Security Hole Claimed for BlackBerrys
New research released over the weekend indicated that BlackBerrys -- the ubiquitous handheld devices favored by on-the-go types -- are vulnerable to a security hole that could let attackers break in to the gadgets by convincing users to open a specially crafted image file attached to an e-mail.
The information was released at the 22nd Chaos Communication Congress hacker convention in Berlin by this guy -- "FX" of the security research group Phenoelit.
Research in Motion Ltd., the Canadian company that makes the devices, said it is a previously reported issue "that has been escalated internally to our development team. No resolution time frame is currently available." RIM's advisory downplays the threat, saying that "a corrupt Tagged Image File Format (TIFF) file sent to a user may stop a user's ability to view attachments. There is no impact on any other services (for example, sending and receiving messages, making phone calls, browsing the Internet, and running handheld applications to access a corporate network)."
RIM didn't mention anything about the flaw allowing attackers to download and execute programs on the targeted device, but I'm left wondering whether they escalated this because of just such a threat. I obviously didn't hear FX's talk, but an alert released over the weekend by US-CERT says remote code execution is possible.
RIM doesn't say when it plans to have a fix available, but for now it is urging companies who use the service to reconfigure any machine serving as an internal BlackBerry Internet Server to filter TIFF images or disable the file-attachment capability altogether.
Update, 10:27 a.m. ET: Having just spoken with FX (a.k.a Felix Lindner), I definitely feel like I understand the threat here a bit better, and it is a little more serious than I first thought. Lindner said the real problem -- a vulnerability in the way Blackberry servers handle portable network graphics (PNG) images, was not disclosed by either RIM or the US-CERT advisory. Lindner said he suspects that's because this PNG flaw is present not in the newest version of Blackberry server but in all versions from 4.0 to 4.0.1.9 (the latter was released roughly a month ago, and no doubt many companies still run that version).
Lindner said he started looking into Blackberry's proprietary communications protocols because the Blackberry server requires an unusual level of access inside of a corporate network: the server must be run inside a company's network firewall and on a Windows machine that is granted full and direct administrative access to the customer's internal e-mail server.
"We started looking at all of the privileges this server needs while sitting right in the middle of the network and realized we didn't know anything about it," Lindner said. "In a lot of companies, corporate managers want to install it because they want their Blackberrys, but we wanted to find out what risks are there connected to running this thing."
Lindner's slides from his presentation -- which he agreed not to release until RIM has fully fixed this problem -- show that the Blackberry server which manages all of the encryption keys needed to unscramble e-mail traffic to and from all Blackberry devices registered on the network stores them on a Micorosft SQL database server in plain, unencrypted text.
Lindner found that by convincing a Blackberry user to click on a special image attachment, that handheld device could be made to pass on malicious code to the Blackberry server, which could then be taken over and used to intercept e-mails or as a staging point for other attacks within the network.
I put in a call to the RIM folks: Will update the post if I get a response from them directly.
By
Brian Krebs
|
January 3, 2006; 1:10 AM ET
Categories:
Latest Warnings
Share This: E-Mail | Technorati
| Del.icio.us | Digg | Stumble
Previous: Security Hole Claimed for BlackBerrys
Next: Security Hole Claimed for BlackBerrys
Posted by: tsmith | January 3, 2006 4:13 PM | Report abuse
"We started looking at all of the privileges this server needs while sitting right in the middle of the network and realized we didn't know anything about it," Lindner said.
"Quis custodiet ipsos custodes?", still, obviously, an open question.
Posted by: GTexas | January 3, 2006 4:33 PM | Report abuse
Thank you for the latest in information. We will pass the word.
HLC
Posted by: H.L.Cornell | January 3, 2006 6:04 PM | Report abuse
I hear there is a company that makes an antivirus program for Blackberry called fb-4. http://www.fb-4.com
Posted by: Bob Johnson | January 3, 2006 7:49 PM | Report abuse
sk18ild2-1000025005
Posted by: Anonymous | March 24, 2006 8:19 AM | Report abuse
bkvnb41r-1000034963
Posted by: Anonymous | March 24, 2006 12:49 PM | Report abuse
6jvoqbyr-102215647
Posted by: Anonymous | March 27, 2006 10:15 AM | Report abuse
c2b42yyb-102277801
Posted by: Anonymous | March 28, 2006 12:33 AM | Report abuse
bkvnb41r-202885535
Posted by: Anonymous | March 28, 2006 9:21 AM | Report abuse
hmdzzb2e-102369284
Posted by: Anonymous | March 28, 2006 10:52 PM | Report abuse
[url=http://spaces.msn.com/50-cent-window-shopper/blog[/url] window shopper music
Posted by: Anonymous | March 30, 2006 6:46 AM | Report abuse
bebarh8z-102592596
Posted by: Anonymous | March 31, 2006 9:28 PM | Report abuse
otu953v9-203287809
Posted by: Anonymous | April 3, 2006 5:27 PM | Report abuse
vjok149y-203323479
Posted by: Anonymous | April 4, 2006 12:37 AM | Report abuse
[url=http://spaces.msn.com/50-cent-window-shopper/blog[/url] window shopper music
Posted by: 50 cent window shopper mp3 | April 7, 2006 9:52 AM | Report abuse
s2p4k46i-603033634
Posted by: Anonymous | April 13, 2006 11:32 AM | Report abuse
5kst2hp8-103233677
Posted by: Anonymous | April 13, 2006 11:06 PM | Report abuse
I hope everyone has enjoyed the blog as much as I have enjoyed writing it.
Tyrell parkins
Posted by: Tyrell parkins | May 3, 2006 2:25 AM | Report abuse
7kn58x0o-1000998293
Posted by: Anonymous | May 3, 2006 8:12 PM | Report abuse
javg8ev2-304485916
Posted by: Anonymous | May 3, 2006 10:16 PM | Report abuse
itosj1co-304549633
Posted by: Anonymous | May 5, 2006 3:52 PM | Report abuse
2tvhy5bo-1001060686
Posted by: Anonymous | May 5, 2006 6:25 PM | Report abuse
Your site is very informative, interesting and a certain daily visit for critical weather information. Thank you.
Posted by: Chad | June 22, 2006 11:05 AM | Report abuse
Thank you for your website. We have found it very interesting and helpful.
Posted by: Wendy | June 26, 2006 7:37 AM | Report abuse
The comments to this entry are closed.












Nitpick: PNG is "portable", not "portal" (http://www.google.com/search?q=define%3APNG&start=0&ie=utf-8&oe=utf-8&client=firefox-a&rls=org.mozilla:en-US:official)