Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Microsoft needs to rethink Windows Mobile security

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Microsoft needs to rethink Windows Mobile security
LinkBack Thread Tools Display Modes
Old 02-Jan-2007, 09:11 PM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,715
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Microsoft needs to rethink Windows Mobile security

I got my first Windows Mobile device in 2004, a Telecom New Zealand HTC Falcon Smartphone phone running the Windows for PocketPC 2002 variant of the Microsoft’s operating system for handhelds and the next year, the EV-DO Rev 0 enabled HTC Harrier, with Windows Mobile 2003 Second Edition loaded. I really liked the phones, but being used to Windows in general, one of the first things I looked for was an update function of some kind, to apply bug fixes and security patches.

There was none. I thought this was remarkable at the time, and interviewed Microsoft about it for the Virus Bulletin. Microsoft downplayed the risks and basically said “try not to get infected”, a response that didn’t satisfy Michael Moser of IBM Research GmbH in Switzerland, who wrote a follow-up story in Virus Bulletin critical about Microsoft’s approach to security for Windows Mobile devices.

The original alert about the MMS exploit came via Ollie Whitehouse at Symantec’s security blog. Whitehouse points to Colin Mulliner’s working exploit using SMIL (Synchronized Multimedia Integration Language). All you need to do to make use of the exploit is to send an MMS with the malicious code to someone. If that person views the MMS message, s/he’s “0wn3d” (Colin lists multiple exploits in fact, with effects ranging from remote Denial of Service to execution of arbitrary code on the device being attacked).

I talked to Geekzone’s resident expert on mobile devices in general and Windows Mobile in particular, Mauricio Freitas about the MMS exploit. He points out that the MMS clients are supplied by third-party vendors and not Microsoft. The vendors in question should release fixes as soon as possible, and Mauricio also thinks it’s irresponsible to release a working exploit while there’s no patch for the vulnerability. It should also be noted that Symantec has what could be deemed a conflict of interest here, as it offers security solutions for mobile devices.

In principle, I agree with Mauricio here. At the same time though, Colin Mulliner reported the vulnerability to Microsoft and Arcsoft in July last year, and disclosed it on Bugtraq in August. It’s now January 2007, so where are the patches? Well, there are none. This goes back to what I discovered in 2005, that urgent security maintenance on Windows Mobile (or should I say, Windows CE?) is almost impossible.

When it comes to something like the MMS exploit, vendors have to develop a patch, make sure it passes Microsoft’s scrutiny and then test it with their manufacturer and carrier partners around the world. What’s more, the patch wouldn’t be distributed via Microsoft or the vendor, but through the carrier partners. This is a slow and cumbersome process with customers being left vulnerable for months if not years on end.

Is this really acceptable? Windows Mobile devices are in many cases deployed by corporate customers whose users hook them up to the workplace network. Sure, you can add firewalling and even put an anti-virus or malware detector on the WM device, but surely it would be better plug the vulnerability instead?

Maybe it’s time for Microsoft to rethink how it manages Windows Mobile security before a mass attack happens.
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 11:59 AM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228