Free Newsletters

   All InfoWorld Newsletters
Security Adviser | Roger A. Grimes » Palm not fixing Treo security bypass vulnerability

February 14, 2007 | Comments: (0)

Palm not fixing Treo security bypass vulnerability

Yet another vendor cares so little about their customer base that they have decided not to fix a critical system bug.

Thanks to Symantec for finding the bug and reporting it. As a Treo user, I'm far from thrilled. I plan to get rid of my Treo. Way to go Palm.

Here's the full story as reported on Security Focus:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Symantec Vulnerability Research
http://www.symantec.com/research
Security Advisory

Advisory ID: SYMSA-2007-002
Advisory Title: Palm OS Treo Find Feature System Password Bypass
Authors: J.R. Wikes, Matt Cooley, & Scott King
Release Date: 14-02-2007
Application: N/A
Platforms: Palm OS Treo smart phones - Tested on Verizon,
Sprint, & Cingular Treo 650 (Treo650-1.03a-VZW &
Treo650-1.12-SPCS), Cingular Treo 680, and
Sprint/Verizon Treo 700p phones
Severity: Locally exploitable
Vendor status: Verified by vendor. No patch forthcoming.
CVE Number: CVE-2007-0859
Reference: http://www.securityfocus.com/bid/22468


Overview:

Palm OS Treo smartphones are equipped with a system password lock to secure contents of handheld data from unauthorized access.
When this lock is engaged, Treo's built-in Find feature is still accessible and can be used to perform searches on text in Treo applications and databases (e.g. SMS Messages, Memos, Calendar, Tasks, etc). Search results are accessible, and depending on their size, may be truncated. An attacker may use this vulnerability to retrieve information from a locked device.

The built-in Find feature can also be used to access an Edit window and paste previously cut or copied data into the search field of a locked device. An attacker may use this vulnerability to view data that was cut or copied from Treo applications prior to the device being locked.


Details:

The Find feature can be accessed when the handheld is locked by issuing keyboard shortcut keys on the Emergency Call screen and the Call In Progress screen that is displayed when an incoming call is accepted. More details for each of these methods is listed below.

1. Emergency Call Screen

- From the System Lockout screen, select 'Make Emergency Call'.
Press the keyboard shortcut keys for Find (Option Key + Find Key).
This will open the Find window on the bottom half of the screen.
Enter the desired text to search and click on 'OK'. (Searching on a single space usually returns data)

To access the Edit window, press the Menu key while the Find window is open. Select Paste from the Edit window to paste previously cut or copied data in the Find window.

2. Call In Progress screen

Accept an incoming call.
Press the keyboard shortcut keys for Find (Option Key + Find Key) during the call. This will open the Find window on the bottom half of the screen. Enter the desired text to search and click on 'OK'. (Searching on a single space usually returns data)

To access the Edit window, press the Menu key while the Find window is open. Select Paste from the Edit window to paste previously cut or copied data in the Find window.

Note: The Find window will stay open after a call has been disconnected. However, users will be returned to the Lockout screen when the find results are closed.


Vendor Response:

14-08-2006: Initial Vendor Notification.
06-09-2006: Vendor acknowledges receipt of vulnerability description.
06-09-2006: Vendor confirms vulnerability.
19-01-2007: Vendor decides not to fix vulnerability.
14-02-2007: Advisory released.


Recommendation:

In the interim of a patch being released to address this vulnerability, users should be notified of this condition so that they may take appropriate actions including encrypting sensitive handheld databases.


Common Vulnerabilities and Exposures (CVE) Information:

The Common Vulnerabilities and Exposures (CVE) project has assigned the following names to these issues. These are candidates for inclusion in the CVE list (http://cve.mitre.org), which standardizes names for security problems.

CVE-2007-0859

- -------Symantec Vulnerability Research Advisory Information-------

For questions about this advisory, or to report an error:
research@symantec.com

For details on Symantec's Vulnerability Reporting Policy:
http://www.symantec.com/research/Symantec-Responsible-Disclosure.pdf

Symantec Vulnerability Research Advisory Archive:
http://www.symantec.com/enterprise/research/archive.jsp

Symantec Vulnerability Research GPG Key:
http://www.symantec.com/research/Symantec_Vulnerability_Research_GPG.asc

- -------------Symantec Product Advisory Information-------------

To Report a Security Vulnerability in a Symantec Product:
secure@symantec.com

For general information on Symantec's Product Vulnerability reporting and response:
http://www.symantec.com/security/

Symantec Product Advisory Archive:
http://www.symantec.com/avcenter/security/SymantecAdvisories.html

Symantec Product Advisory PGP Key:
http://www.symantec.com/security/Symantec-Vulnerability-Management-Key.asc

- ---------------------------------------------------------------

Copyright (c) 2007 by Symantec Corp.
Permission to redistribute this alert electronically is granted as long as it is not edited in any way unless authorized by Symantec Vulnerability Research. Reprinting the whole or part of this alert in any medium other than electronically requires permission from research@symantec.com.

