Gadgetell | Tech News, Reviews, and Interesting Things

Subscribe to our content for free: (?)
Get our Daily Email

RIM issues patch for browser bug

by Sue Walsh on Oct 1, 2009 at 05:32 PM

RIM has issued a patch for a bug in its browser that could allow BlackBerry users to be hit by a phishing attack.  The bug involves the security feature that notifies a user if the website they are trying to visit has a certificate mismatch. The browser correctly identifies such sites but does not display the mismatch properly if it contains null, or hidden, characters.  This means a user could easily think the notification was in error and continue to load the page.

A hacker could take advantage of this bug by creating a fake site and purposely altering its certificate.  They could then send an SMS text message to a user with the malicious link included.  The user would click on it and be tricked into thinking it’s a legit and trusted site.  For example, say a hacker decided to create a phishing site for a major bank such as HSBC and purposely alter the certificate.  They would then send out an SMS made to look like an alert from the bank with the malicious link included.  Thinking it’s a real alert the BB user clicks on the link (since it was sent via an SMS text the mouse hover trick would not work).  When the BB user gets the warning the bug makes the warning look bogus so the user continues on and logs into the fake site.

This bug affects all devices and OS versions and it is highly recommended that BB users download the fix and apply it ASAP.  In the meantime avoid clicking on links sent via SMS.

Read [ZDnet]

Keep up with the latest gadget goodness! - Subscribe to our feed


Join the Discussion

Name: *

Email: *

Location (Links to Google Maps):

URL:

Enter Your Comment Below...

* Required fields

Remember my information?

Notify me of follow-up comments?

Submit the word you see below:


Special Features