ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec warns users over Bluetooth security

Lynn Tan ZDNet Asia

Published: 21 Sep 2007 09:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

With Bluetooth fast becoming a commonplace feature on mobile devices, users need to be aware of vulnerabilities and learn how to protect themselves from security threats.

A study by research firm InsightExpress revealed that 73 percent of mobile device users are not acquainted with security issues that could put their mobile devices at risk, including mobile phones and Bluetooth-equipped notebooks. To these users, terms such as "bluejacking", "bluesnarfing" or even "bluebugging" would probably be unfamiliar.

"There are many other methods that [launch] a variety of denial-of-service attacks, and even some that could allow an attack to eavesdrop on private conversations," Ooi Szu-Khiam, senior security consultant at Symantec Singapore, said in an email interview. Ooi noted that "numerous instances of mobile viruses, worms and Trojan horses" have emerged in the past year.

"While none has done damage like some of the major PC malware, their rapid evolution presents an obvious cause for concern," Ooi cautioned.

Bluejacking, also known as "bluespamming", is a technique used to send anonymous text messages to mobile users via Bluetooth, Ooi explained. "Phones that are Bluetooth-enabled can be tweaked to search for other handsets that will accept messages sent via Bluetooth."

"Despite the name, it doesn't hijack the phone or suck off the information. It simply presents a message, similar to email spam. The recipient can ignore the unsolicited message, read it, respond or delete it," Ooi said. "While bluejacking can be an extremely annoying onslaught of unsolicited messages, it is generally a minimal security risk."

Bluesnarfing, however, is a more dangerous technique that can allow a malicious hacker to access information stored on a mobile device without its user's knowledge, said Ooi.

"This technique takes advantage of a security flaw, [inherent] in some older versions of Bluetooth-enabled handsets, that could allow an attacker to access and copy data stored on the device without the user's knowledge," Ooi said. The Symantec executive noted that it is still possible to connect to such devices even if the users have configured their devices to be in "non-discovery" mode, where the device remains hidden when someone searches the vicinity for Bluetooth devices.

"Any potentially valuable information stored on a phone, such as address books, calendars, email and text messages, are at risk in a bluesnarfing attack," Ooi said.

A third threat, and possibly the most serious of the three risks, is bluebugging. This technique allows attackers to access mobile-phone commands using Bluetooth technology, without notifying or alerting the device owner, Ooi noted.

"This vulnerability allows the hacker to initiate phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations and connect to the internet," Ooi explained. "As with all the attacks, the hacker must be within a 10-metre range of the [targeted] phone." Unlike bluesnarfing which simply provides attackers access to personal information on the device, bluebugging allows the attacker to take control of a device, he said.

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

To ensure their wireless devices are well-protected, Ooi noted, users can equip their gadgets with mobile security products, which include antivirus, firewall, anti-SMS spam and data-encryption technologies, that are easy to deploy, manage and maintain.

"This kind of layered security can not only mitigate the unique security risks of mobile devices, but can also enable companies to more easily and cost effectively comply with internal security policies and external regulations," Ooi said.

Ooi highlighted four tips on how mobile users can protect their Bluetooth-enabled devices:

Stay offline
Turn off features that you are not using. If you have a Bluetooth-equipped device and do not need the function, then don't turn it on.

Stay invisible
If you are using the Bluetooth function and don't require your device ID to be visible to others, make sure the device's visibility setting is set to "hidden" so malicious hackers will not be able to scan and search for it.

Verify incoming transmission
Do not accept and run attachments from unknown sources unless you are expecting them. For example, if you receive a message to install an application and you don't know its origin, don't run it.

Use passwords
Ideally, use passwords with a large number of digits. A four-digit PIN or password can be broken in less than a second, and a six-digit PIN in about 10 seconds, while a 10-digit PIN would is likely to take weeks to crack.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
17 out of 17 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Drive Test / Field Trials Engineer - Mobile Handsets - Berkshire

My client, a leading Telecoms company based in Berkshire are currently recruiting for a Field Trials Engineer to work in a small team responsible for ...

Security/Quality Analyst-00055189

Meet the application maintenance security lead on the fortnightly basis to coordinate efforts to reduce application security risks and close any open ...

IBM Websphere Message Broker- Flow Developer- ESQL JAVA

IBM Websphere Message Broker (WBIMB) Flow Developer (ESQL or JAVA) urgently required by my West Midlands client for a short term contract. You will ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment