Monday, August 22, 2016

Can an app call a phone without me knowing?


The reason I ask is because I have gotten various calls from seemingly random numbers saying that I had called them. When I check my call log, there is no outgoing call to their number.


This has happened multiple times, but not very often, maybe once every two weeks. I am normally very careful with the apps that I download and have avg downloaded and scanning periodically. Could it be that someone else can use the same number to call?



Answer



An app with the appropriate permissions can not only initiate calls without you knowing, but also remove all evidence from your call logs:



  • CALL_PHONE: Allows an application to initiate a phone call without going through the Dialer user interface for the user to confirm the call being placed.

  • WRITE_CALL_LOG: Allows an application to write (but not read) the user's contacts data.



(Source: Manifest Permissions).


If your provider supports a full call listing on your bill: that's a place no app can touch, so there you would find evidence.


Though it is technically possible somebody else could fake your number, that's rather unlikely. To do this, one would need some privileges a normal phone connector doesn't offer; so this person must either sit at a provider's site directly, or at some (usually bigger) company with the appropriate privileges granted.




To help you isolating the possible culprit, there are several tools available. I'd suggest to take a look at something like Permission Explorer:


Permission Explorer: Categories Permission Explorer: CALL_PHONE
Permission Explorer (Source: Google Play; click images to enlarge)


As you can see, this app allows browsing by category, and nicely lists up all installed apps with a given permission. You can most likely skip system apps here, then see what's left and re-check playstore comments on suspicious apps. I also recommend checking on AppBrain, as they often point out malicious apps: Use their search page and see if the result for your app is "minimized", which already is one indicator. Also a good idea: try AppBrain Ad Detector, which does the same for apps on your device:


AppBrain Ad Detector AppBrain Ad Detector

AppBrain Ad Detector (Source: Google Play; click images to enlarge)


Additional benefit of this app: it automatically alerts you when you install an app with suspicious permissions ("Live Detection Mode" triggers on app install).


No comments:

Post a Comment

samsung galaxy s 2 - Cannot restore Kies backup after firmware upgrade

I backed up my Samsung Galaxy S2 on Kies before updating to Ice Cream Sandwich. After the upgrade I tried to restore, but the restore fails ...