Disclaimer
The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information.
Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.

Symantec, Symantec products, and Symantec Consulting Services are registered trademarks of Symantec Corp. and/or affiliated companies in the United States and other countries. All other registered and unregistered trademarks represented in this document are the sole property of their respective companies/owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (Cygwin)

iD8DBQFF0fdBuk7IIFI45IARAo2OAKCOjb/3hM3y1LqakzIRSjUZrINRQwCffwf/
LiKdpxGBKZXOqMpIzxrYw9M=
=2CJL
-----END PGP SIGNATURE-----

Posted by Roger Grimes on February 14, 2007 09:02 AM


RATE THIS ARTICLE:





 

  •  
  • COMMENTS




This is true but Palm has excellent third party support. One can easily buy Warden Security (http://LockMyTreo.com) and get much more than data security. (Warden is also available for Windows Mobile).

Posted by: Charles Tipton at February 14, 2007 03:53 PM

Just don't let someone else mess with your treo or lose it. Like a notebook computer, if you lose it and did not encrypt your data, tough luck.

Posted by: RU at February 15, 2007 02:24 PM

Palm should offer a patch however the risk is so low that this vulnerability is not much of a threat. If it concerns you, as Charles noted there are several power on password vendors to choose from. Many in fact encrypt the entire Palm database such as Credant to make this a threat a yawn...next! event.

-my PalmOS Treo can only be taken from my cold dead hands...and not before! -

Posted by: Eric at February 15, 2007 07:06 PM

Just one more flaw in the Treo...


Treo is too large to be a good phone, but the screen is too small to be a good PDA (I continue to use a Palm T3 as my "real" PDA)

It cannot be used phone without headset - voice is terrible in both directions otherwise

The reception is definitely a problem - I have had both a Verizon version and a Sprint version and cannot get a signal in places where others have no trouble

Treos lock up more than frequently (average 3-5x per day) requiring complete reboot - slows to a crawl more often than that

auto turnoff/keyboard lock only works when it feels like it

phone will not ring even when it has a strong signal (voicemail magically appears when the phone never rang)

The built in MS apps are not as capable as Desktop to Go

Using Bluetooth with a headset sucks the battery dry in about 4 hours

The keys are too small to use

My company MIS group chose the Treo - the only reason I haven't chucked it off a bridge is that I need a device to get email from Exchange(text only - the Treo doesn't handle attachments well) automagically while on the road - what I need to do when I have time is figure out what my options are to replace the Treo

Posted by: Keith Swindell at February 15, 2007 07:44 PM

All this hype over Treo's bug using 'Find' feature is unnecessary. This is completely false that hacker can get access to data. I tested it myself on my treo 650 and found out that I can only see the results after executing Find function. As soon as I click on any one of the find results, treo takes me back to the phone screen and does not let me enter into any of the contacts, memos, calendar or anything.

The agencies reporting the bug are not giving complete information. They told that hacker can access the Find functiona and see the results. But they did not tell that hacker CANNOT access any treo entry by clicking on the find results.
-----------------
My reply:

Thanks for writing.

First, although the Edit part of the attack does not work on my 650 either, it does on 600's and 700's, and probably more, but it's all I've tested. There are 15 models in all.

Second, I have been able to recover other people's passwords using the Find feature, without needing the Editing feature.

Third, any confidential information being revealed (such as my personal home phone number, my kid's phone numbers, and other personal numbers I wouldn't want thieves having) is a bug.

In short, when a company offers password protection, it should protect all data, not just some of it or most of it, but all of it.

Lastly, if all this story was about was a Treo bug, I wouldn't have blogged it. But it's yet another example of a major company refusing to fix a security problem. I'll never buy another Treo again. I will speak with my dollar votes.

Roger

Posted by: AG at February 16, 2007 08:56 AM

The find window can not appear over modal windows (windows were the titlebar goes across whole whole screen) to fix that is just a checkbox on the Palm SDK! so palm has NO excuse for not fixing this.

Posted by: Linux at February 20, 2007 04:15 PM

Theres a discussion and free patch named SecurityLockFindFix at this link:


http://discussion.treocentral.com/showthread.php?t=136942&page=2

Works like a charm.

Posted by: TV at April 20, 2007 02:03 AM

Technology White Papers

 

InfoWorld Technology Marketplace

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
» BUY A LINK NOW

Sponsored Technology Links