PPCGeeks Forums HTC Arrive HTC HD2 HTC Thunderbolt HTC Touch Pro 2 HTC Evo 4G HTC Evo 3D Samsung Galaxy S II Motorola Droid X Apple iPhone Blackberry
Go Back   PPCGeeks > Site Information > Smartphone News > News Archives
Register Community Search

Notices


Reply
 
LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 10-20-2008, 07:54 PM
0wolfe's Avatar
N00b
Offline
Pocket PC: tp
Carrier: sprint
 
Join Date: May 2008
Posts: 32
Reputation: 5
0wolfe is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Ppc Viruses Are Coming!!!!

kaspersky also make a a PPC backround virus software.
Reply With Quote
This post has been thanked 1 times.
  #12 (permalink)  
Old 10-21-2008, 05:36 AM
ny152's Avatar
PPCGeeks Regular
Offline
Pocket PC: htc touch
Carrier: sprint
 
Join Date: Jul 2008
Posts: 194
Reputation: 295
ny152 is becoming a PPCGeeks regularny152 is becoming a PPCGeeks regularny152 is becoming a PPCGeeks regular
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Ppc Viruses Are Coming!!!!

There's a FREEWARE Spybot version for Windows Mobile... go here for info and d/l:

http://www.download.com/Spybot-Searc...dlPid=10575061
Reply With Quote
This post has been thanked 2 times.
  #13 (permalink)  
Old 10-21-2008, 06:15 AM
Aniken's Avatar
N00b
Offline
Pocket PC: HTC Touch PRO 2
Carrier: Sprint
Location: Blacklick, Ohio
 
Join Date: Aug 2007
Posts: 44
Reputation: 55
Aniken is becoming a great contributor
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to Aniken
Viruses are already here.

There is a well documented issue with Active Sync and it's ability to "crossover" a trojan from your PPC. I agree that a "three-finger salute" would solve the problem but the loss of data as noted in the article following the link would for sure be a pain in the *** if your in the field.

http://news.zdnet.co.uk/hardware/0,1...9254952,00.htm
Reply With Quote
This post has been thanked 1 times.
  #14 (permalink)  
Old 10-21-2008, 06:58 PM
dannzeman's Avatar
I love root
Offline
Pocket PC: HTC Hero
Carrier: Sprint
Location: Iowa -- Go Hawkeyes!
 
Join Date: Jan 2007
Posts: 1,588
Reputation: 2175
dannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIP
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Viruses are already here.

Quote:
Originally Posted by Aniken View Post
There is a well documented issue with Active Sync and it's ability to "crossover" a trojan from your PPC. I agree that a "three-finger salute" would solve the problem but the loss of data as noted in the article following the link would for sure be a pain in the *** if your in the field.

http://news.zdnet.co.uk/hardware/0,1...9254952,00.htm
Wow, not to slam you or anything but that article was published in March of 2006. I think desktop AV software has progressed enough since then to catch that. Even so, all of us here are pretty much on the edge of mobile tech news and if some virus did show up we'd pretty well informed about it.

http://www.wmexperts.com/articles/ed...are_mobil.html
__________________
Join the PPCGeeks Group in Google Maps with Latitude
Quote:
Originally Posted by Big D5
Lesson learned don't work on PPC while drinking.
Reply With Quote
  #15 (permalink)  
Old 10-21-2008, 07:34 PM
Aniken's Avatar
N00b
Offline
Pocket PC: HTC Touch PRO 2
Carrier: Sprint
Location: Blacklick, Ohio
 
Join Date: Aug 2007
Posts: 44
Reputation: 55
Aniken is becoming a great contributor
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to Aniken
Re: Ppc Viruses Are Coming!!!!

I would definitely agree that for the most part... some posters are among the smartest using a PPC.
However, I think you missed the entire point of my post. Although your PC, my PC or most any PC running a decent AV would ultimately block or remove a virus, you have to agree that any data loss on a your PPC, well maybe not yours, would not be warmly received. I too can find articles that disagree with your post. Hence the following....Please remember your not always right.

A Simple Sync Can 'Sink' Your PC

Researchers release proof-of-concept for attack on Windows' ActiveSync 4.0

SEPTEMBER 30, 2008 | Careful when you sync your mobile handset with your PC: Researchers have found a way to hack their way into a PC that runs Microsoft’s ActiveSync 4.0.

White Wolf Security has released proof-of-concept code called ActiveSink that demonstrates how an attacker could use ActiveSync 4.0 to hack into a PC via an attached Windows Mobile device. “The vulnerability is that all an attacker needs to do is plug in a Windows Mobile device to a PC with ActiveSync installed -- in its default mode -- and the mobile device will establish a direct TCP/IP connection to the host PC. This happens whether or not the users account is locked,” says Seth Fogie, chief security officer at White Wolf Security and vice president of Airscanner Corp. “Once the connection is established, then it is a matter of penetration testing and exploitation.”

Fogie says it’s basically yet another method of bypassing a firewall. He contacted Microsoft about the vulnerability over a month ago, and was told someone would get back with him, but so far, no word.

At the heart of the problem is the so-called Remote Network Driver Interface Specification (RNDIS) Microsoft added to version 4.0 of the syncing application, which basically opens the door for an attacker, according to White Wolf’s research.

Fogie describes AppSink this way: It creates a user account on the targeted system and establishes a “reverse-shell” on it and back to the Windows Mobile device. The attacker would plug his Windows Mobile device into the targeted system and “tuck it behind” it, Fogie says, and use tools like Metasploit or Wireshark to hack into the machine wirelessly via the mobile device. Once it found the vulnerable elements, it could then exploit them or add a new account on the victim’s PC to access data on the machine, he says.

This isn’t the first sync vulnerability discovered, but previous ones mostly have been man-in-the-middle or spoofing attacks, Fogie says. This one just goes after ActiveSync 4.0’s operations. “It only takes one vulnerable PC to actively sink your network's security — even if that PC is kept offline and/or behind a corporate firewall,”
Reply With Quote
  #16 (permalink)  
Old 10-21-2008, 07:47 PM
schettj's Avatar
morsus mihi
Offline
Pocket PC: iPhone 4
Carrier: AT&T
Location: Not from around these parts
 
Join Date: Oct 2006
Posts: 3,017
Reputation: 3616
schettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIPschettj is still contributing even after becoming a VIP
Mentioned: 2 Post(s)
Tagged: 0 Thread(s)
Re: Ppc Viruses Are Coming!!!!

So, just to recap in case you didn't understand it...

When you connect any device it creates a local network between itself and the PC - so it's now "inside" the corporate firewall, talking to exactly 1 PC (yours) as if it were a peer node on the local network.

So, then, you run something like ICS on the winmo, and you connect to it, and then you can start probing the one PC its connected to to find something on the PC you can exploit via a network connection.

Most/many firewalls will by default firewall the RNDIS adapter, so if you're running one of those this assault dies there. Also, this assumes the PC is logged in with AS running and USB connection enabled. I'm reasonably sure if you're not LOGGED IN, there is 0 risk as well.

Frankly, if MR BAD HACKER is roaming my hallways looking to jack into a locked PC to see if its running activesync, I have MUCH BIGGER security issues*

* simple example. MR BAD walks in, finds a conference room with an open ethernet port, and drops in a wifi access point. If he's good, he drops about 15 of these around with ssid like "Corporate Trial Do not Use" "Testing" "Accounting" etc... with WPA enabled.

Then he goes outside, fires up his laptop, and has at the corporate network as a first class node.

But indeed, you should BE AFRAID and most importantly SEND MONEY TO SOMEONE TO FIX THIS!!!

Sheesh.
__________________
Reply With Quote
This post has been thanked 1 times.
  #17 (permalink)  
Old 10-21-2008, 08:02 PM
Aniken's Avatar
N00b
Offline
Pocket PC: HTC Touch PRO 2
Carrier: Sprint
Location: Blacklick, Ohio
 
Join Date: Aug 2007
Posts: 44
Reputation: 55
Aniken is becoming a great contributor
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to Aniken
Re: Ppc Viruses Are Coming!!!!

Thanks again schettj, as I said "some posters are among the smartest using a PPC."
Reply With Quote
  #18 (permalink)  
Old 10-21-2008, 08:43 PM
dannzeman's Avatar
I love root
Offline
Pocket PC: HTC Hero
Carrier: Sprint
Location: Iowa -- Go Hawkeyes!
 
Join Date: Jan 2007
Posts: 1,588
Reputation: 2175
dannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIPdannzeman is a VIP
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Re: Ppc Viruses Are Coming!!!!

Aniken, I wasn't saying you were wrong and I was right. I was merely make the point that we as a community, or at least I myself, haven't heard a lot about viruses taking over our ppc's. I never said it wasn't possible or that they don't exist. I was just trying to make the point that I don't think AV software is needed on our phones yet and if viruses ever did get out that we'd be informed about it.
Reply With Quote
  #19 (permalink)  
Old 10-22-2008, 12:19 AM
PocketPcUser's Avatar
Regular 'Geeker
Offline
Pocket PC: XV-6700 (Verizon HTC Apache)
Carrier: Only PPCGEEKS.com; I don't even pay monthly anymore.
 
Join Date: Feb 2007
Posts: 432
Reputation: 200
PocketPcUser is keeping up the good workPocketPcUser is keeping up the good workPocketPcUser is keeping up the good work
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via AIM to PocketPcUser Send a message via MSN to PocketPcUser
Re: Ppc Viruses Are Coming!!!!

I think the bigger issue here, is not a "virus," but a "bug" that could be far more harmful. Here is the example:
You write a software code that performs a hard-reset, and boom, you are just as much in trouble, then having your device infected. This is where the real possiblity lies, but there is little to be done to prevent an attack like this.
Thus, since it is so easy to do, the AV companies (IMO) obviously are in charge of the development of both the AV products, and the viruses etc. too... Isn't hackers supposed to be relentless, with new viruses coming out each day?
__________________
If you have been helped by me, or I
have provided services to you; and since I don't
charge for my technical support, please consider donating
by clicking below:



Thanks,
Andrew,
Reply With Quote
  #20 (permalink)  
Old 10-22-2008, 06:45 AM
Aniken's Avatar
N00b
Offline
Pocket PC: HTC Touch PRO 2
Carrier: Sprint
Location: Blacklick, Ohio
 
Join Date: Aug 2007
Posts: 44
Reputation: 55
Aniken is becoming a great contributor
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via Yahoo to Aniken
Re: Ppc Viruses Are Coming!!!!

Quote:
Originally Posted by dannzeman View Post
Aniken, I wasn't saying you were wrong and I was right. I was merely make the point that we as a community, or at least I myself, haven't heard a lot about viruses taking over our ppc's. I never said it wasn't possible or that they don't exist. I was just trying to make the point that I don't think AV software is needed on our phones yet and if viruses ever did get out that we'd be informed about it.
Dannzeman, I apologize. After reading your second response and thinking about PPCgeeks.com as a community, I realize that I may have jumped to conclusions and everyone is entitled to his or her opinion on any given subject.
I have looked through the postings here with great admiration and always come here searching for answers....Normally, I would never post if I didn't think what I was saying was for the better good of the community.
Again please accept my apology and continue to support PPCgeeks.
Reply With Quote
Reply

  PPCGeeks > Site Information > Smartphone News > News Archives


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 07:15 AM.


Powered by vBulletin® ©2000 - 2025, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0
©2012 - PPCGeeks.com