ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Year-old Bluetooth vulnerability invites mobile worm

Munir Kotadia ZDNet.co.uk

Published: 03 Aug 2004 13:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

For the past year, mobile phone vendors have been trying to fix several Bluetooth security vulnerabilities that could allow hackers to create an MSBlast-type worm that spreads from handset to handset without any user intervention.

Bluetooth has suffered a number of security alerts over the past year ranging from the relatively harmless to the incredibly serious. The first known Bluetooth vulnerability was the Cabir worm, which was discovered a month ago. The security problems do not seem to stem from the Bluetooth standard itself, but rather the way in which handset manufacturers have implemented the technology.

Mikko Hyppönen, director of antivirus research at Finnish firm F-Secure, said an MSBlast or Sasser-style worm spreading between Bluetooth devices becomes possible if handsets can be made to accept and execute a file without first asking the user for permission.

"If you can get Bluetooth file transfers to be accepted automatically, that would end up with an automatic Bluetooth worm. They could combine the bluesnarfing technique to automatically accept a Bluetooth file offering," said Hyppönen.

Just making a handset accept a file does not guaranteed it will be executed, said Mark Rowe, an IT security consultant at Pentest, which was one of the first companies to discover the Blusnarfing vulnerability. However, Rowe said that Pentest is working with an unnamed Bluetooth product vendor to help it resolve vulnerabilities in a Bluetooth implementation that makes it possible for just such a worm to thrive.

"We are aware of a number of vulnerabilities that are not public domain yet that would allow a worm to be uploaded and executed without any user intervention," said Rowe.

To make matters worse for users, Rowe said another myth about Bluetooth attacks is that devices are only vulnerable if they are within 10 metres of the attacker. This may be true for standard Bluetooth devices, but if an attacker wanted to, they could use antenna attachments and other methods to make it possible to attack a device that is "hundreds of metres" away.

"We have been testing with various antennas and we get ranges well into the hundreds of metres. If a Bluetooth worm did come out and if someone was malicious enough, they could infect a lot of people fairly easily," said Rowe.

According to Rowe, handset manufacturers have been very slow to react to the security issues because, unlike computer software developers, they are relatively innocent about security vulnerabilities and don't have the people or processes in place to tackle them.

"The problem is that a lot of the Bluetooth vendors -- like the phone manufacturers -- are used to dealing with a small and specific bit of software, like the Bluetooth stack. They are not like Microsoft or IBM that have got used to people reporting security vulnerabilities and have teams of people specifically to deal with them," said Rowe.

Richard Starnes, president of security industry group ISSA UK, agreed with Rowe. He said that mobile phone operators have been slow to react because they are in a different "threat environment".

"They are operating in a more insular environment with a lower threat profile than a business operating on the Internet. As a result, mobile phone operators have relatively little experience in dealing with these types of issues. Over the past few years, several of the larger operators have been slowly ramping up their staff and skills in these areas," said Starnes.

Another reason that the mobile phone industry has been slow to react to Bluetooth security issues is that they expected the initial threats to come from a combination of SMS and WAP, said F-Secure's Hyppönen

"When we were thinking about mobile viruses, we never thought Bluetooth would be the method used. We were looking at SMS messages containing links or buffer overflows," said Hyppönen.

Neither Nokia nor Sony Ericsson were available for comment.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
87 out of 169 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Campaign Manager

Sets campaign parameters on a daily basis - Ensures campaigns are executed as per agreed business requirements - Monitors campaigns throughput taking ...

Senior Technician (Web Developer) - Warwick

Job Title: Senior Technician (Web Developer - SoftGrid, SMS, SCCM, DNS, SharePoint 2007, SCOM, Internet Filtering & Monitoring) Salary Scale: 18,907 ...

SENIOR FIELD ENGINEER - SMS / ISA / EXCHANGE - GOLD PARTNER - MIDLANDS

FIELD ENGINEER? STRONG WINDOWS SERVER & EXCHANGE SKILLS? WANT TO WORK WITH ALL THE LATEST MICROSOFT TECHNOLOGIES? Then read on New opening for a ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment