• On MovieTome: Leaked images from TRANSFORMERS 2?

September 21, 2007 6:56 AM PDT

Symantec warns users over Bluetooth security

  • Print
With Bluetooth wireless features fast becoming commonplace on mobile devices, users need to be aware of the security vulnerabilities linked to the technology, said a Symantec executive.

A study by research firm InsightExpress revealed that 73 percent of mobile device users are not acquainted with security issues that could put at risk mobile devices such as cell phones and Bluetooth-equipped notebooks. To these users, terms such as "bluejacking," "bluesnarfing" or even "bluebugging" would probably be unfamiliar.

"There are many other methods that (launch) a variety of denial-of-service attacks, and even some that could allow an attack to eavesdrop on private conversations," Ooi Szu-Khiam, senior security consultant at Symantec Singapore, said in an e-mail interview. Ooi noted that "numerous instances of mobile viruses, worms and Trojan horses" have emerged in the past year.

"While none has done damage like some of the major PC malware, their rapid evolution presents an obvious cause for concern," Ooi said.

Bluejacking, also known as "bluespamming," is a technique used to send anonymous text messages to mobile users via Bluetooth, Ooi explained. "Phones that are Bluetooth-enabled can be tweaked to search for other handsets that will accept messages sent via Bluetooth."

"Despite the name, it doesn't hijack the phone or suck off the information. It simply presents a message, similar to e-mail spam. The recipient can ignore the unsolicited message, read it, respond or delete it," Ooi said. "While bluejacking can be an extremely annoying onslaught of unsolicited messages, it is generally a minimal security risk."

Bluesnarfing, however, is a more dangerous technique that can allow a hacker to access information stored on a mobile device without its user's knowledge, said Ooi.

"This technique takes advantage of a security flaw, (inherent) in some older versions of Bluetooth-enabled handsets, that could allow an attacker to access and copy data stored on the device without the user's knowledge," Ooi said. The Symantec executive noted that it is still possible to connect to such devices even if the users have configured their devices to be in "nondiscovery" mode, where the device remains hidden when someone searches the vicinity for Bluetooth devices.

"Any potentially valuable information stored on a phone, such as address books, calendars, e-mail and text messages, are at risk in a bluesnarfing attack," Ooi said.

A third threat, and possibly the most serious of the three risks, is bluebugging. This technique allows attackers to access mobile-phone commands using Bluetooth technology, without notifying or alerting the device owner, Ooi noted.

"This vulnerability allows the hacker to initiate phone calls, send and receive text messages, read and write phonebook contacts, eavesdrop on phone conversations and connect to the Internet," Ooi explained. "As with all the attacks, the hacker must be within a 10-meter range of the (targeted) phone."

Unlike bluesnarfing, which simply provides attackers access to personal information on the phone, bluebugging allows the attacker to take control of the device, he said.

To ensure their wireless devices are well-protected, Ooi noted, users can equip their gadgets with mobile-security products, which include antivirus, firewall, anti-SMS spam and data-encryption technologies, that are easy to deploy, manage and maintain.

"This kind of layered security can not only mitigate the unique security risks of mobile devices, but can also enable companies to more easily and cost-effectively comply with internal security policies and external regulations," Ooi said.

Ooi highlighted four tips on how mobile users can protect their Bluetooth-enabled devices:

Stay offline
Turn off features that you are not using. If you have a Bluetooth-equipped device and do not need the function, then don't turn it on.

Stay invisible
If you are using the Bluetooth function and don't require your device ID to be visible to others, make sure the device's visibility setting is set to "hidden," so hackers will not be able to scan and search for it.

Verify incoming transmissions
Do not accept and run attachments from unknown sources unless you are expecting them. For example, if you receive a message to install an application and you don't know its origin, don't run it.

Use passwords
Ideally, use passwords with a large number of digits. A four-digit PIN or password can be broken in less than a second, and a six-digit PIN in about 10 seconds, while a 10-digit PIN is likely to take weeks to crack.

Lynn Tan of ZDNet Asia reported from Singapore.

See more CNET content tagged:
Symantec Corp., Bluetooth, mobile device, attacker, text message

Add a Comment (Log in or register) 1 comment
haseeb
by wamiqhaseeb February 26, 2008 6:16 AM PST
kia bat ha
Reply to this comment
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

Markets

Market news, charts, SEC filings, and more

Related quotes

Symantec (4.51%) 0.50 11.59
Dow Jones Industrials (3.31%) 270.00 8,419.09
S&P 500 (3.99%) 32.60 848.81
NASDAQ (3.70%) 51.73 1,449.80
CNET TECH (3.64%) 36.93 1,051.13
  Symbol Lookup
advertisement

Inside CNET News

Scroll Left Scroll Right
  • Business Tech

    IPOs a thing of the past?

    At AlwaysOn Venture Summit West conference, investment bankers, venture capitalists, and private equity players weigh in on the prognosis for the IPO market.

  • Gallery

    Photos: Space station marks a decade aloft

    The first pieces of the International Space Station went into orbit 10 years ago. Now a full-fledged lab facility, it continues to grow.

  • Security

    Apple deletes Mac antivirus suggestion

    Apple removes statement to customers urging them to use antivirus software, saying that Macs are safe "out of the box."

  • Beyond Binary

    Microsoft-HP cashback saga continues

    Earlier this week a Microsoft representative indicated that a deal offering 40 percent cash back at HP.com would be restarted following Black Friday glitches. Now that appears less certain.

  • Video

    A toast to online wine A toast to online wine
  • Digital Media

    Conde Nast to shutter teen site Flip.com

    The teenage girl social-networking site plans to shut down on December 16, according to an e-mail sent to users.

  • Video

    Wi-Fi while you fly Wi-Fi while you fly
  • Gaming and Culture

    From Cy Young to video game fame

    Tim Lincecum, one of the best pitchers in baseball, was chosen to be the cover athlete for 2K Sports' next baseball game. On Tuesday, he did a motion-capture session for the game.

  • Green Tech

    Ta ta, Tesla

    Are the Valley-based VCs and big-wigs who back Tesla Motors really serious about asking the federal government for low-interest loans?

  • Gallery

    Photos: Top-rated reviews of the week

    Here are a few of CNET Reviews' favorite items from the past week, including Adobe suites, laptop bags, and a Panasonic flat panel TV.

  • Crave

    HTC focuses on phone design; acquires One & Company Design, Inc.

    Looking to concentrate on design, smartphone manufacturer HTC acquires San Francisco-based design firm, One & Company Design, to help create its future devices.

  • Green Tech

    Ford accelerates electric-vehicle plans

    In its turnaround plan presented to Congress, Ford says it will invest billions in fuel efficiency and introduce a family of hybrid-electric and all-electric cars.