1. catseyenu's Avatar
    After reading the CERT Warning regarding the P.O.C. PhoneSnoop, I ran across Kisses in the PhoneSnoop author's comments.
    Is anyone familiar with the author & his work, is this company considered trust worthy?
    I would hate to see anyone installing rogue "security software" especially myself.
    11-15-09 12:45 PM
  2. catseyenu's Avatar
    Looks like Brian Krebs from the Washington Post covered the author to some degree..

    Security Fix - DHS: PhoneSnoop app bugs BlackBerrys

    /still digging..
    11-15-09 01:13 PM
  3. berryite's Avatar
    Looks like Brian Krebs from the Washington Post covered the author to some degree..

    Security Fix - DHS: PhoneSnoop app bugs BlackBerrys
    Interesting. But it appears this is not a threat unless someone gets their hands on your phone without your permission and you ignore the icon PhoneSnoop leaves in your application profile.
    11-15-09 01:28 PM
  4. SplinterCell's Avatar
    The developer of "Kisses" was questioned hard and left speechless HERE. The scamster and developer of "Kisses of Death" was trying to debate the issues and was just plain-out, shut-up and busted! I would stay far away from Kisses, it's a trap!


    Regards,
    Chris
    11-15-09 01:48 PM
  5. DH350nWo's Avatar
    Kisses installs PhoneSnoop on your phone. This topic was covered about 2 weeks ago but the mods removed the thread.

    Posted from my CrackBerry at wapforums.crackberry.com
    11-15-09 01:57 PM
  6. catseyenu's Avatar
    Interesting. But it appears this is not a threat unless someone gets their hands on your phone without your permission and you ignore the icon PhoneSnoop leaves in your application profile.
    You know, that's what got my attention.. I let someone I don't know use my phone last night because "their battery was dead".
    He was in sight the whole time and it looks like he made 2 call to the same number but being the suspicious creature that I am I started wondering if and OTA install could be accomplished with a simple phone call.

    /I'm not paranoid, I'm just drawn this way.

    Edit: Also I saw some discussion on hiding the icon and or code injection.
    Last edited by catseyenu; 11-15-09 at 02:07 PM. Reason: additional info.
    11-15-09 02:05 PM
  7. catseyenu's Avatar
    The developer of "Kisses" was questioned hard and left speechless HERE. The scamster and developer of "Kisses of Death" was trying to debate the issues and was just plain-out, shut-up and busted! I would stay far away from Kisses, it's a trap!
    That may be your take but I see it a little differently.
    11-15-09 02:36 PM
  8. SplinterCell's Avatar
    Well, please explain to myself and others how you see it.
    Last edited by SplinterCell; 11-15-09 at 02:52 PM.
    11-15-09 02:49 PM
  9. catseyenu's Avatar
    Double post?
    Last edited by catseyenu; 11-16-09 at 11:16 PM. Reason: Double post?
    11-16-09 11:12 PM
  10. catseyenu's Avatar
    After a little research I found not only Brian Krebs at the Washington Post's even handed discussion of the author and his tools, Sheran Gunasekera was also interviewed by Dark Reading as well as by PCWorld.
    He explains in his blog how PhoneSnoop came about after his presentation of Bugs at the Hack In The Box (HITB) security conference as a promise to other security researchers.
    I even went so far as to contact Brian Krebs, who I've had the pleasure of dealing with on several occasions in the past, who shared his surprise at the reception Sheran received from some of the BB forums.
    My findings in short, Sheran Gunasekera is a valid & known security researcher who has been kind enough to develop and share a legitimate Blackberry security application with the community.
    11-16-09 11:15 PM
  11. SplinterCell's Avatar
    I'm still not installing Kisses; however, you have explained this in a way that Sheran could not. Even after reading his rant and most everything that I researched prior gave me every reason not to trust him. Even after multiple Google searches, Bryan's write-up and the US-CERT warning it was all grounds to raise the red flag.

    It's you actually contacting Brian Krebs that has me thinking that I may be wrong about Sheran. Still not interested in any Kisses, but nevertheless, I may have held the wrong opinion.

    I am still a lottle confused as to why he's asking for donations to purchase Flexispy and MobileSpy; when he says Kisses already detects them?


    Nice homework,
    Chris
    11-17-09 12:10 AM
  12. catseyenu's Avatar
    I am still a lottle confused as to why he's asking for donations to purchase Flexispy and MobileSpy; when he says Kisses already detects them?
    I'm not privy or up to date on the time line of requests and needs of Sheran but it's not unusual at all to make resource requests for research purposes.
    Also, these types of programs are known to change to avoid detection.
    Keeping up with the latest variants can be an expensive "hobby".
    I've seen more than one Anti-malware company go udders vertical trying to keep up.
    11-17-09 02:01 PM
  13. ronin2046's Avatar
    Oh ****! I installed Kisses before reading this thread, but I uninstalled it.

    Is my BB compromised?

    11-17-09 04:44 PM
  14. catseyenu's Avatar
    Oh ****! I installed Kisses before reading this thread, but I uninstalled it.

    Is my BB compromised?

    Did you read the entire thread?
    No, you're not compromised.
    Even Symantec states
    We’d consider this application just a proof of concept for a variety of reasons, including the author himself designing it as such:
    Last edited by catseyenu; 11-17-09 at 05:31 PM. Reason: more..
    11-17-09 05:03 PM
  15. ronin2046's Avatar
    Did you read the entire thread?
    No, you're not compromised.
    Even Symantec states
    Yeah, I figured it didn't do any harm.

    11-17-09 09:17 PM
  16. catseyenu's Avatar
    12-21-09 10:51 AM
  17. davidnc's Avatar
    I don't trust the developer of this app. Just my opinion ! I have researched it in depth as well as followed on CB.
    12-21-09 11:37 AM
  18. griffin.ge's Avatar
    I'm not sure I fully understand. If Kisses is such a controversial application, and possibly a piece of spyware, why did CB showcase it in the app roundup blog? Some people say that it actually installs the phonesnoop application, but aren't the file sizes completely different for the two separate apps?

    I haven't really researched it like some others have, which is why I'm just asking. But can anyone actually show proof that Kisses is actually a compromising piece of spyware? I'm a little nervous because I installed it a little while ago, but have since deleted it. idk....
    12-21-09 11:51 AM
LINK TO POST COPIED TO CLIPBOARD