HTC smartphones left vulnerable to Bluetooth attack

From InfoWorld: If you have an HTC smartphone running Windows Mobile 6 or Windows Mobile 6.1, you may want to think twice before connecting to an untrusted device using Bluetooth. A vulnerability in an HTC driver installed on these phones can allow an attacker to access any file on the phone or upload malicious code using Bluetooth, a Spanish security researcher warned Tuesday.

"HTC devices running Windows Mobile 6 and Windows Mobile 6.1 are prone to a directory traversal vulnerability in the Bluetooth OBEX FTP Service," security researcher Alberto Moreno Tablado said in an e-mail exchange.

For the attack to work, the targeted device must have Bluetooth enabled and file sharing over Bluetooth activated.

"This connection can be done either by standard Bluetooth pairing or taking advantage of the Bluetooth MAC spoofing attack," Moreno Tablado said, referring to a process where the attacking device attempts to convince the target that it's another device on its list of paired devices.

Users worried about the vulnerability should avoid pairing their phones with an untrusted handset or computer. They may also want to delete any devices that are already paired with their phones, he said.

View: Article @ Source Site