Slashdot Mirror


First Trojan for Windows CE Released

Tuxedo Jack writes "Symantec and The Register are reporting that the first Windows CE trojan horse, known as Brador, has been mailed to Trend Micro. This cannot spread on its own; it must be mailed or transmitted, then opened. Once opened, it opens a TCP port, allowing the remote-controller to connect and establish control over it. As expected, this will most likely be used to make new botnets, and it leads me to wonder: will we soon need firewalls for Windows Embedded?"

9 of 213 comments (clear)

  1. Of course we're going to need firewalls... by Dagny+Taggert · · Score: 4, Insightful

    ..for CE because, as usual, people will have to patch their CE-based PDA. If desktop Windows is any example, most people won't bother to download security updates, leading to exposure to other damaging varients. I'm sure the brains at Symantec are running in high gear right about now.

    --
    Don't be a looter...and yes, I know that it's spelled with an "A" instead of an "E".
    1. Re:Of course we're going to need firewalls... by silverfuck · · Score: 3, Insightful

      IMHO, any device capable of running user programs and with any sort of communications should need a firewall. Computers need them, handhelds need them, soon phones (when they become more like PDAs) will need them, everything! It would save a lot of bother if this type of feature were designed into a system from the beginning, when the threat was more theory than any real problem - just think how things would be if computers had had firewalls from the beginning.

      --
      You know you've been IMing too long when you almost say 'lol' out loud to a non-geeky friend...
  2. Attitudes to networking by rokzy · · Score: 3, Insightful

    >will we soon need firewalls for Windows Embedded?

    given how important and prevalent networking is, shouldn't every network capable device now have some sort of a firewall?

    by analogy, after seatbelts were invented, instead of waiting for a car crash and asking
    "do cars need seatbelsts?", then waiting for a van crash and asking
    "do vans need seatbelts?", then waiting for an SUV crash and asking
    "do SUVs need seatbelts", then waiting for a lorry crash and asking
    "do lorrys need seatbelts" ...
    just skip to the end - put seatbelts in all vehicles unless a very good reason not to.

    1. Re:Attitudes to networking by FireFury03 · · Score: 3, Insightful

      "do busses need seatbelts?" - yes, but not many have them
      "do trains need seatbelts?" - probably, but they don't have them
      "do motorcycles need seatbelts?" - dunno, but I don't see many the them :)

  3. first? bullshit. by gl4ss · · Score: 4, Insightful

    since it doesn't even spread or do anything except accept commands over network I highly doubt that it isn't the first of it's kind.

    and tell me, WHAT GOOD WOULD A FIREWALL DO AGAINST AN _INTENTIONALLY_ INSTALLED BACKDOOR PROGRAM? nothing nada zip zero.. if you _wanted_ to run it which you must(in case of this program) you would want to turn off the fw too, no?

    and built for botnets? no way, are you disconnected with reality? building a botnet with these would be total idiocy.

    and then it's for windows mobile, not ce(yes, a mild difference but difference anyways): " Backdoor.Brador.A will work on Windows Mobile 2003 and only affects ARM-based devices."

    oh and another thing. 99% of the time these devices are behind NAT if they're on network.

    --
    world was created 5 seconds before this post as it is.
  4. Re:Windows Broken Security Model. by tesmako · · Score: 4, Insightful

    Well I would love to hear how all the people posting in this story complaining about the operating system security suggest how to prevent this trojan from working? It does not spread, you have to manually download it or get it in a mail, it does not automatically run, you have to run it yourself, just where is the operating system supposed to look to be able to tell that the user needs to protected from itself?

  5. Not a big deal. by mst76 · · Score: 4, Insightful

    What's the big deal about this, trojans are easy to write for any OS. This particular one opens a listening TCP port, and emails out it's IP address. Since WinCE is a fairly complete OS with a TCP/IP stack and an email client, it's rather obvious that something like this can be written. If they'd discovered a hole that can be exploited without user intervention, that would be big news.

    A possible security weakness of WinCE is that it has no real user and priviledge separation (like Win9x). But what many people who argue for security through priviledge seperation forget to mention is that a standard user (both on NT and Unix) usually has quite a lot of priviledges. You don't need to be root to open ports >1024 or silently send out thousands of emails. Remember, anything YOU can do under a normal user account, a trojan can do as well. So something like this could be easily written for Linux or MacOS. The only security that priviledge separation buys you is that you normally can't change system or other users' files. Since WinCE only supports one user, and the system is in ROM (a hard reset erases all virusses), there is nothing to be gained here.

  6. Re:You shouldn't need a firewall by jimicus · · Score: 3, Insightful

    "No Ports Open" simply means that nothing's listening on those ports. It doesn't mean there's some voodoo magic which keeps them closed. If you want that, it implies you want something at a TCP/IP level in the host OS preventing anything from getting to user level programs. I'd call that a firewall.

    The daemons listening on localhost are configured to. Users don't usually configure trojans.

  7. Firewalls all around! by Cid+Highwind · · Score: 3, Insightful

    "...and it leads me to wonder: will we soon need firewalls for Windows Embedded?"

    Not soon, you need them now! If a device has a public network interface, it needs a firewall. It's not just a matter of Windows sucking, PalmOS, Symbian, Linux, etc. devices are going to have exploitable bugs (and therefore need firewalls) as well.

    --
    0 1 - just my two bits