sfba.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A Mastodon instance for the San Francisco Bay Area. Come on in and join us!

Server stats:

2.3K
active users

#sideload

1 post1 participant0 posts today
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://mstdn.social/@BernieDoesIt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>BernieDoesIt</span></a></span> <span class="h-card" translate="no"><a href="https://wandering.shop/@Catvalente" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Catvalente</span></a></span> there is:</p><ul><li><em>REFUSE TO RELEASE ON <a href="https://infosec.space/tags/iOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iOS</span></a> UNTIL THE TERMS ARE CHANGED!</em></li></ul><p>As with every <a href="https://infosec.space/tags/Platform" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Platform</span></a>, <a href="https://infosec.space/tags/Software" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Software</span></a> makes <a href="https://infosec.space/tags/OperatingSystems" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OperatingSystems</span></a> and the <a href="https://infosec.space/tags/OperatingSystem" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OperatingSystem</span></a> makes <a href="https://infosec.space/tags/Hardware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Hardware</span></a>.</p><ul><li>This worked with <a href="https://infosec.space/tags/WindowsPhone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WindowsPhone</span></a> and <a href="https://infosec.space/tags/UWP" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>UWP</span></a>: <em>everyone refused</em> to build <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apps</span></a> for it and thus it died pretty quickly.</li></ul><p>And if you want to say that's not an option, take a look at <a href="https://infosec.space/tags/AltStore" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AltStore</span></a> which automates all the necessary work to perpetually <a href="https://infosec.space/tags/sideload" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sideload</span></a> any <a href="https://infosec.space/tags/App" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>App</span></a> on iOS in a noob-friendly way.</p><p>Remember: <em>"Everyone else does it"</em> never was and never will be a valid excuse for any shit system!</p><ul><li>Also you could just refuse to offer the sales on Apple's platform and add any <em>"<a href="https://infosec.space/tags/Premium" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Premium</span></a> Features"</em> post-launch with your own payment &amp; licensing infrastructure. If you're big enough or small enough you may get away with it. <a href="https://infosec.space/tags/NotLegalAdvice" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NotLegalAdvice</span></a></li></ul><p>Otherwise band together with other <a href="https://infosec.space/tags/developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>developers</span></a> and coordinate.</p><ul><li>Cuz <a href="https://infosec.space/tags/WhatYouAllowIsWhatWillContinue" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WhatYouAllowIsWhatWillContinue</span></a>!</li></ul><p>And if you allow Apple to exploit you harder than <a href="https://infosec.space/tags/Valve" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Valve</span></a>, then you normalize that shit!</p>
Kevin Karhan :verified:<p><span class="h-card" translate="no"><a href="https://social.vivaldi.net/@ajsadauskas" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>ajsadauskas</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@JessTheUnstill" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>JessTheUnstill</span></a></span> also <a href="https://infosec.space/tags/BlackBerry" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlackBerry</span></a>'s <a href="https://infosec.space/tags/PlayBook" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PlayBook</span></a> <a href="https://infosec.space/tags/Tablet" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Tablet</span></a> <a href="https://www.youtube.com/watch?v=lYmHId9kJP4" rel="nofollow noopener noreferrer" target="_blank">was released</a> as a accessory screen for their Phones, which gave it <em>"<a href="https://infosec.space/tags/WiiU" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WiiU</span></a>-Effect"</em> in terms of marketing.</p><ul><li>Plus <a href="https://infosec.space/tags/RIM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RIM</span></a> relying hard on business clients and their proprietary applianced mail systems and having big carriers upsell to business people made them look outdated &amp; quite literally <em>out of touch</em> once <a href="https://infosec.space/tags/iPhone" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iPhone</span></a> went mainstream.</li></ul><p>I mean, the hardware was never their problem and <a href="https://infosec.space/tags/SMS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SMS</span></a>-Typists swear by their <a href="https://infosec.space/tags/BlackberryCurve" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlackberryCurve</span></a>'s <a href="https://infosec.space/tags/keyboard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>keyboard</span></a> but BlackBerry's <a href="https://infosec.space/tags/toolchain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>toolchain</span></a> - just like <a href="https://infosec.space/tags/SymbianOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SymbianOS</span></a>'s - was just hideous to the point that devs like <span class="h-card" translate="no"><a href="https://oxytodon.com/@fuchsiii" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>fuchsiii</span></a></span> didn't even want to try making <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apps</span></a> for those devices.</p><ul><li>Unlike <a href="https://infosec.space/tags/Mozilla" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Mozilla</span></a> fucking up <a href="https://infosec.space/tags/FirefoxOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FirefoxOS</span></a> by refusing to sell devices to <a href="https://infosec.space/tags/developers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>developers</span></a>, by the time RIM &amp; <a href="https://infosec.space/tags/Nokia" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Nokia</span></a> came from their high horses, their market shares had been squeezed into mere <em>"rounding errors"</em> by <a href="https://infosec.space/tags/iOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iOS</span></a> and <a href="https://infosec.space/tags/Android" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Android</span></a> as it was way cheaper and easier to get <a href="https://infosec.space/tags/Apps" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Apps</span></a> developed, tested, sold, bought and use them than on their devices. </li></ul><p><a href="https://infosec.space/tags/Sony" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Sony</span></a> even released some <a href="https://infosec.space/tags/Symbian" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Symbian</span></a> <a href="https://infosec.space/tags/S60" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>S60</span></a> devices but since they didn't have the same signing keys, one couldn't even <a href="https://infosec.space/tags/sideload" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sideload</span></a> apps (not to mention they didn't had the <a href="https://infosec.space/tags/OviStore" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>OviStore</span></a> on those either!)...</p>
Brad<p>2025-03-26 (Wednesday): <a href="https://infosec.exchange/tags/SmartApeSG" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SmartApeSG</span></a> traffic for a fake browser update page leads to a <a href="https://infosec.exchange/tags/NetSupport" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetSupport</span></a> <a href="https://infosec.exchange/tags/RAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RAT</span></a> infection. A zip archive for <a href="https://infosec.exchange/tags/StealC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StealC</span></a> sent over the <a href="https://infosec.exchange/tags/NetSupportRAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NetSupportRAT</span></a> C2 traffic.</p><p>The <a href="https://infosec.exchange/tags/StealC" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StealC</span></a> infection uses DLL side-loading by a legitimate EXE to <a href="https://infosec.exchange/tags/sideload" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>sideload</span></a> the malicious DLL.</p><p>A <a href="https://infosec.exchange/tags/pcap" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pcap</span></a> from an infection, the associated <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> samples, and <a href="https://infosec.exchange/tags/IOCs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>IOCs</span></a> are available at at <a href="https://www.malware-traffic-analysis.net/2025/03/26/index.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">malware-traffic-analysis.net/2</span><span class="invisible">025/03/26/index.html</span></a></p>