ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile working Toolkit

Sony Ericsson phones vulnerable to Bluetooth attack

Greg Sandoval CNET News.com

Published: 10 Feb 2006 09:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Several mobile phones produced by Sony Ericsson are vulnerable to denial-of-service attacks, two security companies reported this week.

The flaw is found in four models of Sony Ericsson phones and comes from an error in their Bluetooth service, according to an FrSIRT advisory

The Bluetooth "fails to properly handle malformed L2CAP", FrSIRT, a France-based security company, said in an advisory posted on its Web site.

Danish security firm Secunia reported the same flaw, and both companies have rated the potential security risk as low. Thomas Kristensen, Secunia's chief technology officer, said that someone intent on knocking out one of the four Sony Ericsson phones, which includes the K600i and T68i, would need only to get within 50 feet while carrying a handheld device configured to send the malicious code via Bluetooth. The code would crash the phone.

"I don't think the phone's user would even know the attack occurred until they tried to use their phone again," Kristensen said.

The good news is that damage would be minimal. Once the phone was turned off and restarted, it would function normally again, Kristensen said.

"Sony Ericsson believes that the possibilities to exploit the Sony Ericsson products mentioned are very limited," the firm said in an emailed statement. "However, if you are concerned, you can help prevent access to the phone by switching off the 'discoverable' mode in the Bluetooth settings of the phone. This makes the phone invisible to others and thereby minimises the risk of being accessed."

Ericsson said it is waiting to learn more details from engineers in Sweden who would have more information.

While this specific vulnerability may be low-risk, Kristensen cautioned that these kinds of vulnerabilities in mobile phones are a growing concern in the security community. Conceivably, hackers could pilfer information from mobile phones one day if the handsets aren't provided with the right security measures.

So far, mobile users have only had to worry about mobile phone viruses, which are still very rare. In October 2005, Nokia tapped Symantec to help secure its mobile phones from viruses that target certain kinds of handsets. Experts don't expect a fast-spreading mobile phone virus to strike for two more years.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
51 out of 120 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Risk Deals Desk Analyst London Oil Major

Do you have commercial market risk experience working with physical and derivatives oil products? We are seeking an experienced market risk, product ...

Application Support - Risk Systems Trading House Perm SQL Unix London

My client is a major Energy Trading House who is looking for an Application Support Analyst to join their risk systems operations team. The role is ...

Business Development. New Business Sales - Risk Management Vendor

My client is a leading provider of Risk Software within the Financial Industry. If you have experience selling software solutions (partically Risk ...

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment