Adups Spy Software

plus_user Post time 2016-11-21 16:22:14 | Show all posts  Close [Copy link]
9 4777
View: 4777|Reply: 9

Adups Spy Software

 Close [Copy link]

2

threads

31

posts

93

credits

Senior Member

Rank: 2

credits
93
Post time 2016-11-18 23:32:57 | Show all posts |Read mode
Edited by plus_user at 2016-11-18 23:52

Hi,

i have a short question. Does UMI use the  Adups software in the Firmware?

I've found a Folder called "com.adups.fota"

Path: Android/data/com.adups.fota

http://www.nytimes.com/2016/11/1 ... -security.html?_r=0
Here is the Link to the detailed report:
http://www.kryptowire.com/adups_security_analysis.html

Moreover, some transmitted the body of the user's text messages and call logs to a server in located in Shanghai. All of the data collection and transmission capabilities we identified were supported by two system applications that cannot be disabled by the end user. These system applications have the following package names:

com.adups.fota.sysoper
com.adups.fota


Post time 2016-11-20 21:21:40 | Show all posts
Dear Users,

Only versions between 5.0.x and 5.3.x of the AdupsFota.apk file are affected but UMi uses the 4.3.0.0 version on its Android 6.0 smartphones. Any UMi models are currently not in the list of the affected devices and not mentioned in researches. In our Android 7.0 final releases we will use the 5.4.x or later versions. If you are an Android 7.0 beta user (only UMi Plus at this moment), your phone is currently affected by this issue as a possible vulnerability (version 5.2.x is installed) but your personal data won't be shared with third parties. The AdupsFota.apk (Wireless update) app itself is needed to process OTA updates.
Once a UMi model will be reported as a vulnerable/infected device, we will take action to release an update as soon as possible.

1

threads

6

posts

26

credits

New Member

Rank: 1

credits
26
Post time 2016-11-19 03:50:35 | Show all posts
Edited by Ru77 at 2016-11-19 05:08 \n\n
Hope we receive a reply also, but doubt we will tbh.

From what the OP has said  it certainly does look as if adups are baked into the firmware.

Luckily, it can be removed (see link below)

http://android.wonderhowto.com/h ... ne-disable-0175034/

2

threads

31

posts

93

credits

Senior Member

Rank: 2

credits
93
 Author| Post time 2016-11-19 03:04:18 | Show all posts
I hope we get an answer!

1

threads

15

posts

76

credits

Senior Member

Rank: 2

credits
76
Post time 2016-11-19 08:22:27 | Show all posts
Ouch. This needs more visibility!

0

threads

40

posts

510

credits

Diamond Member

Rank: 4

credits
510
Post time 2016-11-19 21:22:02 | Show all posts

I'm very very angry!!!
I feel cheated.

2

threads

31

posts

93

credits

Senior Member

Rank: 2

credits
93
 Author| Post time 2016-11-19 23:26:43 | Show all posts
I'll send my UMI Plus back. No informations or statement from UMI. This is really a bad support. Huawei immediately responded to the accusations.

I don't want that anyone makes money with my data. The Adups Software can tranfer complete SMS-messages, call-logs, logs locations and many more. But really disturbing is, that the Adups Software can use command injection.

A Full List is here:
http://www.kryptowire.com/adups_security_analysis.html

And after the update from 2016-11-17, the folder is still there!!! Do you really want to sell your products with this support in Europe?        

Good luck


Comments

Yeah ... this is so disappointing and the UMI management doesn't realize what kind of damage they are doing to their brand "UMI" by this behaviour and also by bad phone designs ....  Post time 2016-11-22 00:00

1

threads

15

posts

76

credits

Senior Member

Rank: 2

credits
76
Post time 2016-11-21 04:12:36 | Show all posts
I can't send it back now, but after my screen problem, and this I would to.

1

threads

45

posts

169

credits

Senior Member

Rank: 2

credits
169
Post time 2016-11-21 16:22:14 | Show all posts
Hmm. So as of right now we are safe but only because Umi using an obsolete version of the app.
Either way, I froze both of them in Titanium Backup for now. Since my bootloader unlocked, using twrp and rooted, I can't use OTA anyways
You have to log in before you can reply Login | WELCOME TO UMIDIGI COMMUNITY

Points Rules

Quick Reply Top Back to list