ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile devices Toolkit

Mobile Java hit with security scare

Stephen Shankland CNET News.com

Published: 25 Oct 2004 15:55 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Polish researcher has found two vulnerabilities in the cell phone version of Sun Microsystems' Java software that under unusual circumstances could let a malicious program read private information or render a phone unusable.

The flaws are difficult to exploit because malicious programs must be tailored to a specific model of cell phone, said Adam Gowdiak, a 29-year-old security researcher with the Poznan Supercomputing and Networking Centre who discovered the vulnerabilities. He figured out how to attack a Nokia 6310i mobile phone, but the effort took four months, he said in a Friday posting to the BugTraq vulnerability mailing list.

Before the vulnerabilities could be exploited, a phone user would have to download and run a malicious Java program, called a midlet, Gowdiak said in an email interview. He's not aware of a way to automate an attack.

He notified Sun of the vulnerabilities in August, and the company said it sent Java licensees a patched version of the vulnerable component, called the Java bytecode verifier, within two weeks.

"We have not seen any attempts to exploit this vulnerability, but if there is one, the user can simply delete... the applications they downloaded from an untrusted source," said Eric Chu, Sun's director of marketing for the Java 2 Micro Edition, or J2ME, software.

But in an October talk at the Hack in the Box conference in Malaysia, Gowdiak said the situation should be taken seriously. "Vendors and [the] antivirus industry are not prepared for this kind of threat," he said in his presentation. "It should be expected that remote vulnerabilities for mobile devices will be published within the next six months."

Sun didn't publish the vulnerabilities, instead choosing to let the cell phone makers notify their customers. "We don't have a relationship with the end consumer," Chu said.

Sun estimates that more than 570 million Java-enabled handsets will have been sold by the end of 2004, and one in three handsets is equipped with Java. Hundreds of cell phone service providers rely on J2ME to sell ring tones, games and other downloads.

Sophisticated mobile devices are growing more important. According to the Meta Group, roughly two-thirds of all businesses and organisations will deploy mobile data services by 2007. Mobile email will top the application list, with half of organisations launching a wireless email system within three years and 75 percent in four years.

The vulnerability disclosure comes on the eve of CTIA Wireless I.T. & Entertainment 2004, a cell phone trade show in San Francisco, where Java will support many new services to be unveiled.

Java has been relatively free of vulnerabilities, especially compared with Windows. One advantage is that Java has built-in security features that make it hard for local or remote programs to take unauthorised actions.

Using the vulnerabilities, Gowdiak created programs for the Nokia phone that could send text messages or photos, wipe the phone's memory, connect to the Internet and steal data such as phone book records -- all without the user knowing.

And at the Hack in the Box conference, he said the vulnerabilities could potentially be used to install software that secretly records text messages, or to install other applications.

Qualcomm makes a competing but less popular technology to download software onto cell phones. There have not been any reports of vulnerabilities among the scores of carriers using Qualcomm's Binary Runtime Environment for Wireless, or BREW, technology.

Microsoft has had some issues with mobile devices; vulnerabilities have been found for its smart phone operating system, its Windows CE for gadgets and its Pocket PC software for handhelds.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 103 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

NHS Project Manager Summary Care Records

My client urgently seeks an NHS Project Manager to initiate the delivery of the Summary Care Records (SCR) as part of the National Programme for IT ...

Project Manager - Summary Care Records - North West - Healthcare

Project Manager with Summary Care Records experience is required to work in the North West on a contract. Summary Care Records experience or NCRS ...

Support Manager-International IT/Conference Co.-35,000 City

Support Manager-International IT/Conference Co. City Manage the support of this international IT/Video conference organisation that has seen huge ...

Featured Talkback

Put simply, what is the compelling reason to pay ~$200 extra for an Eee with Windows XP? A Windows Eee won't come with any useful applications and you'll have to buy anti-virus software to boot. The truth about low cost computing is that nobody really cares whether the machine is running Windows or Linux as long as its cheap, its easy to use and it works.

By: dogStar

Read full story:
Asus to ship 60 percent of Eee PCs with Windows XP

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment