{"id":125,"date":"2008-08-20T13:57:19","date_gmt":"2008-08-20T08:57:19","guid":{"rendered":"http:\/\/www.logichub.net\/blog\/?p=125"},"modified":"2015-02-05T22:50:48","modified_gmt":"2015-02-05T16:50:48","slug":"hacker-claims-java-bug-affects-millions-of-phones","status":"publish","type":"post","link":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/","title":{"rendered":"Hacker Claims Java Bug Affects Millions of Phones"},"content":{"rendered":"<p align=\"justify\">A Polish hacker and self professed security expert claims to have discovered vulnerabilities in the mobile Java technology implemented by Nokia in its mid-range S40 devices, potentially putting millions of handsets at risk.<\/p>\n<p>Adam Gowdiak, who is in the process of setting up a security research firm, Security Explorations, claims the bugs affect around 140 different models of Nokia phone. But given the proliferation of the latest version of Sun&#8217;s Java ME, the number of vulnerable devices could run to 1.5 billion including other makes of handset.<\/p>\n<p>He also claims the mobile Java vulnerabilities allow hackers to completely bypass security restrictions and install malicious applications on a victim&#8217;s device, without their knowledge.<\/p>\n<p>[ad name=&#8221;post-banner-01&#8243;]<\/p>\n<p align=\"justify\"><!--more--><\/p>\n<p align=\"justify\">However, Gowdiak has drawn fire over his method of raising awareness over the bugs. He has not made the information publicly available, at least not for free. Instead he is offering a 178 page technical report, including proof of concept code, for the sum of Eur20,000.<\/p>\n<p>Gowdiak says he is reluctant to give months of research away for free, and intends to raise something in the region of Eur1m in order to set up Security Explorations.<\/p>\n<p>It&#8217;s not clear whether Nokia has bought the research, but Gowdiak believes the end users should be aware of a potential vulnerability as soon as the vendors&#8217; are, even if the finer details are not made public.<\/p>\n<p>The hacker claims to be able to achieve a list of feats on vulnerable devices without the owner&#8217;s knowledge or consent, including SMS, MMS, WAP and PUSH message sending; establishing arbitrary phone calls and internet connections; full read and write access to the files stored on a device; audio and video stream recording; full access to the contacts database; access to the SIM card; and backdoor application installation on the phone with network operator or manufacturers privileges.<\/p>\n<p>Gowdiak hints that the hack is achieved by sending a specially crafted sequence of messages to a given Nokia phone and likens the attack to one on a PC. All malicious applications can be executed in the background, which means they are invisible on the phone screen and to the user, Gowdiak said.<\/p>\n<p>The problem here, as one of our analysts at Informa points out, is that S40 is not a multitasking OS, which presumably means apps cannot be executed in the background.<\/p>\n<p>&#8220;As far as I know S40 does not do multitasking, which means nothing else can be executed if the user uses the phone. When the phone is not used, anything executed will surely be transparent and exposed to the UI,&#8221; said Informa principal analyst Malik Saadi.<\/p>\n<p>The hacker also revealed he had taken a look at the security of the Android platform, but hinted that as the operating system is still in development, developers would be given proper time to fix any issues prior to the official product release.<\/p>\n<p>Update: Gowdiak has responded to our questions about multitasking on S40 and points out it&#8217;s a feature of the Java Virtual Machine used on selected Nokia S40 devices. &#8220;We verified that it is possible to run Java applications in parallel on certain Nokia Series 40 phones,&#8221; he said.<\/p>\n<p align=\"justify\"><a href=\"http:\/\/www.telecoms.com\/itmgcontent\/tcoms\/news\/articles\/20017560920.html\" target=\"_blank\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A Polish hacker and self professed security expert claims to have discovered vulnerabilities in the mobile Java technology implemented by Nokia in its mid-range S40 devices, potentially putting millions of handsets at risk. Adam Gowdiak, who is in the process of setting up a security research firm, Security Explorations, claims the bugs affect around 140 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[23,8,22],"tags":[117,116,94,118],"class_list":["post-125","post","type-post","status-publish","format-standard","hentry","category-hacking","category-it-news","category-vulnerabilities","tag-bugs","tag-hacker","tag-java","tag-phones"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Hacker Claims Java Bug Affects Millions of Phones<\/title>\n<meta name=\"description\" content=\"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hacker Claims Java Bug Affects Millions of Phones\" \/>\n<meta property=\"og:description\" content=\"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/\" \/>\n<meta property=\"og:site_name\" content=\"for everyone... :)\" \/>\n<meta property=\"article:published_time\" content=\"2008-08-20T08:57:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-02-05T16:50:48+00:00\" \/>\n<meta name=\"author\" content=\"Kashif\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kashif\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/\"},\"author\":{\"name\":\"Kashif\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/#\\\/schema\\\/person\\\/a8c02ebbadea5c972ff6f29ca61461a2\"},\"headline\":\"Hacker Claims Java Bug Affects Millions of Phones\",\"datePublished\":\"2008-08-20T08:57:19+00:00\",\"dateModified\":\"2015-02-05T16:50:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/\"},\"wordCount\":536,\"commentCount\":0,\"keywords\":[\"Bugs\",\"Hacker\",\"Java\",\"Phones\"],\"articleSection\":[\"Hacking\",\"IT News\",\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/\",\"url\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/\",\"name\":\"Hacker Claims Java Bug Affects Millions of Phones\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/#website\"},\"datePublished\":\"2008-08-20T08:57:19+00:00\",\"dateModified\":\"2015-02-05T16:50:48+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/#\\\/schema\\\/person\\\/a8c02ebbadea5c972ff6f29ca61461a2\"},\"description\":\"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/2008\\\/08\\\/hacker-claims-java-bug-affects-millions-of-phones\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hacker Claims Java Bug Affects Millions of Phones\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/\",\"name\":\"for everyone... :)\",\"description\":\"etc...\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/#\\\/schema\\\/person\\\/a8c02ebbadea5c972ff6f29ca61461a2\",\"name\":\"Kashif\",\"sameAs\":[\"http:\\\/\\\/www.logichub.net\\\/blog\\\/\"],\"url\":\"https:\\\/\\\/www.logichub.net\\\/blog\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hacker Claims Java Bug Affects Millions of Phones","description":"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/","og_locale":"en_US","og_type":"article","og_title":"Hacker Claims Java Bug Affects Millions of Phones","og_description":"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.","og_url":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/","og_site_name":"for everyone... :)","article_published_time":"2008-08-20T08:57:19+00:00","article_modified_time":"2015-02-05T16:50:48+00:00","author":"Kashif","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kashif","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/#article","isPartOf":{"@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/"},"author":{"name":"Kashif","@id":"https:\/\/www.logichub.net\/blog\/#\/schema\/person\/a8c02ebbadea5c972ff6f29ca61461a2"},"headline":"Hacker Claims Java Bug Affects Millions of Phones","datePublished":"2008-08-20T08:57:19+00:00","dateModified":"2015-02-05T16:50:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/"},"wordCount":536,"commentCount":0,"keywords":["Bugs","Hacker","Java","Phones"],"articleSection":["Hacking","IT News","Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/","url":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/","name":"Hacker Claims Java Bug Affects Millions of Phones","isPartOf":{"@id":"https:\/\/www.logichub.net\/blog\/#website"},"datePublished":"2008-08-20T08:57:19+00:00","dateModified":"2015-02-05T16:50:48+00:00","author":{"@id":"https:\/\/www.logichub.net\/blog\/#\/schema\/person\/a8c02ebbadea5c972ff6f29ca61461a2"},"description":"Vulnerabilities have been discovered in the mobile Java technology implemented by Nokia in its mid-range S40 devices, putting millions of handsets at risk.","breadcrumb":{"@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.logichub.net\/blog\/2008\/08\/hacker-claims-java-bug-affects-millions-of-phones\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.logichub.net\/blog\/"},{"@type":"ListItem","position":2,"name":"Hacker Claims Java Bug Affects Millions of Phones"}]},{"@type":"WebSite","@id":"https:\/\/www.logichub.net\/blog\/#website","url":"https:\/\/www.logichub.net\/blog\/","name":"for everyone... :)","description":"etc...","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.logichub.net\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.logichub.net\/blog\/#\/schema\/person\/a8c02ebbadea5c972ff6f29ca61461a2","name":"Kashif","sameAs":["http:\/\/www.logichub.net\/blog\/"],"url":"https:\/\/www.logichub.net\/blog\/author\/admin\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":115,"url":"https:\/\/www.logichub.net\/blog\/2008\/08\/sun-opens-java-tools-in-mobile-fight-back\/","url_meta":{"origin":125,"position":0},"title":"Sun Opens Java Tools in Mobile Fight Back","author":"Kashif","date":"August 20, 2008","format":false,"excerpt":"Sun Microsystems has open sourced its Java toolkit for building mobile applications