Welcome | Sign In
ECommerceTimes.com
Security

Exploit Code to Target BlackBerry Users

Print Version
E-Mail Article
Reprints
Exploit Code to Target BlackBerry Users

Exploit code known as "BBProxy" and aimed at the BlackBerry mobile computing device is due for release next week, security specialists are warning. The code can be sent as an e-mail attachment to an unsuspecting BlackBerry user. Once installed, BBProxy opens a back channel which can bypass an organization's gateway security mechanisms to create a line of communication between the hacker and the victim's network.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Organizations that have installed BlackBerry servers behind their gateway security devices could be subject to a hacker attack, according to security researchers.

Secure Computing (Nasdaq: SCUR) is warning companies to prepare for security researcher Jesse D'Aguanno's release of hacking code for the BlackBerry next week.

The hacking program -- called BBProxy -- can be sent as an e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse attachment to an unsuspecting BlackBerry user. Once installed, BBProxy opens a back channel which can bypass an organization's gateway security mechanisms to create a line of communication between the hacker and the victim's network.

"We are not saying that this is a vulnerability in the BlackBerry. It is designed to provide this client-server model across an encrypted tunnel," Paul Henry, vice president of Strategic Accounts for Secure Computing, told TechNewsWorld. "However, someone without the best of intentions may decide to use that capability to possibly gain entry into a corporate network and bring malware in or remove confidential information from the network."

A Silent Attack

BBProxy could enter the corporate network through a tunnel that is most often opened by the administrator to allow the encrypted communications channel access to the BlackBerry server inside the organization's network. A malicious person could potentially use this back channel to move around inside an organization's network, undetected.

Because BBProxy uses an encrypted tunnel, Henry said, chances are no would know that an attack has occurred. Security personnel cannot inspect the tunnel properly because it is encrypted.

"The facilities are available within the BlackBerry to prevent the use of this application, but it would require that the administrator take the time to configure it," Henry said.

Henry's concern is that people tend to address issues such as BBProxy as non-issues. Often they believe that a pathway is secure because it is encrypted. That, he stressed, is simply not true. Encryption alone does not equal security.

Closing the Loop

Henry suggests some common sense network architecture and simple policies to reduce the risk of this impending threat, as well as others like it that depend on the encrypted tunnel to gain network access.

First, he notes, servers connecting to the public Internet have an inherent risk. Isolating these Internet-facing servers reduces the risk of a compromised server providing access to other critical servers. Hence, due diligence would require that any Internet-facing server like a BlackBerry server should be isolated on its own, Demilitarized Zone (DMZ) segment.

A DMZ is a part of the network that is neither part of the internal network nor directly part of the Internet. In other words, it is a network sitting between two networks.

Additional Measures

Next, only those connections that are necessary to facilitate the operation of the BlackBerry server should be permitted, Henry said. The BlackBerry server should not be permitted to open arbitrary connections to the internal network or Internet.

In addition, Henry said the mail server that is working with the BlackBerry server is also an Internet-facing server, and should also be isolated on its own separate DMZ.

Only those connections necessary to facilitate the normal operation of the mail server should be permitted. Like the BlackBerry server, the mail server should not be permitted to open arbitrary connections to the internal network or Internet.

Finally, internal users should not be permitted to open arbitrary connections to either the BlackBerry server or mail server.

BlackBerry maker Research in Motion could not immediately be reached for comment.


Print Version E-Mail Article Reprints More by Jennifer LeClaire


Related News Alerts

Hacker Activate Alert | Search Archives

More by Jennifer LeClaire

The Digital Car: Cool Automotive Accessories, Part 2
January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers
January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand
January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network