iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > Is Your Company Data Secure? Blackberry Hacks Are Here
Search:
[ news_security_news ]

Is Your Company Data Secure? Blackberry Hacks Are Here



Rebecca Welch
Contributing Writer
2006-09-08

SecurityProNews: Insider Reports Insider Reports RSS Feed


There's a new route into your company's secure data. It's the Blackberry PDA.

A hacking program has been developed which exploits the relationship between the Blackberry itself, a company's internal server and the network connection to which both are attached. The hacking program works because the data tunnel between the Blackberry and the server is encrypted. Intrusions can't be detected because the protective systems, such as firewalls, exist at the perimeter of the network. This begs the question of all business owners whose employees use a Blackberry: Is your company data secure?

The hacking technique is successful because there are very few companies equipped to detect an intrusion from the inside of the network. Another reason for hacking success is the fact that companies don't see the Blackberry as a potential attack vector.

The Blackberry is not your normal handheld device. It's a continuously running code machine that's always on and always connected to your internal network. It has constant direct access to whatever you give it access to and most company structures allow complete access to the internal network for their employees who use Blackberries. BBProxy is the name of the Blackberry hacking program. It can be loaded on the Blackberry either physically or via e-mail as a Trojan horse.

Once loaded, the Blackberry will call back to the hacker's system and open communication channels between the hacker and the internal network of the company. This process runs in the background behind the safety of the company's firewall scanning for hosts with vulnerabilities in security and is generally undetected.

Recently, an ad on eBay sold a Blackberry "AS IS" for approximately $15.00. While the device didn't come with a cable, synching station, software or manual, it did come with something far more valuable. This Blackberry came with a stockpile of corporate data all there for anyone to read as soon as the device was turned on.

Many employees are insufficiently trained concerning security issues for the electronic devices they use on a daily basis. Company data is stored as attachments on a server, rather than the Blackberry itself, so if a device is ever lost or misplaced someone could easily read sensitive documents. The Blackberry lacks encryption capabilities and relies instead on users locking the device with a password. Unfortunately, anyone with hacking abilities could discover the password and let themselves into the network.

The beauty of the Blackberry is that it's a do it yourself type of device. It basically allows you to take your office with you wherever you go and not be caught unprepared or without the correct documents of a given meeting. However, for individuals and companies who handle and funnel much of their business dealings through these wonderfully useful devices, both internal and external server security must be taken into account.


Tag:

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:



About the Author:
Rebecca Welch is a successful Webmaster and publisher of BestCameraCellPhone.com. She provides researched information on camera cell phones and other mobile communication devices.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds