All the latest UK technology news, reviews and analysis

Researchers crack Palm webOS with a text message

by Iain Thomson

19 Apr 2010

Comments: 4

  • Tweet this
Palm Pre
WebOS security is full of holes, say researchers

Researchers have managed to crack Palm's webOS with a simple text message. The team at Intrepidus Group worked on a Palm Pre running the 1.3.5. version of the webOS operating system, and found it open to many common vulnerabilities due to its inherent design.

"As we started to pry a little it became quite apparent that Palm's new WebOS platform was riddled with some pretty dangerous bugs," said the team in a blog post.

"These bugs can all be traced back to the fact that webOS is essentially a web browser and the applications are written in JavaScript and HTML.

"This also means that webOS applications are subject to the numerous web applications vulnerabilities that any seasoned penetration tester would be all too familiar with."

The researchers loved the operating system as a concept, but were scathing about the security of the handset, saying that Palm must have put "almost no thought into security".

They found common web application flaws built into applications that Palm had written itself.

The team said that the SMS system did not perform input/output validation. This allows an HTML injection attack by inserting an iFrame into the message, which is automatically activated. The team then demonstrated this in a video.

The announcement comes at a low point in Palm's history, with poor financial results, the resignation of its chief executive and rumours of a takeover in the offing.

UPDATE: Intrepidus Group has updated its post to point out that its findings affect an older version of the Palm OS.

"Palm has since released WebOS 1.4, which fixes these vulnerabilities, though not all handsets or carriers are running this version. Due to contractual agreements, the public disclosure of this information was delayed," the firm noted.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

10%

53%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Technischer Consultant

Ihre Aufgaben Sie sind zuständig für die Beratung...

MS Visual Basic Programmierer

***MS Visual Basic Programmierer mit Oracle DB-Erfahrung...

IT Business Analyst

IT Business Analyst Location: London, but...

Senior Software Developer

Senior Software Developer Company overview...

To send to more than one email address, simply separate each address with a comma.