BlackBerry has spyware risk too, researcher says
Security news and headlines - updated as needed.

Moderators: Forum Experts, Management

BlackBerry has spyware risk too, researcher says

Postby rippinchikkin on Mon Feb 08, 2010 7:10 am

Image

BlackBerry has spyware risk too, researcher says
by Elinor Mills
February 7, 2010 9:00 AM PST

We've heard a lot about security issues with the iPhone, but the BlackBerry isn't immune to threats from malicious apps. Tyler Shields, a senior researcher at the Veracode Research Lab, has written a piece of spyware that allowed me to shoot an SMS command to his phone and have his contact list forwarded to my e-mail address in a demonstration.

With another short text command, I was able to get his BlackBerry to e-mail me any SMS messages he sends. And if I had wanted--and he had allowed me-I could have seen a log of all his calls, monitored his inbound text messages, tracked his location in real-time based on the GPS (Global Positioning System) in his device and turned his microphone on to listen to conversations in the room and record them.

"It's trivial to write this type of code using the mobile provider's own API [application programming interface] they provide to any developer," Shields said in an interview in advance of his talk on the spyware scheduled for the ShmooCon security show on Sunday. He calls his program "TXSBBSpy" and is releasing the source code but not an executable version of it.

"My goal is to show how easy it is to create mobile spyware," he said. TXSBBSpy "can take data from the phone, both in real-time and in snapshots, and send it off via SMS or e-mail to any Web server or TCP [Transmission Control Protocol] or UDP [User Diagram Protocol] network connections," Shields said.

CNET Blogs
A rubber band pistol was confiscated from algebra class because it was a weapon of math disruption.
User avatar
rippinchikkin
VP - Syndication
 
Posts: 9183
Joined: Thu Mar 18, 2004 8:38 pm
Location: 32°28′05″N 93°46′16″W

Return to Security News

Who is online

Users browsing this forum: No registered users and 0 guests