just as the role Java plays on handsets comes into question. The company has released the Light-Weight UI Toolkit (LWUIT) (https:\/\/lwuit.dev.java.net\/) under a GPLv2 license with a classpath exception - for binary linking with an application - as\u2026","rel":"","context":"In &quot;IT News&quot;","block_context":{"text":"IT News","link":"https:\/\/www.logichub.net\/blog\/category\/news\/it-news\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":13,"url":"https:\/\/www.logichub.net\/blog\/2008\/08\/microsoft-patches-holes-in-office-browser\/","url_meta":{"origin":125,"position":1},"title":"Microsoft Patches Holes in Office, Browser","author":"Kashif","date":"August 18, 2008","format":false,"excerpt":"Microsoft released patches to fix 26 vulnerabilities in the company's software, including major issues in its Internet Explorer browser and Office suite of productivity applications. The eleven patches, published on Microsoft's monthly schedule, included six fixes rated Critical -- Microsoft's highest rating of severity -- and five updates rated Important\u2026","rel":"","context":"In &quot;IT News&quot;","block_context":{"text":"IT News","link":"https:\/\/www.logichub.net\/blog\/category\/news\/it-news\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":240,"url":"https:\/\/www.logichub.net\/blog\/2008\/09\/apple-iphone-password-locking-bug-lets-physically-local-users-bypass-the-password\/","url_meta":{"origin":125,"position":2},"title":"Apple iPhone Password Locking Bug Lets Physically Local Users Bypass the Password","author":"Kashif","date":"September 9, 2008","format":false,"excerpt":"Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow. Details: SecurityTracker Alert ID: 1020763 SecurityTracker\u2026","rel":"","context":"In &quot;iPhone&quot;","block_context":{"text":"iPhone","link":"https:\/\/www.logichub.net\/blog\/category\/mobile\/iphone\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":502,"url":"https:\/\/www.logichub.net\/blog\/2011\/01\/easy-to-implement-techniques-on-how-to-secure-your-home-pc-from-bad-guys\/","url_meta":{"origin":125,"position":3},"title":"Easy to implement techniques on How to Secure your Home PC from Bad Guys","author":"Kashif","date":"January 13, 2011","format":false,"excerpt":"The\u00a0Internet\u00a0may\u00a0contain dangers\u00a0for the\u00a0ordinary and innocent computer user.\u00a0Without\u00a0proper security measures, your PC and data saved in your PC is\u00a0in\u00a0danger\u00a0every moment of\u00a0your\u00a0system is\u00a0connected\u00a0to the internet. In order to protect your Home PC, these steps are necessary to follow: Use of Strong Password Use of reliable Antivirus and\u00a0Anti Spyware\u00a0software Update your Operating System\u2026","rel":"","context":"In &quot;IT Articles&quot;","block_context":{"text":"IT Articles","link":"https:\/\/www.logichub.net\/blog\/category\/articles\/it-articles\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":38,"url":"https:\/\/www.logichub.net\/blog\/2008\/08\/bluetooth-still-has-space-for-growth\/","url_meta":{"origin":125,"position":4},"title":"Bluetooth Still Has Space for Growth","author":"Kashif","date":"August 19, 2008","format":false,"excerpt":"Bluetooth seems to have reached a maturation period with growth rates that, while strong, do not match the growth of the recent past, reports In-Stat market research firm. Still, there is a place for growth. The Bluetooth chip market should benefit as new standards, such as low-energy and high-speed Bluetooth,\u2026","rel":"","context":"In &quot;IT News&quot;","block_context":{"text":"IT News","link":"https:\/\/www.logichub.net\/blog\/category\/news\/it-news\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":260,"url":"https:\/\/www.logichub.net\/blog\/2008\/10\/checkpagerankws-a-free-page-rank-checking-tool\/","url_meta":{"origin":125,"position":5},"title":"CheckPageRank.ws -A Free Page Rank Checking Tool","author":"Kashif","date":"October 3, 2008","format":false,"excerpt":"Page Rank is one of the many criteria webmasters use to assess popularity and worth of any website. There are many tools available on the web to measure Page Rank like Google Toolbar, one of the popular browser addon also accompanying with Page Rank tool. But here arises some problems:\u2026","rel":"","context":"In &quot;Browser&quot;","block_context":{"text":"Browser","link":"https:\/\/www.logichub.net\/blog\/category\/software\/browser-software\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/posts\/125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/comments?post=125"}],"version-history":[{"count":0,"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/posts\/125\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/media?parent=125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/categories?post=125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.logichub.net\/blog\/wp-json\/wp\/v2\/tags?post=125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}