<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: rim]]></title>
    <link>http://securityratty.com/tag/rim</link>
    <description></description>
    <pubDate>Tue, 15 Jul 2008 17:36:34 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Mobile Malware: What Happens Next?]]></title>
      <link>http://securityratty.com/article/d71cca5983e4ab9c718dae0efdb33c2c</link>
      <guid>http://securityratty.com/article/d71cca5983e4ab9c718dae0efdb33c2c</guid>
      <description><![CDATA[Four years ago, F-Secure Chief Research Officer Mikko Hypponen was talking about malware infections on mobile phones while few others were paying attention. With the growing use of Internet-enabled...]]></description>
      <content:encoded><![CDATA[Four years ago, F-Secure Chief Research Officer Mikko Hypponen was talking about malware infections on mobile phones while few others were paying attention. With the growing use of Internet-enabled phones, particularly Apple's iPhone and RIM's Blackberry, he sees more opportunities than ever for malicious activity. But, surprisingly, he sees a quiet mobile malware landscape at the moment.]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mobile phones">mobile phones</category>
      <category domain="http://securityratty.com/tag/phones">phones</category>
      <category domain="http://securityratty.com/tag/malware infections">malware infections</category>
      <category domain="http://securityratty.com/tag/malicious activity">malicious activity</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/attention">attention</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/ago">ago</category>
      <source url="http://www.networkworld.com/news/2008/111208-mobile-malware-what-happens.html?fsrc=rss-security">Mobile Malware: What Happens Next?</source>
    </item>
    <item>
      <title><![CDATA[Sucking Data off of Cell Phones]]></title>
      <link>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</link>
      <guid>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</guid>
      <description><![CDATA[Don't give someone your phone unless you trust them: There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is...]]></description>
      <content:encoded><![CDATA[<p>Don't <a href="http://news.cnet.com/8301-1009_3-10028589-83.html?tag=newsEditorsPicksArea.0">give someone your phone</a> unless you trust them:</p>

<blockquote>There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is also available to the public. It is called the Cellular Seizure Investigation Stick, or CSI Stick as a clever acronym. It is manufactured by a company called Paraben, and is a self-contained module about the size of a BIC lighter. It plugs directly into most Motorola and Samsung cell phones to capture all data that they contain. More phones will be added to the list, including many from Nokia, RIM, LG and others, in the next generation, to be released shortly.</blockquote>

<p>Another <a href="http://www.physorg.com/news139460365.html">news article</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FDP4FL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FDP4FL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WZ1UtL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WZ1UtL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 02:03:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phones">phones</category>
      <category domain="http://securityratty.com/tag/capture">capture</category>
      <category domain="http://securityratty.com/tag/electronic capture device">electronic capture device</category>
      <category domain="http://securityratty.com/tag/samsung cell phones">samsung cell phones</category>
      <category domain="http://securityratty.com/tag/news article">news article</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/intelligence operations">intelligence operations</category>
      <category domain="http://securityratty.com/tag/csi stick">csi stick</category>
      <category domain="http://securityratty.com/tag/clever acronym">clever acronym</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/sucking_data_of.html">Sucking Data off of Cell Phones</source>
    </item>
    <item>
      <title><![CDATA[RIM Patches Acrobat Distiller Bug In BlackBerry Server]]></title>
      <link>http://securityratty.com/article/02ce12e9df4cd927182e34bf011131f8</link>
      <guid>http://securityratty.com/article/02ce12e9df4cd927182e34bf011131f8</guid>
      <description><![CDATA[Recently we blogged about a serious vulnerability in the PDF distiller in the BlackBerry Attachment Service . Now RIM has announced resolutions to the problem. BlackBerry Enterprise Server version 4.1...]]></description>
      <content:encoded><![CDATA[Recently we blogged about <a href="http://blogs.eweek.com/cheap_hack/content/wireless/blackberry_pdf_distiller_vulnerability.html">a serious vulnerability in the PDF distiller in the BlackBerry Attachment Service</a>. 

Now RIM has announced resolutions to the problem. 

BlackBerry Enterprise Server version 4.1 customers can fix it by applying Service Pack 6 (bringing the product to version 4.1.6). There are also interim fixes for users of earlier versions. Follow the links in <a href="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=KB15766">the advisory</a> to the download pages.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=c4675f66e90a3bf80b26daaecb898ca7" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=c4675f66e90a3bf80b26daaecb898ca7" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/342919462" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 13:27:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry attachment service">blackberry attachment service</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/download pages">download pages</category>
      <category domain="http://securityratty.com/tag/pdf distiller">pdf distiller</category>
      <category domain="http://securityratty.com/tag/interim fixes">interim fixes</category>
      <category domain="http://securityratty.com/tag/rim">rim</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/342919462/rim_patches_acrobat_distiller_bug_in_blackberry_server.html">RIM Patches Acrobat Distiller Bug In BlackBerry Server</source>
    </item>
    <item>
      <title><![CDATA[RIM Patches Acrobat Distiller Bug in BlackBerry Server]]></title>
      <link>http://securityratty.com/article/7e0fbf4dab4725d7ebbee96c2038fa25</link>
      <guid>http://securityratty.com/article/7e0fbf4dab4725d7ebbee96c2038fa25</guid>
      <description><![CDATA[Recently we blogged about a serious vulnerability in the PDF distiller in the BlackBerry Attachment Service. Now RIM has announced resolutions to the problem. BlackBerry Enterprise Server Version 4.1...]]></description>
      <content:encoded><![CDATA[Recently we blogged about <a href="http://blogs.eweek.com/cheap_hack/content/wireless/blackberry_pdf_distiller_vulnerability.html">a serious vulnerability in the PDF distiller in the BlackBerry Attachment Service.</a>

Now RIM has announced resolutions to the problem. 

BlackBerry Enterprise Server Version 4.1 customers can fix it by applying Service Pack 6 (bringing the product to Version 4.1.6). There are also interim fixes for users of earlier versions. Follow the links in <a href="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=KB15766" target="_blank">the advisory</a> to the download pages.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/s0_nPPTswQA" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 13:27:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry attachment service">blackberry attachment service</category>
      <category domain="http://securityratty.com/tag/service pack">service pack</category>
      <category domain="http://securityratty.com/tag/download pages">download pages</category>
      <category domain="http://securityratty.com/tag/pdf distiller">pdf distiller</category>
      <category domain="http://securityratty.com/tag/interim fixes">interim fixes</category>
      <category domain="http://securityratty.com/tag/rim">rim</category>
      <category domain="http://securityratty.com/tag/follow">follow</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/versions">versions</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/s0_nPPTswQA/rim_patches_acrobat_distiller_bug_in_blackberry_server.html">RIM Patches Acrobat Distiller Bug in BlackBerry Server</source>
    </item>
    <item>
      <title><![CDATA[GOING MOBILE: Developing an Effective Corporate Mobile Policy]]></title>
      <link>http://securityratty.com/article/828d0bb8db3ec4a011cdb8318f8c83f4</link>
      <guid>http://securityratty.com/article/828d0bb8db3ec4a011cdb8318f8c83f4</guid>
      <description><![CDATA[Source: RIM) Mobilizing your business is a journey, and it starts with planning and ensuring that you have the right infrastructure and management tools in place to support your needs for today, and...]]></description>
      <content:encoded><![CDATA[<b>(Source: RIM)</b>  Mobilizing your business is a journey, and it starts with planning and ensuring that you have the right infrastructure and management tools in place to support your needs for today, and tomorrow.  Download this paper now.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=cvhOk4"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=cvhOk4" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/342590981" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/management tools">management tools</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/starts">starts</category>
      <category domain="http://securityratty.com/tag/journey">journey</category>
      <category domain="http://securityratty.com/tag/tomorrow">tomorrow</category>
      <category domain="http://securityratty.com/tag/rim">rim</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/342590981/whitepapers.do">GOING MOBILE: Developing an Effective Corporate Mobile Policy</source>
    </item>
    <item>
      <title><![CDATA[GOING MOBILE: Developing an Application Mobilization Plan for your Business]]></title>
      <link>http://securityratty.com/article/b2fab559bb09f9678c1e8d8f9643e329</link>
      <guid>http://securityratty.com/article/b2fab559bb09f9678c1e8d8f9643e329</guid>
      <description><![CDATA[Source: RIM) Mobilizing your business is a journey, and it starts with planning and ensuring that you have the right infrastructure in place to support your needs for today, and tomorrow. Download...]]></description>
      <content:encoded><![CDATA[<b>(Source: RIM)</b>  Mobilizing your business is a journey, and it starts with planning and ensuring that you have the right infrastructure in place to support your needs for today, and tomorrow.  Download this paper now.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=9GiwxC"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=9GiwxC" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/342574688" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/starts">starts</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/journey">journey</category>
      <category domain="http://securityratty.com/tag/tomorrow">tomorrow</category>
      <category domain="http://securityratty.com/tag/rim">rim</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/342574688/whitepapers.do">GOING MOBILE: Developing an Application Mobilization Plan for your Business</source>
    </item>
    <item>
      <title><![CDATA[RIM fixes critical BlackBerry Enterprise Server bug]]></title>
      <link>http://securityratty.com/article/bfc871ac37ef3d48c54598e291c7f14f</link>
      <guid>http://securityratty.com/article/bfc871ac37ef3d48c54598e291c7f14f</guid>
      <description><![CDATA[Research In Motion patched a critical bug in its BlackBerry Enterprise Server to stymie hackers trying to break into company networks by tricking users of the smart phone into opening rigged...]]></description>
      <content:encoded><![CDATA[Research In Motion patched a critical bug in its BlackBerry Enterprise Server to stymie hackers trying to break into company networks by tricking users of the smart phone into opening rigged PDFs.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=qmRMdE"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=qmRMdE" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/339214709" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry enterprise server">blackberry enterprise server</category>
      <category domain="http://securityratty.com/tag/company networks">company networks</category>
      <category domain="http://securityratty.com/tag/critical bug">critical bug</category>
      <category domain="http://securityratty.com/tag/smart phone">smart phone</category>
      <category domain="http://securityratty.com/tag/stymie hackers">stymie hackers</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/pdfs">pdfs</category>
      <category domain="http://securityratty.com/tag/motion">motion</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/339214709/article.do">RIM fixes critical BlackBerry Enterprise Server bug</source>
    </item>
    <item>
      <title><![CDATA[RIM warns BlackBerry admins of critical unpatched PDF bug]]></title>
      <link>http://securityratty.com/article/5818d66b5efef83a63d84662e8133781</link>
      <guid>http://securityratty.com/article/5818d66b5efef83a63d84662e8133781</guid>
      <description><![CDATA[RIM has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's...]]></description>
      <content:encoded><![CDATA[RIM has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's computers.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=IYY3WO"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=IYY3WO" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/338341605" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry enterprise server">blackberry enterprise server</category>
      <category domain="http://securityratty.com/tag/rim">rim</category>
      <category domain="http://securityratty.com/tag/critical vulnerability">critical vulnerability</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/administrators">administrators</category>
      <category domain="http://securityratty.com/tag/component">component</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/338341605/article.do">RIM warns BlackBerry admins of critical unpatched PDF bug</source>
    </item>
    <item>
      <title><![CDATA[RIM warns BlackBerry admins of critical unpatched PDF bug]]></title>
      <link>http://securityratty.com/article/1ebf6a92c9337c87cac7f3b371d86504</link>
      <guid>http://securityratty.com/article/1ebf6a92c9337c87cac7f3b371d86504</guid>
      <description><![CDATA[Research in Motion has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's...]]></description>
      <content:encoded><![CDATA[Research in Motion has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's computers.]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry enterprise server">blackberry enterprise server</category>
      <category domain="http://securityratty.com/tag/critical vulnerability">critical vulnerability</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/computers">computers</category>
      <category domain="http://securityratty.com/tag/administrators">administrators</category>
      <category domain="http://securityratty.com/tag/component">component</category>
      <category domain="http://securityratty.com/tag/hack">hack</category>
      <category domain="http://securityratty.com/tag/motion">motion</category>
      <source url="http://www.networkworld.com/news/2008/071708-rim-warns-blackberry-admins-of.html?fsrc=rss-security">RIM warns BlackBerry admins of critical unpatched PDF bug</source>
    </item>
    <item>
      <title><![CDATA[BlackBerry PDF Distiller Vulnerability]]></title>
      <link>http://securityratty.com/article/66ec1734af2f38fc7f62bfaed5c983b4</link>
      <guid>http://securityratty.com/article/66ec1734af2f38fc7f62bfaed5c983b4</guid>
      <description><![CDATA[An unpatched vulnerability in the PDF distiller in the BlackBerry Attachment Service has been revealed by Research In Motion. Thanks to the Internet Storm Center for alerting us to the problem. The...]]></description>
      <content:encoded><![CDATA[An <a href="http://www.blackberry.com/btsc/dynamickc.do?externalId=KB15766&sliceId=SAL_Public&command=show&forward=nonthreadedKC&kcId=KB15766" target="_blank">unpatched vulnerability in the PDF distiller in the BlackBerry Attachment Service has been revealed by Research In Motion.</a> Thanks to the Internet Storm Center for <a href="http://isc.sans.org/diary.html?storyid=4733" target="_blank">alerting us to the problem.</a>

