Palm PDA threat to network security

Networks could be vulnerable because passwords don't protect data held on Palm PDAs, according to a warning from the US-based security firm @Stake.

Written by Aoife White, Network News

Networks could be vulnerable because passwords don't protect data held on Palm PDAs, according to a warning from the US-based security firm @Stake.

Chris Wysopal, technical director of research and development at @Stake, said that a back door in the Palm OS allows anyone with developer tools to access information with the tap of a stylus.

Advertisement

Palm's debugging program can be exploited by anyone ready to read the Palm OS developer's manual online and hitch up a PC to a Palm. The program is installed on all devices, and is designed to be used only by application developers and technical support.

The program allows anyone to type in commands such as 'coldboot' to wipe all data from the device, or 'export' to copy everything onto another computer. The program can also be used to access a user's Palm password.

An attacker could copy the contents of the average Palm in about five minutes and decrypt a password in a few seconds.

Besides the fact that network managers tend to put commercially sensitive data in their PDAs, Palm devices, which can exchange data with a network, could also be used to crack into a classified network.

"It is not possible to employ a secure application on top of an insecure foundation," said Wysopal. "Because the Palm OS is inherently insecure, methods to completely secure data are moot. A Palm device should not be left unattended, or loaned to a potentially untrustworthy colleague," Wysopal added.

@Stake recommends Palm users glue a piece of plastic over the Palm's serial port connector, leaving the infra-red port as the only method of synching or disabling the Palm's port by opening the case and cutting the specific RS232 lines.

This will prevent an attacker using the debug mode if activated, but would also void the Palm warranty.

A Palm spokesman said improved security protection for the Palm will come with the release of the Palm OS v4.0 this month. PGP encryption for the Palm OS can be downloaded from several software sites.

Also published in Network News

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

Ministry of Defence

MoD data loss total could hit 1.7 million

New figures far higher than initial estimates   More...

Sun Microsystems

Sun Sparc server shatters seven standards

T5440 sets new benchmark records   More...

Gary McKinnon

Home Office turns down latest McKinnon appeal

Home Secretary informs lawyers of arrangements for US extradition   More...

Network cables

Network Instruments touts nanosecond apps troubleshooting

Observer 13 offers upgraded performance and forensic network analysis   More...

Primary Navigation