Comment by xg15

12 hours ago

Hadn't thought about that additional attack vector those proxies are enabling. In addition to "internet access from residental connection" privileges, the attacker also gets access to loopback on the device that does the proxying...

But even then, shouldn't this show the same permission prompt for the user that anything else trying to connect to port 5555 would?

Yes, but users are told to allow it if they want to get free coins etc.

  • You can't fully protect people from the risk of taking bad advice from malicious strangers.

    Not the least because most of our industry relies on it to make money. Marketing and advertising themselves are institutionalized forms of "do this thing that's actually harmful to you to get free coins / be safe / get laid".

    • > Not the least because most of our industry relies on it to make money.

      I mean, this seems more like one of the root causes for a lot of bad things in the industry me...

  • Told by whom though? If it's through proxyware, then there are three parties who mostly don't know each other:

    - the app embedding the proxyware SDK for money

    - the proxy operators

    - the attackers/botnets using the proxy to access ADB.

    The botnet has no access to the app, so it can't show any messages.

    The app can show messages, but probably has no connection to the botnet. (I hope)

    The proxy operators could show a message by abusing the SDK even more, but that would mean they actively colluded with the botnet. Is that likely? Then they could just give the botnet direct access to the app, no need to do the whole proxy thing.

    • It isn't being done behind-the-back of proxy operators.

      It's one more revenue stream to be able to remote control real android phones to pass device attestation checks etc.

      It's marketed to users with phrases like "earn money from your phone whilst you sleep".

      4 replies →