• your Windows® embedded community

    eWEEK Windows for Devices - Your Windows Embedded Community

    Windows For Devices

  • home
  • news
  • embedded PCs
  • boards
  • handhelds
  • tablets
  • thin clients
  • enterprise
  • consumer
  • articles

    News

  • Home > News

        Article highlights PDA security threats

        Doug | Date: Aug 22, 2005 | Comments: 1



        • Print PDF
        • Filed Under: News

        An article in the current issue of [In]Secure magazine suggests that the perception of PDAs as "simple devices" has left many corporate networks vulnerable to attack. Not only can the PDAs themselves be compromised, but PDAs can also be used as trojans to attack a network, writes author Seth Fogie.




        Fogie begins by pointing out that attacking a PDA is not as easy as attacking a PC. Because the operating system is in ROM, PDAs tend to be unique, and the art of exploiting PDAs is relatively new, he notes. But if a hacker is willing to accept these limitations and is sufficiently obsessed, there are a number of ways that PDAs can be exploited.

        Fogie explains how cabinet files and the autorun feature of removable media cards can be used to introduce malicious programs. He shows how Pocket Internet Explorer can be used to trick users into revealing personal information. Additionally, the Soft Input Panel (SIP) that substitutes for a hardware keyboard on Pocket PCs can easily be replaced by a seemingly identical program that is also a keystroke logger, according to Fogie.

        But beyond simple attacks on the device itself, a PDA can be a powerful tool for attacking corporate networks. Fogie shows how a Linux-based PDA equipped with WiFi, an Ethernet card, and a "sniffer" program can be surreptitiously plugged into a network behind the firewall to create a "drop and go" backdoor.

        [In]Secure magazine is available as a PDF download here. The article by Seth Fogie is titled "PDA attacks: palm sized devices -- PC sized threats."



        Related stories:
        • Report notes growth of malicious code targeting mobile devices
        • Free Wi-Fi scanner utility finds rogue devices
        • "Identity management" software secures mobile apps at device level
        • Windows Mobile antivirus software upgrade nears beta
        • Mobile device antivirus software gains enhanced virus detection, disinfection
        • Partnership aims to improve mobile device wireless security
        • Security software guards Windows Mobile Pocket PCs
        • Developing a security policy for mobile devices
      • Newsletter
      • RSS
      • Twitter
      • Got a Tip?
      • Linux Devices

    most read

    • ARM Windows 8 may nix desktop
    • Autonomous robot's built around a Windows Phone handset
    • Intel ships Cedar Trail Atoms
    • America's first 'WhiteFi' network goes live
    • Tiny module boots Windows Embedded Compact 7 in 800 milliseconds

      WfD showcase archives

      • Mobile Phones
      • PDAs and other handhelds
      • Netbooks
      • Windows tablets, UMPCs, and MIDs
      • Audio/video entertainment devices
      • Thin client terminals and devices
      • Voice over IP devices
      • SPOTlight on .NET Micro Framework (MF)
      • SPOT-light on Microsoft's "SPOT" Technology
      • Other smart devices

  • eWEEK Quick LInks
  • Home
  • Windows & Interoperability
  • Mobile & Wireless Technology
  • Application Development
  • Enterprise Applications
  • Enterprise Networking
  • Desktops & Notebooks
  • Technology Videos
  • ZDE Corporate Site
  • Linux for Devices
  • Microsoft Watch Blog
  • Migration Expert Zone
  • Smarter Technology
  • ASP Free
  • Scripts
  • Tutorialized
  • Technology Resource Library

Site Map

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2010 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. eWEEK and Spencer F. Katt are trademarks of Ziff Davis Enterprise Holdings, Inc.
Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.