Click here to learn
about this Sponsor:
Home  |  News  |  Articles  |  Polls  |  Forum  |  Directory

Keywords: Match:
Whitepaper warns of Windows Mobile malware
Sep. 06, 2007

McAfee's Avert Labs has released a whitepaper discussing ways hackers might attack Windows Mobile-based smartphones. Author Zhu Cheng says there is no significant risk today, "but we're in the early stages of what is likely to become a longstanding trend," attributed partly to Microsoft's release of Windows CE kernel source.

Spread the word:
digg this story
Pointing out that carrying a smartphone is basically like having a computer in your pocket, Cheng claims Windows Mobile is vulnerable to attack. "Windows CE's open-source kernel policy allows virus writers to get a deep understanding of the operating system," he writes.

"Developing software under Windows Mobile and Win32 is very similar, so it's easy for authors of Win32 malware to transition to mobile malware," Cheng charges. As an example, he cites the possibility that hackers could turn a smartphone into a secret audio recorder: "Many recording APIs and codecs used by Windows can be applied to Windows Mobile, and serve as a reference for mobile malware authors."

Threats

The whitepaper says the greatest threats to mobile phones lie in these seven areas:
  • Text messages
  • Contacts
  • Video
  • Phone transcriptions
  • Call records
  • Documentation
  • Buffer overflows
With regard to text messaging, says Cheng, Avert Labs has observed examples of SMS phishing, where fake and potentially malicious messages are sent to everyone on a user's contact list. Viruses can also use text message APIs to charge cell phone fees through the SMS payment gateway, he writes.

"According to the Windows Mobile Software Development Kit, an application developer could write code using the sample code MapiRule and load it to implement text message blocking," Cheng charges. By modifying this framework for use as a DLL, it's claimed a hacker could launch a man-in-the-middle attack, intercepting, or responding to message.

With regard to contacts, Cheng says many users take advantage of Windows Mobile smartphones' contact backup tools, which typically use programming calls such as IPOutlook, ItemCollection, Ifolder, and Icontact from the Pocket Outlook Object Model APIs in the Windows Mobile SDK API. "Malware developers could easily use these calls to get and modify contact information and send the results to someone else," he says.

In the area of video, Cheng theorizes that "through Microsoft's APIs, mobile malware could take over the phone and use its camera to snap photos, though it would probably be difficult to get a good angle." However, he says, a virus could search for all JPG files already on a device through the file API, then send those files to a malicious third party.

Audio recordings also pose a threat, Cheng writes. Though limited storage space means malware cannot record indefinitely, it could send audio recordings to a hacker via email or via the Multimedia Message Service (MMS). Malware could use SMS to turn this function on and off, he claims.

Call records are not particularly valuable, but malware can be used to steal documents, once again using the file API function, Cheng warns. "Files with the extensions *.doc, *.xls, and *.pdf are likely to become popular targets for mobile malware thieves," he says.

Finally, "buffer overflows also plague mobile devices," Cheng writes. "Way back at Xcon 2005, we saw a presentation on hacking Windows CE 4. The talk included shell code development advice as well as sample code."

Remedies

In his whitepaper, Cheng suggests some remedies for both users and software developers. For users, he unsurprisingly recommends anti-virus and anti-malware tools, but also says users should follow "safe browsing practices," and only install programs that have digital signatures from reputable manufacturers.

Users should also be careful with their phone's wireless functionality, disabling WiFi and Bluetooth when they are outdoors, Cheng says. Also, "if you find your phone is auto-connected to GPRS (General Packet Radio Service), then your mobile might be infected with a virus that is sending your data to other parties."

To protect valuable data, users should back it up regularly, Cheng says. Asserting that "smartphones and PDAs are simply not very secure," he says confidential files or photos should be stored on removable disks.

For programmers, Cheng suggests using Visual Studio .NET 2005, which adds a security_cookie function to prevent buffer overflows. This strengthens a program's security, but he urges programmers to still check the length of the character string that transmits to the buffer, making sure it will not cause an overflow.

"The profit motive is driving malware writers in increasing numbers to create mobile viruses," Cheng charges. "The bottom line is that the danger is not going away."

To download a copy of this thought-provoking whitepaper, "Mobile Malware: Threats and Prevention," in PDF format, go here.

To download a Microsoft-written article on Windows 5.0 application security -- recommended by Cheng -- go here.



Related stories:


(Click here for further information)


7 Advantages of D2D Backup
For decades, tape has been the backup medium of choice. But, now, disk-to-disk (D2D) backup is gaining in favor. Learn why you should make the move in this whitepaper.

4 Legal Reasons to Control Internet Access
The Internet is obviously a valuable resource for many organizations. However, many are exposed to legal liability concerns because they fail to control Internet access. Learn if you're safe in this white paper.

