Notices

X50 / X51 Forums Talk about anything related to the X50 / X51 series.

Reply
 
LinkBack Thread Tools
Old 02-02-09, 08:32 AM   #1 (permalink)
Aximsite Veteran
 
Join Date: Mar 2005
Location: Toronto
Posts: 1,093
Device: A1200,Moto-Q
Carrier: Rogers
Thanked 0 Times in 0 Posts
Exclamation Microsoft Bluetooth Stack OBEX Directory Traversal Vulnerability

Just saw this vulnerability on all WM6 devices that use the Microsoft BT stack.
Quote:
A directory traversing vulnerability in the Bluetooth OBEX-FTP server of Windows Mobile 6 allows attackers to access files outside of the permitted list. According to the report, using "../" or "..\\" as part of the path name, is sufficient to traverse to other directories. An attacker could use the technique to copy files from a device, or to install their own software, such as a key logger, or other spyware.

The issue does require that the targeted hand held device is paired with the attacking device, which is usually only possible with the owner's consent. There are, though, situations where a user may wish to restrict access to their files for paired devices, and the problem means that these restrictions are only partially effective. Alberto Moreno Tablado, who discovered the bug, has published a detailed guide to the problem.
More detailed info here: Seguridad Mobile - Alberto Moreno
bigbop is offline   Reply With Quote
Sponsor Ads
Reply

Tags
bluetooth, directory, microsoft, obex, stack, traversal, vulnerability

Sponsor Ads

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:35 AM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2003-09 LeckMedia, LLC