• »Sign In
  • »Sign Up
  • Check Out
  • »FAQs

    LED Lights & Accessories Wholesaler

    E-mail:
    Password:
    • SHOPPING
    • NEWS
    • KNOWLEDGE
    • FROUM
    0 Items(s)(US$0.000)
    • All Topics
    • >>
    • Mobile Phones
    • Submit a New Story
    • 17
    • dig it

    HTC Issues Hotfix for Bluetooth Vulnerability in Smartphones

    HTC released a software update on Thursday that fixes a Bluetooth vulnerability disclosed earlier this week by a Spanish security researcher.

    The vulnerability, found in an HTC Bluetooth driver, obexfile.dll, could allow an attacker to gain access to all files on a phone by connecting to it via Bluetooth, according to Alberto Moreno Tablado, the researcher who discovered the bug in the OBEX FTP service and first reported it earlier this year.

    The OBEX FTP directory traversal attack requires that a victim's phone has Bluetooth switched on and Bluetooth file sharing is activated. The vulnerability allows an attacker to move from the phone's Bluetooth shared folder into other folders. This gives the attacker access to contact details, e-mails, pictures or other data stored on the phone. They can also upload software to the phone, including malicious code.

    The vulnerability affects nearly all HTC handsets running Windows Mobile 6 or Windows Mobile 6.1. HTC handsets running Windows Mobile 5 are not affected. Because the flaw is found in an HTC driver, handsets from other companies are not affected by the problem.

    Moreno Tablado notified HTC of the flaw in February but the company didn't fix it, and he ultimately decided to disclose details of the vulnerability on his blog to give users a chance to protect themselves. The following day, HTC made available a hotfix for its Touch Pro, Touch Diamond, and Touch HD handsets that increases Bluetooth security.

    The hotfix fixes the vulnerability that causes allows the directory traversal attack, Moreno Tablado said.

    While the Touch HD is listed among the HTC handsets that the hotfix was designed for, Moreno Tablado said the handset doesn't include the OBEX FTP service. Another HTC handset that is not affected is the Touch Pro 2, which uses Broadcom's Widcomm Bluetooth stack and does not use the HTC driver that causes the security hole, a Broadcom software engineer said.

    It was not immediately clear if the Touch Diamond 2 and Snap handsets, which are among the latest HTC models, are affected by the vulnerability, Moreno Tablado said.

    Other HTC handsets running Windows Mobile 6 and Windows Mobile 6.1 may still be affected. At the time of writing, a search of HTC's Web site showed the company had not yet posted hotfixes for other models that use the affected driver. HTC could not immediately be reached for comment.

    In tests, Moreno Tablado confirmed the Bluetooth vulnerability affects eight HTC handset models: the P3600i, Touch Find, S710, P3650, Touch Diamond, Touch Pro, Touch Cruise, and the S740.

    Users worried about the vulnerability should turn off Bluetooth or avoid pairing their phones with an untrusted handset or computer. Users may also want to delete any devices that are already paired with their phone.

    <style type="text/css">#resourceLinks li { display: none;}</style>
    • Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
    • Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
    • Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
    • Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
    • Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
    <script type="text/javascript">randomlyShowOneItem(document.getElementById('resourceLinks'));</script>

    Submitted:
    933 days ago
    Submitter:
    abracadabram
    Topic:
    Mobile Phones
    Source:
    www.pcworld.com
    • Latest Taiwanese Smartphone Highlights Industry Trend
    • O2 Xda Venn is nifty dual slider
    • RIM Settles Visto Suit for $267 Million
    • Dell Eyes Smartphone Market by Asking Carriers What They Want
    • Sony Ericsson Unveils Facebook-Friendly Walkman Phone
    • Samsung due to release new mid-range mobile phone
     
    Bluetooth Stereo Headset
    Sample Price:US$26.600
     
    Bluetooth Headset Black 01
    Sample Price:US$13.685
    Comments (0)
    • Add Your Comment
    • Please login or register to submit your comment.
      • What are the benefits of having a Dig account?
      • Share your opinion by posting comments on the stories that interest you
      • Dig the stories that you like and help determine what should be popular on Digg
      • Create a network of friends, so you can help each other find interesting stories
      • Start building a history of content that you've Dugg, for easy reference later
     
    Bluetooth Headset Grey 01
    Sample Price:US$13.685
     
    Bluetooth Headset Pink 01
    Sample Price:US$13.685
    CUSTOMER SERVICE SHOPPING HELP MY ACCOUNT COMPANY INFO TOOLS & RESOURCES
    • Contact Us
    • RMA Request
    • Looking for a item
    • Send Us a Message
    • Shopping Process
    • Return Policy
    • FAQs
    • Knowledge Base
    • Login/Register
    • My Account
    • Order History
    • My Wish list
    • About Us
    • The VIP Club
    • Customer Comments
    • Bank Account Info
    • Site Map
    • Downloads
    • Search
    • Links

    visamastercarddiscoverecheckamexpaypalPayPal VerifiedUCC

    VIP Club | Policies | Privacy Notice | Support|Copyright © 2006 LED Lights & Accessories Wholesaler Inc. All rights reserved.