All the latest UK technology news, reviews and analysis

RIM plays down BlackBerry hack threat

by Will Head

14 Aug 2006

Be the first to comment

  • Tweet this
A new threat that could make BlackBerry devices vulnerable to attack requires
RIM claims that the attack is only possible if the built-in security policies of the BlackBerry Enterprise Server are not enabled

A new threat that could make BlackBerry devices vulnerable to attack requires "several reaching assumptions", according to Research In Motion

The BBProxy attack, demonstrated by security specialist Jesse D'Aguanno, opens a back channel bypassing the organisation's gateway security mechanisms between the hacker and the inside of the victim's network. 

"The scenario depicted makes several reaching assumptions about a BlackBerry Enterprise Server deployment," said RIM in a statement.

The attack is only possible if the built-in security policies of the BlackBerry Enterprise Server are not enabled, the company claimed.

"The ability to load and run any third-party software on a BlackBerry device is controlled by an IT policy setting on the BlackBerry Enterprise Server, which would have to be allowed by the administrator," said RIM.

"Furthermore, the ability for a third-party application to make an external connection from a BlackBerry device is also controlled by an IT policy setting in BlackBerry Enterprise Server and would have to be allowed by the administrator.

"In addition, the ability for the BlackBerry Mobile Data System to have access to systems on an internal network is also controlled by an IT policy setting in BlackBerry Enterprise Server, which would also have to be allowed by the administrator."

RIM also stated that it would not be possible to infect a handheld by emailing the malware to an unsuspecting user as an attachment, since the BlackBerry Enterprise Server does not allow users to download attachments to the device.

The company has published two PDF documents outlining the security measures users should take:

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Java developer (J2EE/Web) - Nr Warrington (off M6)

Java / J2EE analyst programmer with experience of building...

Crystal Reports Developer London or Dublin £340 per day

Crystal Reports Developer London or Dublin £340 per day...

Systems Administrator

Our client is a major Broadcasting company seeking a...

Support Engineer - Linux/ Windows

Support Engineer required to work for leading Online...

To send to more than one email address, simply separate each address with a comma.