Slashdot Mirror


Mabir.A Virus Targets Symbian Phones

adennis writes "Exploiting bluetooth and weaknesses in the OS, the Mabir.A virus, like its predecessor, targets the version of the Symbian operating system running on Nokia Series 60 handsets. Since Symbian is the dominant smartphone OS, found on phones made by Motorola, Siemens, Sony Ericsson Panasonic and Nokia, this virus could have great impact. Will mobile OS companies, like desktop OS makers, have to start an automatic update system, or will the OS creators have to start making their software secure?"

9 of 199 comments (clear)

  1. Same thing? by soniCron88 · · Score: 5, Insightful

    Will mobile OS companies, like desktop OS makers, have to start an automatic update system, or will the OS creators have to start making their software secure?

    Wouldn't an automatic update system serve to make the software more secure?

    1. Re:Same thing? by ManikSurtani · · Score: 5, Insightful

      Yep, pretty much, except that I believe the author meant that s/ware should be written with security in mind from the outset.

      On a different note, what I'd loathe to see (but may be inevitable) are goddamn antivirus programs for phones. Imagine those things updating their virus dbs, etc. every time you switch on your phone...

      --
      -- Manik Surtani
  2. Remember when viruses were cool? by Dancin_Santa · · Score: 5, Insightful

    There was a time when a virus could install itself just be latching onto a 3.5" disk boot sector and infect tons of machines without anyone having the slightest clue as to its existence.

    Nowadays, viruses are so pussified that they need to ask the machine owner to install them. How sad.

  3. Well, I'm not impressed by KonijnenBunny · · Score: 5, Insightful

    I own a Nokia 60-series phone and much to my surprise I encountered the above mentioned predecessor (Caribe/Cabir) in the wild. (Yep, my bluetooth's always on)
    I received over 20 identical messages by Bluetooth messaging, all containing a single application-installation file: caribe.sis I had to approve the reception of the message first before I could view the contents. As I browsed the message contents, a further warning that it contained an application was issued, and I image the standard "not-signed" warning would as well if I'd try to actually install it.

    That's 3 warnings I would have to ignore before the virus is installed. Surely in this day and age anyone's brains would have kicked in and wonder whether it would be a wise idea to install an unknown program sent to you by an anonymous stranger? Mobile-phone virii are all still very proof-of-concept in my book...

  4. Re:Want a surefire solution?? I have the answer. by imipak · · Score: 5, Insightful
    Want a surefire solution?? I have the answer. [...] And it ain't pretty. Death penalty for virus writers.

    What a great idea. I'm sure this will work just as effectively as the USA executing alleged murderers - brutal as it sounds, it has at least reduced the murder rate to one of the lowest in the world.

  5. Another FUD from F-Secure by S3D · · Score: 5, Insightful

    This theme is beat to death. So called "virus" require answer "Yes" three times to be installed. The most vocal reporter of these viruses is F-Secure, manufacturer of anti-virus software for symbian phones. Their CEO speaking on one of the previous virus: "somehow, I'm not sure exactly how this virus get installed on my phone" He did't remember answering "Yes" three times ?

  6. Symbian OS will never be secure by Anonymous Coward · · Score: 5, Interesting

    I'm am an experience commercial software developer on the Symbian platform. I have a strong background in many other platforms and i the context of this message, my anonyminity is important since my company can be sued by Symbian just for a biased negative opinion of Symbian made publicly.

    Symbian OS is the most expensive platform to develop on. This means more expensive money and time wise. It takes 3 times as many developers to deliver the same product in twice the time as on comparible platforms (brew, iTron, etc...) as for platforms with real development tools such as Windows Mobile, we use ten developers on Symbian to every one on Windows Mobile to produce a lesser product.

    Symbian has limited hardware level debugging support (if any at all), they lack so much as a command prompt to log to.

    They lack decent compilers and you're stuck with GCC or ARM Realview (neither are that good, satisfactory at best on ARM).

    Documentation is aweful at best.

    A simple program requires you to just through hoops, more complex sets the hoops on fire.

    The emulator environment emulates nothing and simply tries to implement the Symbian UI APIs on Windows and all system level stuff is just layered on Windows. That's fine if you don't need to do anything at the system level.

    The development environment is heavily based on CodeWarrior these days. I find this funny since every other company (Nintendo, Sony, Be, Apple, etc..) where Metrowerks had a good footing, the companies found it more profitable to dump CodeWarrior and do it themselves instead. Symbian is the only company stupid enough to choose to rely on Metrowerks, especially with their pathetic resume.

    As for security, the fact that anyone could possibly ship a product based on Symbian is a miracle in itself. As for securing it as well, I think you're just asking too much.

    1. Re:Symbian OS will never be secure by Anonymous Coward · · Score: 5, Interesting

      10 odd years of reading /. and it takes this to get me to post...

      I've been working with the Symbian OS for some time and the parent smells strongly of BS...

      > Symbian has limited hardware level debugging support (if any at all), they lack so much as a command prompt to log to.

      There is support for both hardware level debugging and there has been a working command prompt for several versions. I suggest you ask Symbian (nicely) how to access these.

      > They lack decent compilers and you're stuck with GCC or ARM Realview (neither are that good, satisfactory at best on ARM).

      What's wrong with GCC suddenly? It's bad compared to what? MS Visual Studio? Arm compilers are what you get for ARM chips - still the undisputed leader for the mobile market.

      > Documentation is aweful at best.

      It is patchy. It's getting better...

      > That's fine if you don't need to do anything at the system level.

      I've seen a variety of system level debugging on the emulator. Maybe you need some pointers?

      > The development environment is heavily based on CodeWarrior these days.

      I'm told Symbian has good feedback into Metroworks and gets their CW specifically tailored for them so maybe it's better than their usual product.

      > As for security, the fact that anyone could possibly ship a product based on Symbian is a miracle in itself.

      Which is obviously why they have something like 80% of the smart mobile market...

      > As for securing it as well, I think you're just asking too much.

      The next big release is supposed to be all about security.

      > as for platforms with real development tools such as Windows Mobile, we use ten developers on Symbian to every one on
      > Windows Mobile to produce a lesser product.

      So why are Microsoft content to deals with Symbian that hurt their own mobile devision? Even they seem to have given up on their own product...

  7. Re:Repeat after me... by Zayin · · Score: 5, Interesting

    I will turn off bluetooth or set my phone's visibility to off.

    Setting your phone's visibility to off is not enough to stop attacks.

    There are already tools out there that find non-discoverable bluetooth devices. A worm might use the same technique.

    --
    "I'd rather have a full bottle in front of me than a full frontal lobotomy"