PPCGeeks Forums HTC Arrive HTC HD2 HTC Thunderbolt HTC Touch Pro 2 HTC Evo 4G HTC Evo 3D Samsung Galaxy S II Motorola Droid X Apple iPhone Blackberry
Go Back   PPCGeeks > Windows Mobile > Windows Mobile Software
Register Community Search

Notices


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 07-20-2009, 08:20 PM
gutrrob's Avatar
Regular 'Geeker
Offline
Pocket PC: Evo 3D
Carrier: Sprint
Location: Los Angeles, CA
 
Join Date: Mar 2008
Posts: 368
Reputation: 505
gutrrob knows their stuffgutrrob knows their stuffgutrrob knows their stuffgutrrob knows their stuffgutrrob knows their stuffgutrrob knows their stuff
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
HTC offers fix for Bluetooth security flaw!!!

HTC offers fix for Bluetooth security flaw

HTC is offering a fix for a Bluetooth security vulnerability for several of its handsets. The fix was issued for the HTC Touch models. Although HTC did not specify exactly what problem it was fixing, the fix coincides with security researcher Alberto Moreno Tablado's discovery which he made public when HTC did not issue a fix after he alerted the company in February.

"Microsoft states this is a 3rd party driver developed by HTC and installed on HTC devices running Windows Mobile, so the vulnerability only affects to this vendor specifically," Tablado wrote. "A remote attacker (who previously owned authentication and authorization rights) can use tools like ObexFTP or gnomevfs-ls from a linux box to traverse to parent directories out of the default Bluetooth shared folder by using ../ or .. marks."

Authentication or Authorization rights could be gotten by pairing the HTC handset with a Bluetooth device, or more complication solutions would include spoofing the MAC address or include sniffing the Bluetooth pairing. Once obtained, an attacker can navigate can access or modify any file stored on the device without the user being aware of the attack.

The fix comes in the hotfix BLA_S00279.exe file which you can download to your device and run. Once it is completed it will soft-reset your device. You can get it from:
http://www.htc.com/europe/SupportDownload.aspx?p_id=133&cat=0&dl_id=609
Reply With Quote
This post has been thanked 2 times.
 

  PPCGeeks > Windows Mobile > Windows Mobile Software


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 04:48 PM.


Powered by vBulletin® ©2000 - 2025, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0
©2012 - PPCGeeks.com