Advertisement
Promo

Mobile devices Toolkit

Mobile Java hit with security scare

Stephen Shankland CNET News

Published: 25 Oct 2004 15:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Polish researcher has found two vulnerabilities in the cell phone version of Sun Microsystems' Java software that under unusual circumstances could let a malicious program read private information or render a phone unusable.

The flaws are difficult to exploit because malicious programs must be tailored to a specific model of cell phone, said Adam Gowdiak, a 29-year-old security researcher with the Poznan Supercomputing and Networking Centre who discovered the vulnerabilities. He figured out how to attack a Nokia 6310i mobile phone, but the effort took four months, he said in a Friday posting to the BugTraq vulnerability mailing list.

Before the vulnerabilities could be exploited, a phone user would have to download and run a malicious Java program, called a midlet, Gowdiak said in an email interview. He's not aware of a way to automate an attack.

He notified Sun of the vulnerabilities in August, and the company said it sent Java licensees a patched version of the vulnerable component, called the Java bytecode verifier, within two weeks.

"We have not seen any attempts to exploit this vulnerability, but if there is one, the user can simply delete... the applications they downloaded from an untrusted source," said Eric Chu, Sun's director of marketing for the Java 2 Micro Edition, or J2ME, software.

But in an October talk at the Hack in the Box conference in Malaysia, Gowdiak said the situation should be taken seriously. "Vendors and [the] antivirus industry are not prepared for this kind of threat," he said in his presentation. "It should be expected that remote vulnerabilities for mobile devices will be published within the next six months."

Sun didn't publish the vulnerabilities, instead choosing to let the cell phone makers notify their customers. "We don't have a relationship with the end consumer," Chu said.

Sun estimates that more than 570 million Java-enabled handsets will have been sold by the end of 2004, and one in three handsets is equipped with Java. Hundreds of cell phone service providers rely on J2ME to sell ring tones, games and other downloads.

Sophisticated mobile devices are growing more important. According to the Meta Group, roughly two-thirds of all businesses and organisations will deploy mobile data services by 2007. Mobile email will top the application list, with half of organisations launching a wireless email system within three years and 75 percent in four years.

The vulnerability disclosure comes on the eve of CTIA Wireless I.T. & Entertainment 2004, a cell phone trade show in San Francisco, where Java will support many new services to be unveiled.

Java has been relatively free of vulnerabilities, especially compared with Windows. One advantage is that Java has built-in security features that make it hard for local or remote programs to take unauthorised actions.

Using the vulnerabilities, Gowdiak created programs for the Nokia phone that could send text messages or photos, wipe the phone's memory, connect to the Internet and steal data such as phone book records -- all without the user knowing.

And at the Hack in the Box conference, he said the vulnerabilities could potentially be used to install software that secretly records text messages, or to install other applications.

Qualcomm makes a competing but less popular technology to download software onto cell phones. There have not been any reports of vulnerabilities among the scores of carriers using Qualcomm's Binary Runtime Environment for Wireless, or BREW, technology.

Microsoft has had some issues with mobile devices; vulnerabilities have been found for its smart phone operating system, its Windows CE for gadgets and its Pocket PC software for handhelds.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
63 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Jabra Stone Bluetooth headset

I don’t get on very well with Bluetooth headsets. But it is not a prejudice against them. I don’t get on well with those flat, saucer-like in-ear headphones either. My ears are just... More

Post a comment

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment

Discussions

manek manek

Time for your baggage to arrive, then

Monday 30 November 2009, 12:44 PM

1 comment
siarad siarad

Reply

Monday 30 November 2009, 10:43 AM

8 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters