BlackBerry smartphones open to SMS attack

By Tom Espiner, ZDNet UK
Thursday, October 01, 2009 09:42 AM

BlackBerry mobile devices are open to attack due to a certificate notification flaw in the smartphone's software, according to Research In Motion.

The problem lies in the BlackBerry Browser, specifically in the dialog box that alerts users if the URL they have clicked on does not match the domain they are being sent to, the company warned in an advisory on Monday.

To exploit the flaw, a hacker could craft a malicious website that spoofs a trusted website, then send users a link to that site using text messaging or email. If the malicious domain name contains a null character and the user chooses to access the site, the certificate-handling software on the device will note that there is a mismatch, but the warning dialog box will not display the null character in the link.

For example, the URL 'zd[null character]net.co.uk' will generate an alert, which will tell the user they are about to visit 'zdnet.co.uk'. BlackBerry users may ignore this alert, as malicious websites could appear benign, RIM said.

"RIM recommends that BlackBerry device users exercise caution when clicking on links that they receive in email or SMS messages," the company said in its advisory. "If a user visits a site that causes a BlackBerry Browser dialog box to warn the user about continuing the connection, the user should select Close connection."

BlackBerry Device Software from version 4.5 onwards is affected. RIM has provided a software update, available from the BlackBerry updates site, to mitigate the issue.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Configure Apache to support multiple SSL sites on a single IP address

Open Source

With Apache 2.2.12 and support for the Server Name Indication extension to the SSL protocol, you can configure name-based HTTPS sites, just as you can name-based HTTP sites.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web