The distiller is a program that reads PDF files and re-renders them in a format that the BlackBerry can display. The BlackBerry Attachment Service runs on the BlackBerry Enterprise Server. The advisory is somewhat unclear as to whether the BlackBerry device is itself vulnerable; more likely it is the server on which the BlackBerry Attachment Service runs that can be compromised by a malicious PDF file. This service has been compromised in the past by malicious files, as its job is to parse a wide variety of file formats, a task that is difficult to protect against attacks, especially heap overflows.

The advisory and some BlackBerry lockdown guides, such as <a href="http://www.dsd.gov.au/library/pdfdocs/BlackBerry_Hardening_Guide_Dec07.pdf">this one from the Australian Department of Defense (PDF),</a> recommend that the Attachment Service be run on a separate computer on an isolated network segment in order to minimize the damage that any compromise can do. The advisory also includes other workarounds you can perform, such as disabling the distiller's support for PDF files.

RIM has no time frame for a resolution of the problem.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=510e541532e18080119b476af7bcaf37" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=510e541532e18080119b476af7bcaf37" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/336629834" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 17:36:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/pdf">pdf</category>
      <category domain="http://securityratty.com/tag/reads pdf files">reads pdf files</category>
      <category domain="http://securityratty.com/tag/pdf files">pdf files</category>
      <category domain="http://securityratty.com/tag/blackberry device">blackberry device</category>
      <category domain="http://securityratty.com/tag/blackberry enterprise server">blackberry enterprise server</category>
      <category domain="http://securityratty.com/tag/blackberry attachment service">blackberry attachment service</category>
      <category domain="http://securityratty.com/tag/attachment service">attachment service</category>
      <category domain="http://securityratty.com/tag/distiller">distiller</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/336629834/blackberry_pdf_distiller_vulnerability.html">BlackBerry PDF Distiller Vulnerability</source>
    </item>
  </channel>
</rss>
