Find your next home with Luxist's "Estate of the Day"

Expert: BES 4.1 policies can control purported BBproxy hack

In light of news that a BBProxy code exists that could enable hackers to exploit a BlackBerry handheld-server link to bypass enterprise gateway security, BlackBerry-maker Research In Motion's security staffers seem to be saying, "what's the big deal?"

First, a description of the exploit.

Security vendor Secure Computing on Tuesday warned corporate users that their BlackBerry Enterprise Server deployments on internal networks could be vulnerable to a BBProxy attack. After manually installing BBProxy or getting a user to install it via an e-mail attachment, a hacker could, according to Secure, exploit the encrypted connection between the handheld and the BES and thus obtain access to the internal network, according to San Jose, Calif.-based Secure.

With the right precautions, though, this doom-and-gloom scenario won't happen.

At least that's what RIM says.

"Our attachment service doesn't work that way. You can send and view e-mail, but the BES system is designed to require users to manually download the application from a Web site," said Scott Totzke,director of Research In Motion's global security group.

David Bean, who is president of RIM partner eAccess Solutions,told CRN writer Kevin McLaughlin that the IT policy tools in BlackBerry Enterprise Server 4.1 can control these vulnerabilities. Bean said that BES 4.1 includes policies that can repel an attack by a self-installing or virus-infected file, but it is up to the server administrator to set up and implement such policies.

Reader Comments

(Page 1)
General
Blackberry Multimedia (102)
Patents (38)
Rumors (116)
BlackBerry Internet Service (11)
Ask BBHUB (8)
BlackBerry OS 4.x (103)
BlackBerry Enterprise Server (327)
Competitors (280)
Fun (720)
Gear (191)
Health (94)
RIM (1198)
Promotions (172)
Security (201)
Software (1150)
Support (390)
Stories (768)
Tips (470)
Developers (13)
Providers
Bell Canada (5)
Cingular-AT&T (313)
International (213)
Miscellaneous (30)
Nextel (95)
Rogers Communications (58)
Sprint (60)
SprintNextel (61)
T-Mobile (211)
Verizon (98)
Vodafone (43)
Models
8703 (23)
8705 (3)
8707 (3)
8800 (28)
Pearl 8100 (314)
7100i (25)
7130e (71)
8700 (264)
7100 (55)
7100t (94)
7100g (95)
7100r (41)
7100x (29)
7100v (49)
7700 (10)
7730 (26)
7750 (27)
7780 (17)
7500 (11)
7510 (22)
7520 (86)
7200 (15)
7230 (42)
7250 (71)
7270 (22)
7280 (27)
7290 (119)
6700 (5)
6710 (7)
6720 (6)
6750 (9)
6200 (6)
6220 (6)
6230 (7)
6280 (6)
5800 (5)
5820 (5)
RIM Partners
3COM (3)
Nortel (4)
Siemens (4)
Sony Ericsson (9)
Features
Interviews (5)
Hardware Hacks (4)

RESOURCES

RSS NEWSFEEDS

Powered by Blogsmith

Other Weblogs Inc. Network blogs you might be interested in: