ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile working Toolkit

BlackBerry security risk revealed

Joris Evers CNET News.com

Published: 09 Aug 2006 09:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

One of the first examples of malicious software on BlackBerry devices has surfaced, but manufacturer Research In Motion does not see it as a serious threat.

At the Defcon hacker confab on Saturday, researcher Jesse D'Aguanno said he developed a program called BBProxy that, when running on a BlackBerry, gives an attacker entry to the network the wireless device connects to. The program exploits the link between the handheld and the email server, and it could be used to place additional malicious code onto a network.

"A malicious person could potentially use this back channel to move around inside an organisation unabated and remove confidential information undetected, or use the back channel to install malware on the network," Secure Computing, a provider of security services, said in a media alert on Tuesday.

The BlackBerry service allows companies to give their employees access to email while they are on the road. A typical installation includes server software that is installed on a corporate network as well as the handhelds used to send and receive messages.

For an attack to be successful, a BlackBerry user has to be tricked into running the malicious application. At Defcon, D'Aguanno suggested that his program could be delivered to users wrapped in a game of "Tic Tac Toe". "First and only BlackBerry Trojan (horse) that I know of," D'Aguanno wrote in his presentation.

It could be the first malicious program aimed at the BlackBerry, Scott Totzke, director of the global security group at RIM, agreed in an interview on Tuesday. However, the Waterloo, Ontario-based company doesn't see a major threat to its customers, he said.

"There are a number of hoops that you have to go through to make this thing possible," Totzke said. For one, it is impossible to email an application to the device; people have to download it, he said.

"When you step back and look at it, BlackBerry is a computing platform and able to run applications similar to a laptop and a VPN connection," he said.

The BlackBerry can run applications, including malicious ones, Totzke noted. To avoid that, the device offers several settings that allow companies to protect their systems. These include blocking the ability to run programs. Also, RIM suggests that companies put their BlackBerry servers and email servers in discrete sections of the network to limit the connection between the two.

In anticipation of D'Aguanno's presentation, RIM published two documents on its security Web site that provide instructions on secure installation of a BlackBerry system and on protection against malicious software.

D'Aguanno plans to publicly release BBProxy in the coming weeks. RIM isn't worried. "I don't see releasing code as much of a threat," Totzke said. "It is an example of an application running on a BlackBerry that is designed to connect to network resources."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
194 out of 279 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

SUPPORT ENGINEER - HERTS - c25k - ELECTRONIC FUNDS TRANSFER

Customers, company staff and third party suppliers (such as Installation Engineers) to ensure that all Customer support calls are handled in a ...

J2ME / Blackberry Application Developer - I PAY MORE THAN OTHER AGENTS

If you are a J2ME/Blackberry Developer call me now or send me your CV. Want to push J2ME/Blackberry development to its limits? This is the contract ...

New Business Sales Consultant

Expert in presentation skills, negotiations, conflict resolution Experience in managing solution sales where duration exceeds 90 days. This will ...

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment