Monday, March 10, 2008

BlackBerry Servers 'Ripe For The Hacking'

John E. Dunn writes on Techworld.com:

Many companies running BlackBerry Enterprise Server (BES) could be inadvertently opening a door to attackers, a penetration testing company has found.

Penetration testing consultancy NTA Monitor found that most of its customers running the BlackBerry Server with Microsoft Exchange were taking the path of least resistance by opening unencrypted ports from the heart of their network to service providers. The providers, in turn, opened a return back to the BES that would pass through firewalls without any policies being applied.

This left the network open on several levels, including session hijacking, IP spoofing, or just the interception of unencrypted traffic.

More here.

0 Comments:

Post a Comment

<< Home