Ads by TechWords

See your link here
Receive the latest technology news and information.
Mobile/Wireless Computing
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Careless downloading makes BlackBerry users spy targets

October 7, 2009 10:15 AM ET

IDG News Service - IPhone lovers and other smartphone users should take heed: A security researcher showed ways to spy on a BlackBerry user during a presentation Wednesday, including listening to phone conversations, stealing contact lists, reading text messages, taking and viewing photos and figuring out the handset's location via GPS.

And ironically, Sheran Gunasekera, head of research and development at ZenConsult, said the BlackBerry is one of the most secure smartphones available, in some ways better than the iPhone.

"There is no technical way of hacking a BlackBerry, it's impossible," said Gunasekera, during a presentation at the Hack In The Box security conference in Kuala Lumpur. "It's just too secure for that. So we have to rely on social engineering."

For hackers, social engineering is the art of tricking someone into loading spyware onto a device or finding some other way to install it, such as borrowing the device and downloading malware from the Internet or a MicroSD card, for example.

One way to entice a BlackBerry user to download spyware onto their smartphone is by offering a free application that appears to be a game or some other harmless software, but in fact carries a dangerous payload. Enticing slideshows are even easier to get users to accept, Gunasekera said.

"I will have the slideshow running on top and the spyware doing its nastiness on the bottom," he said.

What kind of nastiness?

A small piece of software able to conceal itself by not appearing on the BlackBerry's application menu, nor taking up much memory space nor using much processing power, can allow a hacker to do all kinds of things.

"People tend to put a lot of personal data on a BlackBerry," he said, but it's not just the data on the phone that's at risk.

Spyware on a BlackBerry could intercept a phone call and let the hacker listen in, or even let the hacker listen to a meeting the victim is sitting in on. By silently answering the victim's phone, then turning on the speakerphone, the spyware could allow the hacker to overhear the meeting. It could also forward incoming and outgoing text messages to the hacker, and even enable the hacker to write messages from the victim's BlackBerry, or run up the victim's phone bill by making international calls.

The hacker could also program the spyware to have the handset's camera take pictures every 10 seconds, for example, to see find out the victim's location.

One recent example shows a massive installation of spyware on BlackBerry phones in the United Arab Emirates.

Regional mobile phone service provider Etisalat last June told its 145,000 BlackBerry subscribers to download a software upgrade that turned out to be spyware. Once users downloaded the "upgrade," it forwarded the phone's e-mails to a central server, Gunasekera said. The ploy was discovered because the software drained BlackBerry batteries at an excessive rate, in as fast as 30 minutes after a full recharge.


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

HITB

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Accelerating Your Mobile Workers: Controlling the Uncontrollable
Today's workforce is truly mobile. Unlike the managed environment of the office LAN, remote users face many challenges to being productive while out...

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Managing Laptops Outside the Office
Learn how you can reduce costs by tracking mobile computers no matter where they are located.

Mobile U Webinar
Watch Now!

The New Mobile Order
Download Now  

4G Ahead Video Program
Uncover the features and benefits of the two leading 4G technologies for enterprises considering future deployment.

WAN Application Delivery for Executives
Learn how to simplify server and application administration without creating performance problems for distributed users.  

Horror stories: Managing IT Across Multiple Locations
How one extra sharp IT manager eliminates daily agony, hassle and repetition.


IT Jobs