Advertisement
Promo

Security threats Toolkit

Security researcher demands money from Sun, Nokia

David Meyer ZDNet.co.uk

Published: 12 Aug 2008 17:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Polish security researcher has claimed to have found multiple flaws in mobile Java, but is demanding €20,000 (£15,700) in return for full details of the vulnerabilities.

Adam Gowdiak, founder and chief executive of Security Explorations, has written on his website that he has created two proof-of-concept codes — stretching to over 14,000 lines — to attack vulnerabilities "affecting the implementation of mobile Java [J2ME] used by Sun and Nokia in their products". He has published the first few pages of his 178-page report, but will only reveal the rest if Nokia or Sun pay him €20,000.

On his website, Gowdiak stated he is taking this approach "to gather funds for creating a cutting-edge security research centre in Poland", adding: "It's [a] better approach than to beg a [venture capital] company for money." His overall funding target is €1m.

Gowdiak also appears to be a former employee of Sun, according to the biography on his site.

The research paper appears to include information on how to hack into a Nokia Series 40 handset and maliciously target functions such as phone information, SMS sending, audio and video recording, phone-book access and SIM-card access. According to Gowdiak, attackers could initiate phone calls or internet connections, or read and write to files stored on the device.

"Security Explorations successfully verified that Sun's implementation of mobile Java technology used in its latest version of Java Wireless Toolkit software is vulnerable to the discovered flaws," Gowdiak said in a statement, adding that an attacker needed only "a cell-phone number of a target device" in order to gain unauthorised access to "selected Nokia devices".

Gowdiak suggested that his unusual method of obtaining compensation for his research helps maintain "freedom with regard to the research we conduct". In the FAQ section of the Security Explorations website, the company claims not to be afraid of lawsuits because "if a given vendor prefers to throw money for lawyers instead of spending them to improve the security of their products, we can't do anything about it".

Sun was not able to provide comment on Gowdiak's claims at the time of writing on Tuesday, but Nokia issued a statement in which it confirmed it had received a vulnerability notice from Security Explorations.

"Nokia takes security very seriously at all phases of the mobile communications development process, and is investigating the allegations made using our normal processes and comprehensive testing," the statement read. "Nokia is committed to continuously develop its products and services offerings to ensure a positive user experience."

Security researchers who find vulnerabilities already have two outlets for selling them. Through its Zero Day Initiative, TippingPoint offers a bounty and awards programme to researchers who report bugs to the company, while VeriSign's iDefense Vulnerability Contributor Program offers up to $15,000 (£7,900) for "well-researched, high-impact" vulnerabilities.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
5 out of 5 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters