Nokia Phones vulnerable to Java Attacks.

A pair of critical vulnerabilities in Sun Microsystems Inc.‘s Java technology for mobile devices could be used by hackers to surreptitiously make calls, record conversations, and access information on Nokia Series 40 cell phones, a Polish researcher said Monday.

Adam Gowdiak, a researcher who has found numerous bugs in Java 2 Micro Edition (J2ME) in the past, said he reported the two vulnerabilities to Sun last Thursday, and notified Nokia the same day of the security issues in its handsets. However, Gowdiak is taking a disclosure tack he admitted will be controversial. He has provided the vendors with only a small subset of the information he’s uncovered, approximately one-to-two pages worth. To obtain the remainder, which includes proof-of-concept code, Sun or Nokia will have to pony up $29,826.

The flaws can be used by attackers to force-feed malicious Java applications to Nokia Series 40 phones, said Gowdiak. Those applications, in turn, could be crafted to conduct all kinds of mischief, including making phone calls from the phone, sending text messages from the phone, and recording audio or video. Hackers could also access any file on a Nokia 40 model phone, obtain read and write access to the phone’s contact list, access the phone’s SIM card, and more, added Gowdiak.

“This can completely wipe out any security within J2ME,” said Gowdiak in an interview Monday. “It allows [attackers] to do anything malicious on any mobile device.”

All told, Gowdiak said he had found 14 security issues with the Nokia Series 40 handsets. The Series 40 is the world’s most widely-used mobile platform, according to Nokia. Gowdiak estimated that approximately 140 different Nokia handsets use the Series 40 platform.

All an attacker needs to hack a specific Series 40 handset is its phone number, Gowdiak claimed. A security flaw in the platform can be exploited by simply sending a maliciously crafted series of messages to a given phone. “By combining the vulnerabilities with the Series 40 issues, one could develop malware which could be simply deployed. And that malware won’t be visible to the user,” he said.

Gowdiak tested seven different Nokia Series 40 handsets — “At least one from each major family in the series,” he said — but he suspects that other manufacturers’ phones that use J2ME may also be vulnerable.

He said that the most current version of Sun’s Java Wireless Toolkit also contains the critical bugs. The Toolkit is essentially a software developer’s toolkit, or SDK, for building wireless applications based on J2ME. The implication, said Gowdiak, is that any application created with the Toolkit would also be open to attack, including those installed on handsets other than Nokia’s.

Nokia did not respond to a request for comment Monday, and although Sun did return a call, its spokeswoman did not have any immediate information about the vulnerabilities reported by Gowdiak.

For his part, Gowdiak said security teams at both companies had confirmed receiving his reports last week. “They seem to be working on these issues,” he added.

But the vulnerabilities may not be what many focus on, Gowdiak admitted.

To fund his start-up — a Polish-based company called Security Explorations — Gowdiak is selling copies of his research for 20,000 euros each. “There are six long months of work in this research,” he said in justifying the price. “It was an enormous amount of research.”

But Gowdiak is savvy enough to know that the move will be controversial. “Of course. The whole security arena is divided,” he argued. “Some will be against this and some will be for it.”

He said that the amount of information he had turned over to Sun and Nokia was “similar” to what he had disclosed to vendors previously. “We’re not blackmailers, we’re not black hats,” he said. “They have a choice whether they want to sign up for our security research or whether they want to [devote] research engineers of their own to investigate the vulnerabilities.

“But in our opinion, they have full vulnerability information.”

He also stressed the special nature of the vulnerabilities he had discovered. “This is the first time that such a widespread and critical attack has been demonstrated against Nokia’s Series 40 devices,” he said. “We have proved that these devices can be hacked and infected with malware in a very similar way PC computers are.”

Still, he was on the defensive. “Some people will attack us, and hate us,” he said, for selling research in this fashion. “But in time, people will be able to judge on their own whether we got it right.”

He stopped short, however, of promising to release more information once Sun and/or Nokia had patched their software. “We’re considering it,” was as far as he would go.

(Source:ComputerWorld)

Current State of the Georgia-Russian Cyberwar

I called it from day one. The minute Russia goes to war, they are going to engage in cyberwarfare tactics. They have executed DDOS attacks against Georgian infrastructure, news networks, and any source that georgians could use to communicate military instruction, pleas for help, or update news agencies by anything other than traditional (generally non-actionable) [...]

Read the full article »

DNS Patch Flaw Still Exists

So you still support Private Disclosure of Bugs? The Huge problem that was recently reported in DNS servers was patched, granted it took nearly a year for all coorporations to come on board. Nearly 75% of all servers are patched to “fix” the issue. “Well, What’s the problem”, you may ask. The problem is the [...]

Read the full article »

Georgia-Russian War

Four hours prior to this story, Russia launched a guided missle at the georgian capital. The tensions between Georgia and Russia have been palpable in the international landscape over the past 5 years- and although there have been skirmishes along the border- never have the two nations been so close to full scale war. Both [...]

Read the full article »

Olympic Cyberscape Threat Analysis

I meant for this to go up the day before the olympics, However- Lightning had other plans. Blew out my modem and any dsl access I had, so here is the delayed version of the olympic cyberscape threat analysis So with the 2008 Beijing Olympics beginning tommorow today, I figured I would do an threat [...]

Read the full article »

Tennessee Valley Authority Laptops Stolen

Wonderful. Yet another government computer is stolen out from under the authorities noses.Supposedly this computer was supposed to be encrypted, however- statistics show that only 30 percent of computers required to be encrypted by law- are encrypted. So chances are that the thief stole this laptop from the back of ANOTHER admin’s car, and instantly [...]

Read the full article »

Java Wielding Pictures

More and More evidence is always stacking up to disable Java inside of your browser. This week, a new attack method was revealed by the “Next Generation Security Software” foundation, along with Ernest & Young Advanced Security Center. It turns out that attackers have been beginning to use a new stealth tactic to gain control [...]

Read the full article »

Traveling Tech?

Recently an article from Scheiner on Security tweaked my interest, as it has many security professionals. I began to research the actual policy and am even more stunned than when I read scheiner’s initial article. It seems that anytime you come in to the country (See Ports of Entry:Here) you are subject to a having [...]

Read the full article »

New Phishing Attempts

Almost daily, You will get emails claiming someone has changed your password, that someone wants to be your friend, or that you just received a huge sum of money from a long lost uncle. The catch? All you have to do is login and put in your secret answer. Most people have discovered that these [...]

Read the full article »

How To Visit A Website (In Internet Explorer)

As many people have already learned, either through word of mouth or by personal experience, Internet Explorer is probably the WORST browser you could use for the security of your personal data. Between gaping holes in the coding, ease of manipulation for viruses, and the mass use in the marketplace, internet explorer is ripe with [...]

Read the full article »