<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>windows phone apps &#124; WP7 Accessories &#124; WP7 games &#187; Security Vulnerability</title>
	<atom:link href="http://www.1800pocketpc.com/tag/security-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.1800pocketpc.com</link>
	<description>windows phone apps &#124; WP7 Accessories &#124; WP7 games</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:03:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>An SMS could cripple Windows Phone .. do you really want to know how ?</title>
		<link>http://www.1800pocketpc.com/an-sms-could-cripple-windows-phone-do-you-really-want-to-know-how/25631/</link>
		<comments>http://www.1800pocketpc.com/an-sms-could-cripple-windows-phone-do-you-really-want-to-know-how/25631/#comments</comments>
		<pubDate>Tue, 13 Dec 2011 01:48:14 +0000</pubDate>
		<dc:creator>Saijo George</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=25631</guid>
		<description><![CDATA[It seems that Khaled Salameh has discovered a bug with Windows Phone that could cause serious problem for Windows Phone users. Its is not know if this affect all Windows Phone users at this stage but winrumors does test this out on a Samsung and HTC device and it would seem both of them are [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>It seems that Khaled Salameh has discovered a bug with Windows Phone that could cause serious problem for Windows Phone users. Its is not know if this affect all Windows Phone users at this stage but winrumors does test this out on a Samsung and HTC device and it would seem both of them are affected by the bug, the effect of which causes Windows Phone to reboot and disables the message hub and it&#8217;s said that the user will not be able to open up the messaging hub unless they do a hard reset. All it takes is a SMS to be sent to Windows Phone ( using a specific set of text ). </p>
<p>Thankfully Khaled Salameh and WinRumors have not made this particular info public and its a good thing , imagine the trouble if something like this were made public. </p>
<p> <a href="http://www.1800pocketpc.com/an-sms-could-cripple-windows-phone-do-you-really-want-to-know-how/25631/#more-25631"  class="more-link">(more&#8230;)</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/an-sms-could-cripple-windows-phone-do-you-really-want-to-know-how/25631/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>[ Security ] moTweets saves your twitter password in plain text !!</title>
		<link>http://www.1800pocketpc.com/security-motweets-saves-your-twitter-password-in-plain-text/13455/</link>
		<comments>http://www.1800pocketpc.com/security-motweets-saves-your-twitter-password-in-plain-text/13455/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 06:44:21 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[motweets]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=13455</guid>
		<description><![CDATA[I am not sure how the other Windows Mobile clients handle this according to @mus_hi, the free ad supported version of moTweets saves your twitter password in an XML file. With access to the file system via a File Explorer on Windows Mobile, its all too easy to look for this XML file in the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div id="attachment_13456" class="wp-caption alignright" style="width: 192px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2010/06/moTweets-AccountsXML.jpg" ><img src="http://www.1800pocketpc.com/blog/wp-content/uploads/2010/06/moTweets-AccountsXML-192x320.jpg" alt="moTweets-AccountsXML" title="moTweets-AccountsXML" width="192" height="320" class="size-thumbnail wp-image-13456" /></a>
	<p class="wp-caption-text">moTweets-AccountsXML</p>
</div><br />
I am not sure how the other Windows Mobile clients handle this according to <a target="_blank" href="http://www.twitter.com/mus_hi" >@mus_hi</a>, the free ad supported version of moTweets saves your twitter password in an XML file. With access to the file system via a File Explorer on Windows Mobile, its all too easy to look for this XML file in the installation directory and open it and guess what ? You password is saved there. We have contacted <a target="_blank" href="http://www.panoramicsoft.com/" >Panoramic Software</a> to inform them of the issue and will let you know about any updates on the issue. ( read more about the issue on <a target="_blank" href="http://www.mushive.com/do-not-use-motweets-twitter-software-for-windows-mobile" >mushive.com</a> ), I wouldn&#8217;t say you should stop using moTweets, but dont pass your device around to those nosy friends / siblings. moTweets is definitely one of the better twitter client on Windows Phone and I hope they have an update to fix the issue soon.</p>
<p><strong>What twitter Client do you guys use ? Does it have the same issue ?</strong></p>
<p class="alert"><strong>Update :</strong> A rep from Panoramic Software got back to us with this info ..  This issue has already been addressed and will be released with the next version 1.8.3, which should be out today.</p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/security-motweets-saves-your-twitter-password-in-plain-text/13455/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>[ Security Vulnerability ] International Calls from Windows Mobile without users permission &#8211; ghost dialer trojan ??</title>
		<link>http://www.1800pocketpc.com/security-vulnerability-international-calls-from-windows-mobile-without-users-permission-ghost-dialer-trojan/12021/</link>
		<comments>http://www.1800pocketpc.com/security-vulnerability-international-calls-from-windows-mobile-without-users-permission-ghost-dialer-trojan/12021/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 07:20:22 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=12021</guid>
		<description><![CDATA[Many Windows Mobile users started noticing a strange issue with their windows Mobile device. The device was automatically calling out random international numbers with out the users permission. The issue was first noticed by smudgelab over at xda-developers. some of the telephone numbers that was dialed out includes +88213213214 +1(767)503-3611 +25240221601 After a lot of [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div class="wp-caption alignright" style="width: 241px">
	<img alt="Virus" src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/windows-mobile-virus.png" title="Virus" width="241" height="323" />
	<p class="wp-caption-text">Virus</p>
</div><br />
Many Windows Mobile users started noticing a strange issue with their windows Mobile device. The device was automatically calling out random international numbers with out the users permission.</p>
<p>The issue was first noticed by <em><strong>smudgelab </strong>over at <a target="_blank" href="http://forum.xda-developers.com/showthread.php?t=650393" >xda-developers</a></em>. some of the telephone numbers that was dialed out includes<br />
<strong><br />
+88213213214<br />
+1(767)503-3611<br />
+25240221601</strong></p>
<p>After a lot of discussion , they have found a common issue most of the users have installed a game <strong>&#8221; 3D Anti-terrorist &#8220;</strong>. We are not 100% if the issue stems from this game but We received an email from someone who posed to be the developer of the game, and gave us the developers site as a fake-page hosted on atspace.com. The game was hosted on rapidshare on the fake-developers page. Apparently the game was developed by <strong><a target="_blank" href="http://huike.cn/" >Huike.cn</a> </strong>and its not a free game. This dodgy individual must have loaded the game with the trojan dialer and many unsuspecting users including myself installed this game. </p>
<h3>What should you do now.</h3>
<p>Go through your call history, check for any calls that look suspicious ( cross reference with the numbers posted above ). Block out going international and premium numbers ( if you dont use them ). Delete &#8221; 3D Anti-terrorist &#8221; if you have installed it. Install a Windows Mobile Antivirus ( most of them are not free, try the demo to see if they work for you )<br />
<a target="_blank" href="http://www.airscanner.com/" >AirScanner</a><br />
<a target="_blank" href="https://www.mylookout.com/" >LookOut</a> ( Free )<br />
<a target="_blank" href="https://www.kasperskyanz.com.au/kaspersky_mobile_security" >Kaspersky Mobile Security</a><br />
<a target="_blank" href="http://www.symantec.com/business/mobile-antivirus-for-windows-mobile" >Symantec Mobile AntiVirus</a><br />
<a target="_blank" href="http://mobile.f-secure.com/downloads/trial/index.html" >F-Secure Mobile Security</a></p>
<p>We will keep you posted on the developments in regards to this issue. </p>
<p>Thanks to <strong>Alfredo-Nicolas Rios</strong> for bringing the issue to our attention.</p>
<p> <a href="http://www.1800pocketpc.com/security-vulnerability-international-calls-from-windows-mobile-without-users-permission-ghost-dialer-trojan/12021/#more-12021"  class="more-link">Continue reading</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/security-vulnerability-international-calls-from-windows-mobile-without-users-permission-ghost-dialer-trojan/12021/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Trojan-SMS.WinCE.Sejweek.a for Windows Mobile</title>
		<link>http://www.1800pocketpc.com/trojan-sms-wince-sejweek-a-for-windows-mobile/9742/</link>
		<comments>http://www.1800pocketpc.com/trojan-sms-wince-sejweek-a-for-windows-mobile/9742/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 04:54:29 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=9742</guid>
		<description><![CDATA[Kaspersky has relased info on a new Mobile Phone trojan ( Trojan-SMS.WinCE.Sejweek.a ) , WMPowerUser informs us that &#8221; the Trojan-SMS.WinCE.Sejweek.a trojan is commonly found associated with pirated software, downloads an XML file from a website which contains the numbers of premium rate SMS numbers and the frequency at which the expensive ($1 per message) [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div id="attachment_5882" class="wp-caption alignright" style="width: 241px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/windows-mobile-virus.png" ><img src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/windows-mobile-virus.png" alt="windows-mobile-virus" title="windows-mobile-virus" width="241" height="323" class="size-full wp-image-5882" /></a>
	<p class="wp-caption-text">windows-mobile-virus</p>
</div><br />
<a target="_blank" href="http://www.viruslist.com/en/weblog?weblogid=208187951" >Kaspersky</a> has relased info on a new Mobile Phone trojan ( Trojan-SMS.WinCE.Sejweek.a ) , <a target="_blank" href="http://wmpoweruser.com/?p=11427" >WMPowerUser</a> informs us that &#8221; <em>the Trojan-SMS.WinCE.Sejweek.a trojan is commonly found associated with pirated software, downloads an XML file from a website which contains the numbers of premium rate SMS numbers and the frequency at which the expensive ($1 per message) SMS messages will be sent. Due to the variety of SMS numbers being sent to it is less easy to block the money making part of the scheme, making the trojan’s utility that much longer lived. </em>&#8221;</p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/trojan-sms-wince-sejweek-a-for-windows-mobile/9742/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Australian DSD ( Defense Signals Directorate ) gives Windows Mobile 6.1 the thumbs up</title>
		<link>http://www.1800pocketpc.com/australian-dsd-defense-signals-directorate-gives-windows-mobile-6-1-the-thumbs-up/6940/</link>
		<comments>http://www.1800pocketpc.com/australian-dsd-defense-signals-directorate-gives-windows-mobile-6-1-the-thumbs-up/6940/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 02:28:55 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=6940</guid>
		<description><![CDATA[The DSD is the Australian Government’s national authority for information security. Windows Mobile 6.1 operating system have successful completed the Defence Signals Directorate (DSD) Australasian Information Security Evaluation Program and also has obtained Common Criteria Evaluation Assurance Level 4 (EAL4). ( EAL7 is the highest possible level ) By meeting the security criteria for EAL4, [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div class="wp-caption alignleft" style="width: 244px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/06/default.png" ><img alt="No ScreenShot" src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/06/default.png" title="No ScreenShot" width="244" height="323" /></a>
	<p class="wp-caption-text">No ScreenShot</p>
</div><br />
The DSD is the Australian Government’s national authority for information security. Windows Mobile 6.1 operating system have successful completed the Defence Signals Directorate (DSD) Australasian Information Security Evaluation Program and also has obtained <a target="_blank" href="http://en.wikipedia.org/wiki/Common_Criteria" >Common Criteria Evaluation Assurance Level 4</a> (EAL4). <em>( EAL7 is the highest possible level )</em></p>
<p>By meeting the security criteria for EAL4, Windows Mobile 6.1 are accepted under the Common Criteria Recognition Arrangement (CCRA) by Australia and 25 other countries worldwide including the United Kingdom and the United States. The CCRA ensures that evaluations of IT products are performed to high and globally consistent standards. Thus, this certification provides government and enterprise customers with definitive information about the security features in Windows Mobile 6.1, and assurance that mobile workers can securely access sensitive data on information networks.</p>