Rapidly Resolve J2EE Application Problems
Whether you are in the process of building J2EE applications or have J2EE applications already running in production, you must ensure that they deliver the expected ROI. Learn how in this white paper.

Load Testing 2.0 for Web 2.0
There are many unknowns in stress testing Web 2.0 applications. Find out how to test the performance of Web 2.0 in this white paper.

Build Better Games Online
For the game infrastructure providers, life is complex. Making money from games has become more complicated. Why? Find out in this white paper.

Building a Virtual Infrastructure from Servers to Storage
This white paper discusses the virtual storage solutions that reduce cost, increase storage utilization, and address the challenges of backing up and restoring Server environments.

Gaining Faster Wireless Connections with WiMAX
Welcome to what is quickly becoming the hyperconnected world where anything that would benefit from being connected to the network will be connected. Learn more in this white paper.

Is Your Desktop a Security Threat?
The new wave of sophisticated crimeware not only targets specific companies, but also targets desktops and laptops as backdoor entryways into those business’ operations and resources. Learn how to stay safe in this white paper.

Increasing SAN Reliability by 100 Percent
Storage area networks (SAN) are a strong part of storage plans. Learn how to increase your reliability and uptime by 100 percent in this case study.

 


Got a HOT tip?   please tell us!
Free weekly newsletter
Enter your email...
Click here for a profile of each sponsor:
PLATINUM SPONSORS
(Become a sponsor)

ADVERTISEMENT
(Advertise here)


Check out the latest Windows-powered...

mobile phones!

other cool
gadgets

HOT TOPICS
Microsoft targets PNDs with new embedded OS
Microsoft tips .NET MF 3.0 highlights
Microsoft previews Windows Embedded Standard
Microsoft offers free Windows CE 6.0 textbook
Microsoft renames embedded operating systems
Microsoft unveils Windows Mobile 6.1
New Atom models target low-cost PCs
REFERENCE GUIDES
Windows Device Showcase
Intro to Windows Embedded
Intro to Shared Source
Real-time Windows Embedded
Windows Embedded books
Join our Windows Embedded discussion forums:
Windows XP Embedded
Windows CE
Windows Mobile


Windows Embedded developer newsgroups
Windows CE
XP Embedded
PocketPC
Smartphone

Microsoft's Windows Embedded resources
Embedded dev center
Mobile dev center
Windows CE tutorials
XP Embedded tutorials
Windows Embedded seminars
Windows Embedded application categories
3rd-party partners


BREAKING NEWS

• Upated JVM supports Windows CE
• Windows Mobile 6.1 phone has GPS
• Windows CE thin client hides in wall sockets
• Portable spectrum analyzer runs Windows CE
• VoIP client gains add-ons, API
• Windows Mobile phone has dual active SIMs
• Access gives away Windows Mobile utilities
• Intel's Atom powers mini-ITX board
• Microsoft revamps Windows Mobile website
• Low-cost phone bundles IM client
• Pico-ITX board bears twins
• Microsoft details finalists in student competition
• Intrinsyc revs Windows CE-based software platform
• $300 mini-laptop runs Windows CE
• Microsoft releases server virtualization technology


MOST POPULAR (last 90 days)
Windows Mobile 6 SDKs available for download
Guide to HTC's Windows Mobile smartphone platforms
Microsoft unveils Windows Mobile 6.1
HTC announces unlocked Windows Mobile 6.1 phone
UMPC squeezes in optical drive
Running Windows Mobile 6.1 on your desktop computer
Microsoft releases Windows XP Service Pack 3
Mobile Firefox gets speedup, design tweaks
MOST POPULAR (Classics from the vault)
The Windows Mobile Phones Showcase
Windows XP Embedded USB boot
Troubleshooting Windows XPe's blue screen "Stop 0x0000007B" error
Asus reveals $190 mini notebook
HTC adds GPS to Windows Mobile Touch line
Windows Mobile VPN client plays with Cisco
Guide to HTC's Windows Mobile smartphone platforms
Customizing Windows XP Embedded thin clients
The Windows Mobile Pocket PCs Showcase

Also visit our sister sites:


Sign up for WindowsForDevices.com's...

news feed

Home  |  News  |  Articles  |  Polls  |  Forum  |  Directory  |  About  |  Contact
 

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
Tech RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video | VARs | Channel News

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | Enterprise Network Security | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | Security IT Hub | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | igrep

Use of this site is governed by our Terms of Service and Privacy Policy. Except where otherwise specified, the contents of this site are copyright © 1999-2008 Ziff Davis Enterprise Holdings Inc. All Rights Reserved. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise is prohibited. Windows is a trademark or registered trademark of Microsoft Corporation in the United States and/or other countries and is used by WindowsForDevices under license from owner. All other marks are the property of their respective owners. WindowsForDevices is an independent publication not affiliated with Microsoft Corporation.