Home > Ask the Security Experts > Information Security Threats Questions & Answers > Defining mobile device security concerns
Ask The Security Expert: Questions & Answers
EMAIL THIS

Defining mobile device security concerns

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 January 2008
What is the greatest security concern with mobile applications for PDAs, BlackBerrys and other similar mobile products?

>
EXPERT RESPONSE
The biggest issue here is the information stored on these devices. Think about it: an innocuous-looking PDA, BlackBerry or cell phone likely holds some valuable secrets about a person's enterprise and life. What would a competitor give for your phone contacts? How about a copy of recent emails or an appointment calendar? For most enterprise personnel, the information they carry on their PDAs is a goldmine for the bad guys.

Today, the most common method for stealing information from mobile devices is physical theft. Few people password-protect their cell phones and PDAs, although the vast majority of products on the market support authentication with a simple PIN. Yes, it's inconvenient, but it significantly boosts security. (The downside, unfortunately, is that if the cell phone is lost and you try to call it, an innocent person who finds the phone will likely be unable to answer it without the PIN, making it difficult to get it back. But, for many people, the information on their mobile devices is far more valuable than the actual hardware itself, so protecting that information at the risk of losing the hardware might be a reasonable trade-off.)

While physical theft dominates today, remote exploitation is an emerging vector for information theft from mobile devices. Some of these attacks involve a bad guy sending device content (such as an email or text message) that exploits a flaw such as a buffer overflow. Other attacks involve the mobile device user accessing a service set up by an attacker, such as using a browser on the mobile device to surf to a website hosting the attacker's content. Either way, the device is exploited, making it run code and install software of the attacker's choosing. That code could tell the device to send all of the sensitive information back to the hacker, across the network wirelessly, meaning all of your data was just swiped out of your pocket, likely without you knowing it.

Given the widespread use of these devices, the valuable information stored on them and the "newness" factor of creating exploits for this rapidly expanding realm of the IT industry, it's no wonder that many are diligently hunting for remote mobile device exploits. In fact, the Metasploit project includes an exploit for Apple's iPhone Safari Web browser, exploiting a flaw in its TIFF image-handling library. Metasploit includes a nifty shell called ipwn (pronounced "eye-pone") as a payload an attacker can use for the exploit. The attacker gets remote command shell access to an iPhone simply because its user surfed to the machine on which the attacker was running Metasploit. While the TIFF flaw was patched on a recent iPhone update, not all users are running the latest software. And, surely numerous other flaws will be found for not only the iPhone, but also other kinds of mobile platforms. Mobile device software should be kept up-to-date to lower the chance of falling prey to this kind of attack.

For more information:

  • In this tip, Core Competence's Lisa Phifer reviews today's options for achieving secure remote access from Windows mobile smartphones.
  • Contributor Ed Skoudis examines iPhone-specific attacks, and reveals how organizations can limit their exposure as the popular devices infiltrate the enterprise.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Information Security Threats
    What are the dangers of cross-site request forgery attacks (CSRF)?
    Should social engineering tests be included in penetration testing?
    What kind of data is compromised during a Google hack?
    Best practices for using restriction policy whitelists
    What security measures can be taken to stop crimeware kits?
    What software development best practices can prevent input validation attacks?
    What is the most secure way for application developers to manage cookies?
    Is there a market for standalone antivirus products?
    Can 'herd intelligence' effectively stop malware?
    Should keystroke loggers be used in enterprise investigations?

    Handheld and Mobile Device Security
    Should enterprises implement a mandatory iPhone VPN?
    Should iPhone email be sent without SSL encryption?
    Employee-owned handhelds: Security and network policy considerations
    How secure is a mobile phone platform that has an open source framework?
    Is the mobile malware threat overblown?
    Secure remote access: Closing the Windows Mobile Smartphone loophole
    iPhone security in the enterprise: Mitigating the risks
    Should the enterprise be concerned with the Apple iPhone's automatic connection to Wi-Fi networks?
    Apple iPhone SDK could increase security threats
    McAfee acquires SafeBoot for endpoint encryption
    Handheld and Mobile Device Security Research

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts