Friday, October 22, 2004

Adam Gowdiak's Research on J2ME Vulnerabliites

I never really looked at the Hack in the Box conferences;this year it was in Kuala Lumpur. The Register has an article mentioning Adam Gowdiak's presentation at the latest conference.
The PDF of his presentation comes in at about 53 MB(91 pages).

There was a also presentation on .net self compiling viruses .

I haven't gone through the whole thing yet, but here are some interesting quotes from the J2ME presentation:

on future threats -
  • The fact that there are more users of mobile devices than
  • PC’s makes it very attractive target for attackers and worm writers
  • It should be expected that remote vulnerabilities for
  • mobile devices will be published within next 6 months
  • Vendors and antivirus industry are not prepared for this kind
  • of threats (there are no means to protect users of the so called „closed” mobile devices against malicious code)
  • Open platforms (PalmOS, Symbian OS, Windows CE)
  • seem to be easier to protect, but they are also at the most risk.

on the rest of his research -
  • Research paper with all the details including some
    additional material that didn’t fit into this 90min talk will be
    published in a couple of months


J2Me might be the "in" malware needed that bluetooth wasn't . I'm not sure how worried I'd be that "closed" mobile devices are at risk, as they usually lack in memory and additional networking capabilities compared to "open" systems. Still, anywhere from 3-6 months to find out. :)

* Hack in the Box is putting out videos of the conference via BitTorrent within the next 4 weeks.



No comments:

Auto "Kill Switch", solving the wrong problem?

Consumer Watchdog, a consumer advocacy group, put out a report on the dangers of Internet connected cars. They received coverage on the nigh...