ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

RIM plugs BlackBerry phishing hole

By | September 30, 2009, 5:48am PDT

Summary: Research in Motion (RIM) has shipped a fix for a serious security vulnerability that exposes BlackBerry users to phishing attacks.

Research in Motion (RIM) has shipped a fix for a serious security vulnerability that exposes BlackBerry users to phishing attacks.

The certificate handling vulnerability, which carries a CVSS severity score of 6.8, affects all versions of the BlackBerry device software.  The flaw allows malicious hackers to trick BlackBerry device users into connecting to an attacker-controlled Web site, RIM warned in an advisory.

Here’s the crux of the problem:

A malicious user could create a web site that includes a certificate that is purposely altered using null (hidden) characters in the certificate’s Common Name (CN) field or otherwise manipulated to deceive a BlackBerry device user into believing they have connected to a trusted web site.

If the malicious user then performs a phishing-style attack by sending the BlackBerry device user a link to the web site in an SMS or email message that appears to be from a trusted source, and the BlackBerry device user chooses to access that site, the BlackBerry Browser will correctly detect the mismatch between the certificate and the domain name and display a dialog box that prompts the user to close the connection. However, the dialog box does not display null characters, so the user may believe they are connecting to a trusted site and disregard the recommended action to close the connection.

This screenshot provided by RIM shows an example of a BlackBerry Browser dialog box that does not clearly indicate that there is a mismatch between the web server address and its associated certificate:

BlackBerry users are urged to download and apply the patch the BlackBerry Device Software as soon as possible.

In the meantime, RIM recommends that BlackBerry device users exercise caution when clicking on links that they receive in email or SMS messages.

“If a user visits a site that causes a BlackBerry Browser dialog box to warn the user about continuing the connection, the user should select Close connection,” the company said.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
5
Comments

Join the conversation!

Just In

RE: RIM plugs BlackBerry phishing hole
lovedong 13th Sep
so awesome!! replica watches
0 Votes
+ -
Software version
ChrisDTC Updated - 30th Sep 2009
Is there anywhere RIM states the software versions that contain the patch? I used their online tool to check my AT&T Bold and it told me v4.6.0.297 that I installed a month ago was the most current software.
0 Votes
+ -
Useless
cj100570@... 30th Sep 2009
I got the same result with my Storm. 1 would think that an update such as this would simply be pushed out OTA or at least install the next time I connected my device to the Desktop Manager. I don't want a flame war to ensue but this is 1 place where Apple has a good handle on how to do things; you always know where to go to get an iPhone update.
0 Votes
+ -
so awesome!! replica watches
0 Votes
+ -
It seems the patch is not available for download just yet! Read this post from Berryreview.com from yesterday - it has some great info in it for added understanding on this issue:
-------------------------------------
Al spotted this latest security advisory from RIM about their browser. Turns out that most of the official BlackBerry OS versions out there are susceptible to a browser certificate issue where NULL characters in the certificate can fool users into thinking they are on a trusted website.

From RIM's Advisory:

RIM recommends that BlackBerry device users exercise caution when clicking on links that they receive in email or SMS messages. If a user visits a site that causes a BlackBerry Browser dialog box to warn the user about continuing the connection, the user should select Close connection.

Essentially a malicious hacker could send you a link to a website that has a certificate altered with hidden null characters. The phishing style attack can then send you an email and correctly popup a message saying that the certificate's Common Name field does not match. The problem is that it wont show the null characters so it will look like the message to the right. Make sure to CLOSE THIS CONNECTION!

Sadly it looks like RIM is yet again playing the carrier waiting game and letting carriers approve the patched OS versions before releasing them. I guess RIM has yet to find a solution for Zero Day vulnerabilities that may arise in the future.

the table below lists the versions you need to have to no longer be susceptible to such a bug. Notice how AT&T is still on Bold OS 4.6.0.297. while version .303 is the patched version.

Current software version
Software version to update to

BlackBerry Device Software Version 4.5.0.x
BlackBerry Device Software Version 4.5.0.173 or later

BlackBerry Device Software Version 4.6.0.x BlackBerry Device Software Version 4.6.0.303 or later

BlackBerry Device Software Version 4.6.1.x BlackBerry Device Software Version 4.6.1.309 or later

BlackBerry Device Software Version 4.7.0.x BlackBerry Device Software Version 4.7.0.179 or later

BlackBerry Device Software Version 4.7.1.x BlackBerry Device Software Version 4.7.1.57 or later



Posted for ?BerryReview by Ronen Halevy, September 29, 2009, 12:58 pm. | RIM Reveals Browser Certificate Vulnerability | 10 comments |

http://rss.berryreview.com/~r/Berryreview/~3/Z7AY63EqseA/
0 Votes
+ -
RE: RIM plugs BlackBerry phishing hole
birumut Updated - 2nd May 2011
Great!!! thanks for sharing this information to us!
seslisohbet seslichat

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix