1. This one isn't really a bug, but I bet the people on the Huawei forums can help.
FYI, I use a sim card from CMLink - SIM #1 [1], which piggy back off EE in the UK, and CMCC in China, and provide useful roaming plans for use between the two countries. They only provide data plans limited by the month, and I have signed up for their 22GB plan. To track usage, I have a P10 and have been trying to set it up to automatically calibrate the data usage measure on a daily basis. I think it does this by sending an SMS containing simply 'Check' to CMCC's service number '10086', and extracts the data from the response (not 100% sure about that, but hey). There seems to be a 'calibrate' button in the settings to do this manually (under the usage graph), but when I try I get the message 'Incorrect network provider. Reselect and try again.' I'd really like to get this going.
2. Related to above, I've set the setting to show the usage under the notifications when you drag down from the top of the screen. I've configured my plan information - ie 22GB per month, and starts on the 17th of each month. However, while the 'Today' seems to increase appropriately, the 'Left' is stuck at the maximum. I imagine the 'Total' is supposed to stay at 22GB. I expect the 'Left' to go down as I use it throughout the month.
3. This one is unrelated to above. If I open a browser and go to my web mail site, there is an option on the menu to 'Add to Home screen'. As expected, when I select that option, it does add an icon to the homescreen. Since it is something I want on every page of the homescreen, I drag that icon onto the row on the bottom of the screen that is shown on every page. I do that for a couple of web pages - my email and my calendar. At this point, it all works swimmingly. However, if I reboot the phone, then those icons seem to be moved back onto the homescreen, and also are 'greyed out' and placed under the clocks (the clock widget) I have placed there. So, that's not 'expected'.
What do you think?
Max.
Device info:
Model: VTR-AL00
Build number: 9.1.0.201 (C00E75R1P12patch02) GPU Turbo
EMUI version: 9.1.0
Android version: 9
Android security patch: 1 August 2019
Kernel version: 4.9.148
Network (I selected things that might be helpful):
SIM 1 (my UK CMLink SIM): China Mobile, LTE, SMS centre number - a UK number
SIM 2 (my Chinese CMCC SIM): China Mobile, EDGE, SMS centre number - a China number
[1] ...and also a 2nd one, SIM 2, which is a local SIM
Click to expand...
Click to collapse
Your three question are really confused and difficult to understand for me as I never used a CMLink sim card.
But I will try my best to get to know your situations and help you as more as I can.
First, let's clarify your 3rd question.
On my Huawei phone, there are at most 5 icons on the row on the bottom of the screen that is shown on every page. Every icon here for apps on my device works fine even if I reboot my device. So, is it a defect of the couple of web pages - email and calendar?
Try to drag an icon of another app or widget there. Check if it will work well, please.
> I never used a CMLink sim card
I don't think there's anything special about the CMLink, except that it works in either country pretty much the same as the other. It is the same as any other SIM card with a monthly limited data plan. So, you could consider that it is the same as a Chinese SIM card, I suppose.
> So, is it a defect of the couple of web pages - email and calendar?
Well, I guess I don't know exactly what the problem is, of course. My impression is that they hadn't considered this use-case much at all - I notice the Huawei browser doesn't have this 'add to homescreen' functionality at all.
However, you prompted me to experiment a bit more, and it doesn't happen with all web pages. Previously, I had my email and calendar on there, and they both were moved back onto the homescreen underneath other icons/widgets and greyed out (and didn't actually work to launch the web pages). However, now, the calendar page does seem to stay on there, and works when I click it. I also have tried both Chrome and Brave, and they both seem to show the same problem. I can't really see how it could be a web page problem, since nothing is being launched. I suppose it could be a web *manifest* problem, since that is where the icons usually come from...though looking in chrome devtools, I see that it has no manifest, and so the icons must be taken from the <meta> in <head>. The calendar, which does seem to be staying on the quick launch bar, also doesn't have a manifest file - so not that then.
It's pretty easy to reproduce though:
1. open your browser (chrome, probably) on https://www.fastmail.fm/
2. click on the menu and select 'Add to homescreen'
3. 'Add' on the dialog
4. 'ADD on the next dialog
5. go to the homescreen and locate the shortcut
6. drag and drop it onto the quick launch bar.
7. restart
Well, that's frustrating - I was writing those down as I did them, and when I restarted, it looked fine :/ I wonder if it makes any difference which position the icons are in on...ah, yeah, it looks like it is more reproducible if the shortcut is the left-most. Arghh. This time I lost a *native* app I had on there too - WeChat of all things - you'd imagine they'd make sure that works fine. Actually, it wasn't the WeChat app I had on there, but a shortcut to one of the contacts - you can add a wechat contact from the menu on their item in the wechat contacts list - 'Add to Desktop' it is in English. Hrm I notice that, while the web page shortcuts get moved back onto the homescreen, the WeChat contact shortcut is just gone....and I can't even add it again from WeChat - it says it is, but nothing appears :/
Gosh, it's really a bit of a mess. Perhaps it's too broken and inconsistent to even bother filing any bug. I'm tempted to apply for a job there to try and help, but in any case, I can't see too many Westerners being happy with such issues I suppose Chinese people just don't do this sort of thing.
> What's your question about logging into that forum?
>
> But as I found, it seems a community forum in Chinese. Almost all posts there are in Chinese. So, will you get any effective response even if you can log in it?
> Maybe it's better to contact a local Huawei customer service center in order to get some helps. Do you think so?
Well, the question is where I can get help with logging in - but, if it is all in Chinese, I would modify my question to be: where can I find forums that are in English, and corresponding community support? Since there is a huge market for English speakers, I imagine they have somewhere for us to learn how to use it, and ask questions and report problems, etc?
davidmaxwaterman said:
> What's your question about logging into that forum?
>
> But as I found, it seems a community forum in Chinese. Almost all posts there are in Chinese. So, will you get any effective response even if you can log in it?
> Maybe it's better to contact a local Huawei customer service center in order to get some helps. Do you think so?
Well, the question is where I can get help with logging in - but, if it is all in Chinese, I would modify my question to be: where can I find forums that are in English, and corresponding community support? Since there is a huge market for English speakers, I imagine they have somewhere for us to learn how to use it, and ask questions and report problems, etc?
Click to expand...
Click to collapse
Yes, your requirement is very reasonable.
When I posted some questions about mobile phone usage here, there would be someone would replied to my thread and tried to get more detailed info to help me. They said they were the Huawei official staff.
I will post a thread about "where for you to ask questions and report problems in English" for you soon.
On the other hand, you can access the forum either via web application (mobile web as well as computer web) or via an official app. You can also try the app. If you need it and can not find the apk, I will show you the link.
James_Watson said:
Yes, your requirement is very reasonable.
When I posted some questions about mobile phone usage here, there would be someone would replied to my thread and tried to get more detailed info to help me. They said they were the Huawei official staff.
I will post a thread about "where for you to ask questions and report problems in English" for you soon.
On the other hand, you can access the forum either via web application (mobile web as well as computer web) or via an official app. You can also try the app. If you need it and can not find the apk, I will show you the link.
Click to expand...
Click to collapse
Thanks. I look forward to finding out if there is a forum for English language users somewhere. I do kind of feel like they could spend more attention to this requirement, unless, of course, I'm just not looking hard enough. I remember when I was using a ZTE phone - they were very popular due to having front-facing speakers, and so had a pretty good US based forum and it was very useful. [Side note - I wish Huawei would produce a phone with front-facing speakers].
I don't think an app will get me very far...I probably have it on my phone already - I see one called 'HiCare', for example, and there's the top line on the settings. It's all very unfamiliar and things so often don't seem to quite work as expected. I kind of wish the Huawei stores had 'help' sessions like they do (or did anyway) in Apple stores.
davidmaxwaterman said:
> I never used a CMLink sim card
I don't think there's anything special about the CMLink, except that it works in either country pretty much the same as the other. It is the same as any other SIM card with a monthly limited data plan. So, you could consider that it is the same as a Chinese SIM card, I suppose.
> So, is it a defect of the couple of web pages - email and calendar?
Well, I guess I don't know exactly what the problem is, of course. My impression is that they hadn't considered this use-case much at all - I notice the Huawei browser doesn't have this 'add to homescreen' functionality at all.
However, you prompted me to experiment a bit more, and it doesn't happen with all web pages. Previously, I had my email and calendar on there, and they both were moved back onto the homescreen underneath other icons/widgets and greyed out (and didn't actually work to launch the web pages). However, now, the calendar page does seem to stay on there, and works when I click it. I also have tried both Chrome and Brave, and they both seem to show the same problem. I can't really see how it could be a web page problem, since nothing is being launched. I suppose it could be a web *manifest* problem, since that is where the icons usually come from...though looking in chrome devtools, I see that it has no manifest, and so the icons must be taken from the <meta> in <head>. The calendar, which does seem to be staying on the quick launch bar, also doesn't have a manifest file - so not that then.
It's pretty easy to reproduce though:
1. open your browser (chrome, probably) on https://www.fastmail.fm/
2. click on the menu and select 'Add to homescreen'
3. 'Add' on the dialog
4. 'ADD on the next dialog
5. go to the homescreen and locate the shortcut
6. drag and drop it onto the quick launch bar.
7. restart
Well, that's frustrating - I was writing those down as I did them, and when I restarted, it looked fine :/ I wonder if it makes any difference which position the icons are in on...ah, yeah, it looks like it is more reproducible if the shortcut is the left-most. Arghh. This time I lost a *native* app I had on there too - WeChat of all things - you'd imagine they'd make sure that works fine. Actually, it wasn't the WeChat app I had on there, but a shortcut to one of the contacts - you can add a wechat contact from the menu on their item in the wechat contacts list - 'Add to Desktop' it is in English. Hrm I notice that, while the web page shortcuts get moved back onto the homescreen, the WeChat contact shortcut is just gone....and I can't even add it again from WeChat - it says it is, but nothing appears :/
Gosh, it's really a bit of a mess. Perhaps it's too broken and inconsistent to even bother filing any bug. I'm tempted to apply for a job there to try and help, but in any case, I can't see too many Westerners being happy with such issues I suppose Chinese people just don't do this sort of thing.
Click to expand...
Click to collapse
1. About CMLink, okay, I just posted a thread for you to Huawei community about how to report issue about Huawei phone usage for those speak English. Wait for their response, please.
2. Now I have gotten to know the feature 'Add to Home Screen'. In my Firefox Focus browser, I found it. I will have a try soon.
James_Watson said:
1. About CMLink, okay, I just posted a thread for you to Huawei community about how to report issue about Huawei phone usage for those speak English. Wait for their response, please.
2. Now I have gotten to know the feature 'Add to Home Screen'. In my Firefox Focus browser, I found it. I will have a try soon.
Click to expand...
Click to collapse
Awesome. That's very cool of you, thanks Maybe I'll try Firefox too...
Max.
davidmaxwaterman said:
Awesome. That's very cool of you, thanks Maybe I'll try Firefox too...
Max.
Click to expand...
Click to collapse
I tried Firefox Focus just now.
When I opened a simple web page, then selected 'Add to Home screen' from the menu, entered some words for the icon title, tap 'Add' at last.
But it was so strange that then I couldn't find this icon on the home screen at all. It must be a bug of Huawei EMUI system. The QC engineers should ignore this use case.
Btw, it's time to home for me. I will try to help you tomorrow. Would you like to support my apps available on Google Play? Thanks in advance.
James_Watson said:
I tried Firefox Focus just now.
When I opened a simple web page, then select 'Add to Home screen' from the menu, entered some words for the icon title, tap 'Add' at last.
But it was so strange that then I couldn't find this icon on the home screen at all. It must be a bug of Huawei EMUI system. The QC engineers should ignore this use case.
Click to expand...
Click to collapse
Ah, I hit this too. I suspect it is simply that you need to grant the app permissions to add to homescreen in the phone's settings in the Apps->permissions...or somewhere like that.
It's a bit odd that they don't get this automatically...I never had this issue with Google Android phones.
James_Watson said:
I tried Firefox Focus just now.
When I opened a simple web page, then selected 'Add to Home screen' from the menu, entered some words for the icon title, tap 'Add' at last.
But it was so strange that then I couldn't find this icon on the home screen at all. It must be a bug of Huawei EMUI system. The QC engineers should ignore this use case.
Btw, it's time to home for me. I will try to help you tomorrow. Would you like to support my apps available on Google Play? Thanks in advance.
Click to expand...
Click to collapse
You are right. I granted the app permission 'add to homescreen' to Firefox Focus, and then tried the feature again.
The function works well. Even after rebooting, the icon is still there on the row on the bottom of the screen that is shown on every page. So, I misunderstood that feature.
James_Watson said:
You are right. I granted the app permission 'add to homescreen' to Firefox Focus, and then tried the feature again.
The function works well. Even after rebooting, the icon is still there on the row on the bottom of the screen that is shown on every page. So, I misunderstood that feature.
Click to expand...
Click to collapse
Cool. It seems like it might be working better for you than for me. I've not tried firefox yet, but chrome and brave both seem to lose any shortcuts on the quick launch bar, but not always. It is also quite curious what has happened to the shortcut from wechat...since that's a native android app :/
Perhaps you're on a more recent Android/EMUI version? What kind of phone are you using?
TBH, I'm seriously considering the P30 Pro 5G when I get back to the UK, and this is sort of a test run with a hand-me-down phone which I presume is very similar in UI/UX, so it is all 'influencing' my decision.
davidmaxwaterman said:
Cool. It seems like it might be working better for you than for me. I've not tried firefox yet, but chrome and brave both seem to lose any shortcuts on the quick launch bar, but not always. It is also quite curious what has happened to the shortcut from wechat...since that's a native android app :/
Perhaps you're on a more recent Android/EMUI version? What kind of phone are you using?
TBH, I'm seriously considering the P30 Pro 5G when I get back to the UK, and this is sort of a test run with a hand-me-down phone which I presume is very similar in UI/UX, so it is all 'influencing' my decision.
Click to expand...
Click to collapse
In fact, my phone is an old model, Mate 8 with EMUI/Android 8.0. I also have a wechat installed on my device.
Btw, would you like to leave a 5-star for my app which is available on Google Play? Thanks.
James_Watson said:
In fact, my phone is an old model, Mate 8 with EMUI/Android 8.0. I also have a wechat installed on my device.
Btw, would you like to leave a 5-star for my app which is available on Google Play? Thanks.
Click to expand...
Click to collapse
LOL, well I would be happy to, except I don't have Google Play on my phone...or Google anything, I think....except Chrome, of course. I'm a web app developer, so I prefer to use web apps than native android apps.
davidmaxwaterman said:
LOL, well I would be happy to, except I don't have Google Play on my phone...or Google anything, I think....except Chrome, of course. I'm a web app developer, so I prefer to use web apps than native android apps.
Click to expand...
Click to collapse
I posted a thread in that forum for you yesterday. https://club.huawei.com/thread-21560821-1-1.html
But till now, I have not gotten any response. So, I sent a PM to the ADMIN just now.
You may try to log in the web app or the native app for the community forum. There you might post a thread in English as your device language is English. Have a try, please. Good luck to you.
Yesterday, I managed to contact the CEO of Huawei Consumer Business Group, Richard Yu, through his social network account. But till now I have not gotten his reply to my PM.
I suggest you post your issues on the Reddit: https://www.reddit.com/r/Huawei/ . Good luck to you.

My Huawei P30 has been hacked with a RAT! can I still save my accounts?

I have a Huawei p30 phone with last security patch received in august 2020, not rooted and never been in strangers hands.
This crazy psycopath woman has been stalking me badly for a year, but then in september 2020 she shared a weird (fake) video with the image of a pixeled pony on my Facebook page. I clicked on it but strangely it won't open. Few hours later this crazy woman deleted the fake video and begun to write me about things I said privately to a friend via Whatsapp! and in the following months she started insulting me with fake Instagram profiles every time I chatted privately with other girls, making fun of the things I wrote to them. She seems to see everything on every social network! And even when I took a picture with a girl that I never shared but only had privately in my gallery, she reacted to it by insulting me!
I don't know what kind of trojan or RAT is this but I would like so much to get rid of it!
1) Can you guys tell me how can I get rid of this RAT? I've already searched with Kaspersky, Malawarebytes, Avast for Android but they can't see a damn thing.
2) Can I put my sim card with my whole whatsapp (and related backup messages and contacts) on a new device or I am going to risk?
3) Can I keep my Gmail and Instagram accounts by disconnecting them from the hacked device and changing passwords from a new device?
THANKS
Personally don't think your phone got infected by a RAT and/or Trojan: this type of malicious software requires root-access get granted to it.
IMO your issue is related to the social media you make use of, the method you login there, the passwords you use with this accounts.
You know that FB, WA and Instagram basically are ONE company, that your related account details get shared between them?
jwoegerbauer said:
Personally don't think your phone got infected by a RAT and/or Trojan: this type of malicious software requires root-access get granted to it.
IMO your issue is related to the social media you make use of, the method you login there, the passwords you use with this accounts.
You know that FB, WA and Instagram basically are ONE company, that your related account details get shared between them?
Click to expand...
Click to collapse
If you look around over the Internet there is PLENTY of new generation RAT trojans that take root permissions of Android phones with just one click. Some of them are called drive-by download, they use a buffer overflow mechanism. Off course you need security holes for this to happen, and Huawei is very very exposed to this, they never release security patches! Even the police officer I talked to when I filled the complaint told me that they see many cases like these. It's absolutely possible.
Columbus93 said:
If you look around over the Internet there is PLENTY of new generation RAT trojans that take root permissions of Android phones with just one click. Some of them are called drive-by download, they use a buffer overflow mechanism. Off course you need security holes for this to happen, and Huawei is very very exposed to this, they never release security patches! Even the police officer I talked to when I filled the complaint told me that they see many cases like these. It's absolutely possible.
Click to expand...
Click to collapse
I want to say one thing to the one guy laughing underneath my post. ALL of my accounts were protected with double step autentication (2FA) and just yesterday, my phone received a series of notification about a Google chromecast device that was connected to my Huawei p30. I even got the last notification saying "you succeded connected google chromecast to your device". Now tell me how this is even possible, because I never had a google chromecast device and I was at work the whole time! Looks like there's a clone of my p30 smatphone out there. Do not aswer if you have no clue about new hacking programs.
1. Make sure that you have finished a full data backup.
2. Do a factory reset + wipe cache.
3. Change your passwords ASAP.
Just for your reference.
A side remark dedicated to visitors here who don't know what a RAT is:
A RAT ( read: Remote Administration Tool ) is an Android app that always runs as an Android service, what gets started at Android's boot. It has initially been developed as an university project. A RAT consits of a client module ( the mentioned Android service ) and a server module located somewhere outside of Android device, reachable via Android's network connection.
A RAT's client module only can get installed on Android devices with unlocked bootloader, AVB disabled and rooted Android. It's the user - and ONLY he /she - who allows a RAT service to get installed on Android
​These are a RAT's functionalities typically available
Get contacts (and all theirs informations)
Get call logs
Get all messages
Location by GPS/Network
Monitoring received messages in live
Monitoring phone state in live (call received, call sent, call missed..)
Take a picture from the camera
Stream sound from microphone (or other sources..)
Streaming video (for activity based client only)
Do a toast
Send a text message
Give call
James_Watson said:
1. Make sure that you have finished a full data backup.
2. Do a factory reset + wipe cache.
3. Change your passwords ASAP.
Just for your reference.
Click to expand...
Click to collapse
About the backup: can I just connect the hacked phone (offline) to a clean PC to transfer my files? I am afraid I'll transfer also the rat this way!
jwoegerbauer said:
A side remark dedicated to visitors here who don't know what a RAT is:
A RAT ( read: Remote Administration Tool ) is an Android app that always runs as an Android service, what gets started at Android's boot. It has initially been developed as an university project. A RAT consits of a client module ( the mentioned Android service ) and a server module located somewhere outside of Android device, reachable via Android's network connection.
A RAT's client module only can get installed on Android devices with unlocked bootloader, AVB disabled and rooted Android. It's the user - and ONLY he /she - who allows a RAT service to get installed on Android
​These are a RAT's functionalities typically available
Get contacts (and all theirs informations)
Get call logs
Get all messages
Location by GPS/Network
Monitoring received messages in live
Monitoring phone state in live (call received, call sent, call missed..)
Take a picture from the camera
Stream sound from microphone (or other sources..)
Streaming video (for activity based client only)
Do a toast
Send a text message
Give call
Click to expand...
Click to collapse
So you are basically telling everyone that when FBI is live monitoring your smartphone, that's because you CHOOSE to ALLOW a RAT service to get installed into your smartphone? I never ever allowed this thing to install inside my phone, all I did was to click on that fake video! and things like this, to mutuate the words of the police officer I talked to, do happen all the time!
My last 2 cents here:
If someone ( like FBI employee, spouse, life companion, etc.pp ) wants to monitor everything on your Android phone not having your phone in hands, wants to access your phone's data not having your phone in hands, he / she must install a monitoring app or RAT software ( e.g. AndroRAT ) on your Android phone. Point.
Have a nice day.
jwoegerbauer said:
My last 2 cents here:
If someone ( like FBI employee, spouse, life companion, etc.pp ) wants to monitor everything on your Android phone not having your phone in hands, wants to access your phone's data not having your phone in hands, he / she must install a monitoring app or RAT software ( e.g. AndroRAT ) on your Android phone. Point.
Have a nice day.
Click to expand...
Click to collapse
I'm positive with what you say, but I'm also saying that this monitoring app CAN be disguised as fake video or image, thus by clicking on it you will inadvertitely launch a series of payloads that will root and then hack your phone. This is a fact. It happened to me and if you give a look online you'll see how this works and how many apps are doing this (obviously you need HUGE security holes in your device to do that, and older Huawei devices, which are rarely updated, do have them).

Categories

Resources