BlackBerry Server Can Be Hacked With Image File

timothy posted about 3 years ago | from the image-of-the-emir-perhaps dept.

Blackberry 51

Trailrunner7 writes "There are remotely and easily exploitable vulnerabilities in the BlackBerry Enterprise Server that could allow an attacker to gain access to the server by simply sending a malicious image file to a user's BlackBerry device. The vulnerabilities are in several version of BES for Exchange, Lotus Domino and Novell GroupWise, and Research in Motion said that an attacker who is able to exploit one of the bugs might also be able to move from the compromised BES server to other parts of the network."

It's A Trade Off (5, Funny)

WrongSizeGlass (838941) | about 3 years ago | (#37081006)

Sure my client's BES could be hacked with an image file, but the image is of a really hot chick, so it's a fair trade.

Re:It's A Trade Off (1)

Anonymous Coward | about 3 years ago | (#37081092)

You made me click on the TFA with your comment!

I am sad. There is no hot chick in TFA... :(

Re:It's A Trade Off (2)

girlintraining (1395911) | about 3 years ago | (#37081560)

Sure my client's BES could be hacked with an image file, but the image is of a really hot chick, so it's a fair trade.

That's pretty sexist. Only about half the population would appreciate that.

Re:It's A Trade Off (0)

Anonymous Coward | about 3 years ago | (#37081600)

about half? aren't you forgetting about the lesbians and bisexuals? So the OP might be sexist, but you appear to be homophobic!

don't cast stones from glass houses.
la la lala la

Re:It's A Trade Off (1)

Anubis350 (772791) | about 3 years ago | (#37081750)

To be fair, *if* the GP were assuming that approx. 50% of the pop is male, 50% female, and that there are approximately similar numbers of gays and lesbians (no idea if that's in any way true or not), the comment would make perfect sense without being homophobic...

Re:It's A Trade Off (2)

jmac_the_man (1612215) | about 3 years ago | (#37081984)

To be even more fair, the question was about "is into chicks." If gays and lesbians occur with the same frequency in the population of men and women, respectively, they would cancel each other out. But if bisexuals ALSO occur with the same frequency regardless of gender, they don't cancel each other out, but instead that number counds twice.

Re:It's A Trade Off (2)

Anubis350 (772791) | about 3 years ago | (#37082142)

unless there's enough asexuals to cancel them out :-p

Re:It's A Trade Off (0)

Anonymous Coward | about 3 years ago | (#37082536)

And everyone is forgetting about the pedophiles. They need to be counted too!

Re:It's A Trade Off (1)

Scott Scott (1531645) | about 3 years ago | (#37083236)

Actually, anyone who's read girlintraining's user page would know she's anything but homophobic.

(Did someone say something about glass houses?)

Re:It's A Trade Off (0)

Anonymous Coward | about 3 years ago | (#37083068)

I'm a male and I don't think that's a fair trade for a compromised client's BlackBerry server...but if it were a DOS attack sending many images...

Re:It's A Trade Off (0)

Anonymous Coward | about 3 years ago | (#37090580)

Only about half the population would appreciate that.

A fair bit more than half the population because bisexual people get two votes. Sex is not a democracy.

Re:It's A Trade Off (1)

drinkypoo (153816) | about 3 years ago | (#37093276)

That's a lot of crap, there are tons of (straight) women who look at the pictures in Playboy because they can appreciate a pretty woman, but virtually no (straight) men who will even open a copy of Playgirl.


It's all about the image (4, Funny)

SilverHatHacker (1381259) | about 3 years ago | (#37081036)

1. Send goatse image to BB.
2. BB holder frozen in shock.
3. Walk up to frozen holder, appropriate keys/saved passwords/etc.
4. ???
5. Profit!

Re:It's all about the image (1)

Taty'sEyes (2373326) | about 3 years ago | (#37082580)

I'm a little disturbed by your opinion of SFW. What type of work do you do exactly?

Re:It's all about the image (1)

hairyfeet (841228) | about 3 years ago | (#37084494)

PC repair maybe? I know my old boss would never warn me before giving me the PC of "latino guy" or "buttgirl" to fix. Thanks a lot Doug, asshole. Latino guy would always end up with porn bugs for gay sites, usually some Latino oiled up nasty shit, and buttgirl? /Shivers at the horror/ Old buttgirl had a BF that had to weigh a good 350 and was hairy as a damned wookie and she would take all these thong pics of his big old hairy ass and make them her wallpapers, the icons for folders, her screensavers...fuck that was rough. the shit we PC guys get to see sometimes, like the gal that had dildos that i swear needed their own fricking gun rack...eek!

As for TFA...people still use Blackberry? I thought everyone had switched to iPhone and Android by now. If MSFT has any brains left at that outfit they'll make sure to have excellent AD and GPU support in their Nokia WinPhones and will drive the final nail in the coffin that is RIM. Frankly TFA doesn't surprise me as that company has just gone from one mistake after another lately and having a serious security hole just seems like the icing on the cake.

Once upon a time everywhere I went it was crackberries, but now all I ever see is iPhones and the HTC Androids. If a security hole appears but nobody is there to exploit it, does it still count?

Re:It's all about the image (0)

Anonymous Coward | about 3 years ago | (#37088230)

And in the Tottenham riots in London the rioters used Blackberry's Message service because the police could not monitor it but thankfully they looted iPhones rather than gym equipment or golf clubs so the police will be able to monitor next time they, um, get upset about being poor and disenfranchised. Or something else worth rioting over.

If it was iOS Server... (0)

Anonymous Coward | about 3 years ago | (#37081062)

... you would have to use an image of an effeminate, scarf wearing Mac user to hack it

Haven't you heard? (0)

Anonymous Coward | about 3 years ago | (#37081180)

Haven't you heard? Servers aren't trendy. Servers aren't hip. You can't take a server to your local Starbucks and doodle on it while you sip your latte macchiato. A server in a social setting like that would be un-cool.

But NIST certified it! (0)

Anonymous Coward | about 3 years ago | (#37081076)

So it must be secure. Really!

Re:But NIST certified it! (1)

belg4mit (152620) | about 3 years ago | (#37081170)

No, they certified the (stupidly named) PlayBook tablet.


Anonymous Coward | about 3 years ago | (#37081248)

...Snow crash.....

A Malicious Image File eh? (1)

Anubis350 (772791) | about 3 years ago | (#37081256)

I always knew we needed an emoticon for "pwned!"

Do they think I'm stupid? (4, Funny)

MacGyver2210 (1053110) | about 3 years ago | (#37081480)

So you want me to click a link to an article about hacking via image files...?

*opens lynx*

Re:Do they think I'm stupid? (0)

Anonymous Coward | about 3 years ago | (#37081774)

Unless your browsing the internet on your BES Server I think you'll be fine.

This article is illegal! (2)

xmorg (718633) | about 3 years ago | (#37081540)

This article violates teh DMCA and has been sent to the DHS for immediate action against the terrorists who wrote it.
All those involved will be hand molested by the TSA before being sent to Guantanamo bay.

Sad. (1)

m1ndcrash (2158084) | about 3 years ago | (#37081550)

BlackBerry's selling point is high-end security. Unfortunately, we learn again that anything can be broken and/or hacked. Moreover, the fact that exploit doesn't require any user action and launches arbitrary code is simply scary; since most of the mobile malware need to be downloaded and installed manually.

Sad is how negative this was written! (1)

Anonymous Coward | about 3 years ago | (#37081596)

RIM announced the problem, WITH the solution, it wasn't. Announced by a 3rd party, so RIM remains dedicated to security.

The problem is on servers, not on devices, maintaining device security. One would need intimate knowledge of the BES set up to actually extract information from the server.

Their communication between device and server has yet to be hacked

Re:Sad is how negative this was written! (1)

Alex Zepeda (10955) | about 3 years ago | (#37082778)

I think you forgot the quotes around "security". As long as they're decrypting stuff voluntarily for various governments, there's nothing secure about it.

Re:Sad is how negative this was written! (0)

Anonymous Coward | about 3 years ago | (#37083346)

They can't decrypt BES data (which is what this article is about), as the BES keys are generated by the BES server administrator which are not known to RIM.

How about you get your facts straight before you start spreading FUD?

The servers control the devices. (1)

apparently (756613) | about 3 years ago | (#37083528)

While this may be true:

Their communication between device and server has yet to be hacked

This isn't:

One would need intimate knowledge of the BES set up to actually extract information from the server.

Their communication between device and server has yet to be hacked

From the KB warning:

"Vulnerabilities exist in how the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process PNG and TIFF images for rendering on the BlackBerry smartphone. Successful exploitation of any of these vulnerabilities might allow an attacker to gain access to and execute code on the BlackBerry Enterprise Server. Depending on the privileges available to the configured BlackBerry Enterprise Server service account."

Access to the besadmin account gives an attacker all sorts of access to the server. That account has sendas permissions on all users mailboxes, can make configuration changes to the BES configuration, including changing device settings, and pushing applications to the devices.

It really wouldn't be all that hard to completely compromise an organization's Blackberry configuration -- server and device -- and there's a good chance that you'd be able to escalate privileges onto other servers within the network.

Re:The servers control the devices. (1)

kevinmenzel (1403457) | about 3 years ago | (#37084312)

But what is true is that the Slashdot editors or the submitter has decided that instead of even mentioning the patch, they would just focus on the exploit.

Strange of course, as the source material for this post is titled "Severe Remote Flaw Fixed in BlackBerry Enterprise Server", and the source for THAT article does indeed include the patch itself.

Re:The servers control the devices. (1)

lennier (44736) | about 3 years ago | (#37102570)

But what is true is that the Slashdot editors or the submitter has decided that instead of even mentioning the patch, they would just focus on the exploit.

But of course the patch has automagically applied itself to every BES server in the world, instantly, leaving no window of vulnerability while sysadmins scramble to apply it.

I mean, that's what patches do, right?

TNG (1)

Kebis (1396783) | about 3 years ago | (#37082672)

Isn't this exploit pretty much what Captain Picard wanted to do to the Borg in the episode with Hue?

Another reason (0)

Anonymous Coward | about 3 years ago | (#37083598)

not to use a Riotberry

This hasn't been a problem for a while (1)

narcc (412956) | about 3 years ago | (#37089570)

RIM shipped a patch for these vulnerabilities almost a week ago. The headline should read "Blackberry Server Can't Be Hacked With Image File"

That's right, this was discovered and fixed long before it could become a problem. That's what I expect from RIM's best-in-class security.

Re:This hasn't been a problem for a while (0)

Anonymous Coward | about 3 years ago | (#37101410)

Super duper double ungood! You are interpreting the facts wrong! SJ, Infinite Loop, RDF.

Fix (0)

Anonymous Coward | about 3 years ago | (#37106928)

Hi @Trailrunner7,

Alex from RIM here. I just wanted to jump in here to let you know that a fix was issued to this and you can find it here:

Alex, RIM Social Media Team

"ecode" can be used for code snippets, for example:

<ecode>    while(1) { do_something(); } </ecode>