How to control a BlackBerry Enterprise Server with just a PDF

Filed Under: Malware, Mobile


Sorry, I'm not actually going to tell you how to do that.

But Research In Motion (RIM), the company who make the BlackBerry smartphones beloved by corporate workers worldwide, has warned of a vulnerability in the way its devices handles PDF files which could allow hackers to remotely execute code.

According to a security advisory issued by the firm, hackers could send email message with an attached PDF file that, when opened by a BlackBerry mobile user, could cause code to be launched on the computer that hosts the BlackBerry Attachment Service. Of course, this isn't the first time that this kind of problem with RIM's BlackBerry has bubbled up.

RIM is advising that companies disable PDF file processing on the BlackBerry server until the patches are rolled out.

As we've reported umpteen times before, hackers are increasingly exploiting the PDF file format to deliver malicious code to unsuspecting computer users.

As PDFs are so widely used and shared in business, most people wouldn't think twice of clicking on them, making it imperative that corporations keep their security patches and anti-malware defences up-to-date.

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.