|
Brought to you by:
Suppliers of:
|
|
|
| |
| The Palm Pre WebOS <=1.1 suffers from a JavaScript injection attack that allows a malicious attacker to access any file on the mobile device. |
| |
Credit:
The information has been provided by Townsend Ladd Harris.
The original article can be found at: http://tlhsecurity.blogspot.com/2009/10/palm-pre-webos-11-remote-file-access.html
|
| |
Vulnerable Systems:
* Palm Pre WebOS version 1.1 and prior
Immune Systems:
* Palm Pre WebOS version 1.2
A specially crafted email can access any file on the Palm Pre WebOS version <=1.1 mobile device and send it to a web site of the attacker's choice just by viewing the email.
The Palm Pre WebOS 1.1 and lower will parse and execute JavaScript contained in an email it receives. Exploiting this vulnerability allows an attacker to read/extract any file and post it to a remote website the attacker controls.
One particular file of interest is the "PalmDatabase.db3" file. Having this database file will give an attacker emails, email addresses, contact list information including names, phone numbers, etc. Limitations with binary data have been identified, however viewing binary data such as database files is still simple.
Palm has patched this vulnerability and all users are recommended to upgrade to WebOS version 1.2+.
|
|
|
|
|