<p>Mike Burgess, first assistant secretary, Information Security, Defence Signals Directorate, said, “We have worked very closely with Microsoft throughout this assessment process to ensure that Windows Mobile 6.1 meets the security needs for government and enterprise networks.”</p>
<p>via <a target="_blank" href="http://windowsteamblog.com/blogs/windowsphone/archive/2009/08/19/microsoft-mobile-security-receives-global-recognition.aspx" >windowsteamblog.com</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/australian-dsd-defense-signals-directorate-gives-windows-mobile-6-1-the-thumbs-up/6940/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone 3GS Encryption Is ‘Useless’ for Business!! is it really ?</title>
		<link>http://www.1800pocketpc.com/iphone-3gs-encryption-is-%e2%80%98useless%e2%80%99-for-business-is-it-really/6083/</link>
		<comments>http://www.1800pocketpc.com/iphone-3gs-encryption-is-%e2%80%98useless%e2%80%99-for-business-is-it-really/6083/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 01:45:31 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=6083</guid>
		<description><![CDATA[Here is an iPhone Story that many wont tell you. According to Jonathan Zdziarski,, an iPhone developer and a hacker who teaches forensics courses on recovering data from iPhones, claims that the enterprise-friendly encryption included with the iPhone 3GS is so weak it can be cracked in two minutes with a few pieces of readily [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div id="attachment_6084" class="wp-caption alignleft" style="width: 240px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/iphoneinterface.jpg" ><img src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/iphoneinterface-240x302.jpg" alt="iPhone Hacked" title="iPhone Hacked" width="240" height="302" class="size-thumbnail wp-image-6084" /></a>
	<p class="wp-caption-text">iPhone Hacked</p>
</div><br />
Here is an iPhone Story that many wont tell you. According to Jonathan Zdziarski,, an iPhone developer and a hacker who teaches forensics courses on recovering data from iPhones, claims that the enterprise-friendly encryption included with the iPhone 3GS is so weak it can be cracked in two minutes with a few pieces of readily available freeware. In a recent report from <a target="_blank" href="http://www.wired.com/gadgetlab/2009/07/iphone-encryption/" >wired.com</a> He claims that “It is kind of like storing all your secret messages right next to the secret decoder ring,” and also went on to say “I don’t think any of us have ever seen encryption implemented so poorly before, which is why it’s hard to describe why it’s such a big threat to security.”</p>
<p> <a href="http://www.1800pocketpc.com/iphone-3gs-encryption-is-%e2%80%98useless%e2%80%99-for-business-is-it-really/6083/#more-6083"  class="more-link">Get more info about the iPhone&#8217;s Encryption Flaws</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/iphone-3gs-encryption-is-%e2%80%98useless%e2%80%99-for-business-is-it-really/6083/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>O2 Toshiba TG01 Windows Mobile shipped with a virus !!!</title>
		<link>http://www.1800pocketpc.com/o2-toshiba-tg01-windows-mobile-shipped-with-a-virus/5881/</link>
		<comments>http://www.1800pocketpc.com/o2-toshiba-tg01-windows-mobile-shipped-with-a-virus/5881/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 05:02:51 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=5881</guid>
		<description><![CDATA[According to MSMobile.com Toshiba TG01 Windows Mobile sold by O2 has a virus that is located in some memory cards that are delivered in package of Toshiba TG01. This virus has infected only devices sold in July 2009 and devices sold previously (sales of Toshiba TG01 started at O2 Germany in June) are not affected. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div id="attachment_5882" class="wp-caption alignright" style="width: 238px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/windows-mobile-virus.png" ><img src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/windows-mobile-virus-238x320.png" alt="windows-mobile-virus" title="windows-mobile-virus" width="238" height="320" class="size-thumbnail wp-image-5882" /></a>
	<p class="wp-caption-text">windows-mobile-virus</p>
</div><br />
According to <a target="_blank" href="http://msmobiles.com/news.php/8439.html" >MSMobile.com</a> Toshiba TG01 Windows Mobile sold by O2 has a virus that is located in some memory cards that are delivered in package of Toshiba TG01.  This virus has infected only devices sold in July 2009 and devices sold previously (sales of Toshiba TG01 started at O2 Germany in June) are not affected. This is the first time ever when virus software is encountered in a Windows Mobile phone that is commercially sold.</p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/o2-toshiba-tg01-windows-mobile-shipped-with-a-virus/5881/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTC WM6.1 and WM6 Bluetooth Vulnerability</title>
		<link>http://www.1800pocketpc.com/htc-wm6-1-and-wm6-bluetooth-vulnerability/5824/</link>
		<comments>http://www.1800pocketpc.com/htc-wm6-1-and-wm6-bluetooth-vulnerability/5824/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 13:35:27 +0000</pubDate>
		<dc:creator>. Saijo</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=5824</guid>
		<description><![CDATA[HTC devices running Windows Mobile 6 and Windows Mobile 6.1 are prone to a directory traversal vulnerability in the Bluetooth OBEX FTP Service. Exploiting this issue allows a remote authenticated attacker to list arbitrary directories, and write or read arbitrary files, via a ../ in a pathname. HTC handsets running Windows Mobile 5 are not [...]]]></description>
			<content:encoded><![CDATA[<p></p><div id="attachment_5825" class="wp-caption alignright" style="width: 240px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/obex-directory-traversal-display_7.jpg" ><img src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/07/obex-directory-traversal-display_7.jpg" alt="Bluetooth Vulnerability" title="Bluetooth Vulnerability" width="240" height="320" class="size-full wp-image-5825" /></a>
	<p class="wp-caption-text">Bluetooth Vulnerability</p>
</div><br />
HTC devices running Windows Mobile 6 and Windows Mobile 6.1 are prone to a directory traversal vulnerability in the Bluetooth OBEX FTP Service. Exploiting this issue allows a remote authenticated attacker to list arbitrary directories, and write or read arbitrary files, via a ../ in a pathname. HTC handsets running Windows Mobile 5 are not affected. Users worried about the vulnerability should avoid pairing their phones with an untrusted handset or computer. They may also want to delete any devices that are already paired with their phones. Because the driver, obexfile.dll, is an HTC driver, only handsets from the company are affected. Apparently Windows Mobile 6.5 devices will be vulnerable too if HTC does not fix the driver according to Moreno Tablado, who discovered this Vulnerability. </p>
<p>[ via <a target="_blank" href="http://www.pcworld.com/businesscenter/article/168358/htc_smartphones_left_vulnerable_to_bluetooth_attack.html" >PC World</a> ]
<p><a target="_blank" href="http://www.seguridadmobile.com/windows-mobile/windows-mobile-security/HTC-Windows-Mobile-OBEX-FTP-Service-Directory-Traversal.html" >More info about the Vulnerability</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/htc-wm6-1-and-wm6-bluetooth-vulnerability/5824/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Phone Creeper 0.3 &#8211; Espionage Application or Security Vulnerability?</title>
		<link>http://www.1800pocketpc.com/phone-creeper-03-espionage-application-or-security-vunerability/4899/</link>
		<comments>http://www.1800pocketpc.com/phone-creeper-03-espionage-application-or-security-vunerability/4899/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 16:20:15 +0000</pubDate>
		<dc:creator>Mukku</dc:creator>
				<category><![CDATA[Espionage]]></category>
		<category><![CDATA[phone creeper]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[spy]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=4899</guid>
		<description><![CDATA[Phone Creeper which the author describes an an Espionage Suite has been recently released by chetstriker from xda-developers. I am thankful to the developer for pointing out such a vulnerability within the Windows Mobile operating system. Currently it has the following features: secretly and remotely read incoming / outgoing sms secretly and remotely delete incoming [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><div class="wp-caption alignright" style="width: 244px">
	<a href="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/06/default.png" ><img alt="No ScreenShot" src="http://www.1800pocketpc.com/blog/wp-content/uploads/2009/06/default.png" title="No ScreenShot" width="244" height="323" /></a>
	<p class="wp-caption-text">No ScreenShot</p>
</div><br />
Phone Creeper which the author describes an an Espionage Suite has been recently released by <a target="_blank" href="http://forum.xda-developers.com/member.php?u=876347" class="bigusername" >chetstriker</a> from xda-developers. I am thankful to the developer for pointing out such a vulnerability within the Windows Mobile operating system. </p>
<p><strong>Currently it has the following features:</strong></p>
<ol>
<li> secretly and remotely read incoming / outgoing sms</li>
<li> secretly and remotely delete incoming / outgoing sms</li>
<li> secretly and remotely view call history</li>
<li> bounce sms messages off remote phone to someone else.</li>
<li> create a pop-up message on phone</li>
<li> send a secret fart sound</li>
<li> secretly and remotely listen to person. (Initiates silent call back of person to your phone with thier speaker phone enabled)</li>
<li> also send listening in call to somebody else&#8217;s phone</li>
</ol>
<p>All results will be sent via SMS back without leaving any trace on the phone being controlled. Any cell phone can be used to initiate the commands and all commands will respond with a success message for acknowledgment.</p>
<p><strong>Install Instructions :</strong><br />
Just install .cab on the victims wm5 or higher phone. <strong>THEN MAKE SURE YOU REBOOT TO INITIATE IT.</strong><br />
by default the password is &#8220;<strong>chetstriker</strong>&#8220;, obviously not including the quotes and BE SURE IT&#8217;S ALL IN LOWER CASE. The command format is (password and then command)</p>
<p> <a href="http://www.1800pocketpc.com/phone-creeper-03-espionage-application-or-security-vunerability/4899/#more-4899"  class="more-link">Download this Application</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/phone-creeper-03-espionage-application-or-security-vunerability/4899/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Security Vunerability for Microsoft Windows CE 5.0</title>
		<link>http://www.1800pocketpc.com/security-vunerability-for-microsoft-windows-ce-50/353/</link>
		<comments>http://www.1800pocketpc.com/security-vunerability-for-microsoft-windows-ce-50/353/#comments</comments>
		<pubDate>Tue, 27 May 2008 13:08:19 +0000</pubDate>
		<dc:creator>Saijo George</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Vulnerability]]></category>

		<guid isPermaLink="false">http://www.1800pocketpc.com/?p=353</guid>
		<description><![CDATA[We dont usually find a lot of Security Vunerability on Mobile devices when compared to the desktop cousin but once in a while a few of them do surface. A security vunerability for Windows CE posted in the US-CERT Cyber Security Bulletin. Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>We dont usually find a lot of Security Vunerability on Mobile devices when compared to the desktop cousin but once in a while a few of them do surface.</p>
<p>A security vunerability for Windows CE posted in the US-CERT <img src="http://www.1800pocketpc.com/blog/wp-content/plugins/file-icons/icons/silkicons/world_link.png" alt="" width="16" height="16" /> <a href="http://www.us-cert.gov/cas/bulletins/SB08-140.html" rel="nofollow"  target="_blank">Cyber Security Bulletin</a>.</p>
<p>Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted JPEG and GIF images.</p>
<p>For more details see <img src="http://www.1800pocketpc.com/blog/wp-content/plugins/file-icons/icons/silkicons/world_link.png" alt="" width="16" height="16" /> <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2160" rel="nofollow"  target="_blank">National Vulnerability Database (CVE-2008-2160)</a></p>
<p><strong>And update is available from Microsoft</strong> <img src="http://www.1800pocketpc.com/blog/wp-content/plugins/file-icons/icons/silkicons/world_link.png" alt="" width="16" height="16" /> <a href="http://support.microsoft.com/kb/948812" rel="nofollow"  target="_blank">here</a>.<br />
Source : <img src="http://www.1800pocketpc.com/blog/wp-content/plugins/file-icons/icons/silkicons/world_link.png" alt="" width="16" height="16" /> <a target="_blank" href="http://www.4winmobile.com/forums/4wm-news/16138-security-vunerability-windows-ce-posted.html" >4winmobile.com</a></p>

<p>Check out more : <a href="http://www.1800pocketpc.com"><strong>Windows Phone Apps</strong></a> | <a href="http://www.bestwp7games.com"><strong>Windows Phone Games</strong></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.1800pocketpc.com/security-vunerability-for-microsoft-windows-ce-50/353/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

