• Save
Mobile Activesync Russian Roulette - Kiwicon 09
Upcoming SlideShare
Loading in...5
×

Like this? Share it with your network

Share

Mobile Activesync Russian Roulette - Kiwicon 09

  • 2,725 views
Uploaded on

As the popularity of communication (especially email) using mobile devices increases so does the risk of data leakage and data theft. This presentation will review Microsoft Mobile Activesync......

As the popularity of communication (especially email) using mobile devices increases so does the risk of data leakage and data theft. This presentation will review Microsoft Mobile Activesync looking at transport layer security, controls enforced on the mobile devices and some potentially lethal fun (to the device anyway).

  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Be the first to comment
No Downloads

Views

Total Views
2,725
On Slideshare
2,716
From Embeds
9
Number of Embeds
2

Actions

Shares
Downloads
0
Comments
0
Likes
2

Embeds 9

http://www.slideshare.net 7
http://www.linkedin.com 2

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
    No notes for slide
  • How many of you have checked your email while sitting on the toilet? <br /> pause <br /> A report by Osterman Research focusing on mobile messaging in the North American Workplace found that 79% of respondence admitted to doing so. <br /> o 77% have done so while driving (when the car is moving) <br /> o 41% have done so on a commercial flight while in the air <br /> o 16% have done so during a funeral or memorial service <br /> o 11% have done so during a romantic moment <br /> pause <br /> I&#x2019;m here to talk to you about the bad things that can happen while checking your email on the shitter.
  • - austrian by nationality, don&#x2019;t hold an australian passport <br /> - there&#x2019;s no kangaroos in austria <br /> - risky biz movember team
  • - it&#x2019;s a basic web application <br /> <br /> - some organisations implement using the corporate owned devices and some organisations implement the solution using employee owned devices
  • - The server is normally named autodiscover.domain.name <br /> - sync also via USB Cradle Sync <br /> - IIS accepts the connection and then passes it onto the exchange server <br /> - (HTTPS)
  • - Basic Auth - Base64 easily decoded <br /> - Device ID - the administrative interface can be used to block or permit certain device IDs <br /> <br /> - All three platforms tested (WM, iPhone OS, Symbian OS) implemented the Microsoft API to different levels (device policy) <br /> <br /> - Nokia wipe interrupted - removed pin lock and emails were still in inbox <br /> <br /> Device policy consists of things such as: <br /> - enforcing a device password <br /> - min pass length <br /> - alphanumeric pass <br /> - max password age <br /> - pass history <br /> - account lockout threshold <br /> - idle session timeout
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - Just by sniffing traffic you can already start enumerating domain usernames from the URL. <br /> - Policy Key does not appear to change/increment (over a week it didn&#x2019;t change) <br /> <br /> - list of commands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert <br /> <br /> #Binary Data
  • - explain the setup process and &#x201C;automatically obtain settings&#x201D; from exchange server <br /> - Setting are sent to the device via a XML response from the server <br /> - queried public DNS <br /> <br /> AUSTRALIA: <br /> autodiscover.firevibe.com.au <br /> autodiscover.awm.gov.au <br /> autodiscover.brisbane.qld.gov.au <br /> autodiscover.childsafety.qld.gov.au <br /> autodiscover.bendigobank.com.au <br /> autodiscover.banks.com.au <br /> autodiscover.adelaidebank.com.au <br /> autodiscover.benbank.com.au <br /> autodiscover.msn.com <br /> autodiscover.three.com <br /> autodiscover.vodafone.com <br /> autodiscover.altmedia.net.au <br /> autodiscover.abc.net.au <br /> autodiscover.pblmedia.com.au <br /> autodiscover.yahoo.com.au <br /> <br /> NEW ZEALAND: <br /> autodiscover.savethekiwi.org.nz <br /> autodiscover.policy.net.nz <br /> autodiscover.powergenerators.net.nz <br /> autodiscover.newzealandnow.govt.nz <br /> autodiscover.nzalpa.org.nz <br /> autodiscover.caa.govt.nz <br /> autodiscover.otago.ac.nz <br /> autodiscover.auckland.ac.nz <br /> autodiscover.massey.ac.nz <br /> autodiscover.lincoln.ac.nz
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • list of autodiscover domains
  • - Attack one endpoint or the other or the traffic in between <br /> <br /> - SSL has copped a battering this year (wildcard ssl cert, reneg flaw), this talk isn&#x2019;t about that. The user still gets prompted about a dodgy SSL cert...in most cases. This talk is about the shitty implementation of security on the various clients. <br /> <br /> - port 443 is all we care about (maybe dns too!) <br /> <br /> - SSL cert - Moxie&#x2019;s wildcard SSL cert (firefox 2 except the certs without warning, firefox 3 won&#x2019;t prompt the user to accept the cert in default config) <br /> <br /> - proxy to pass, capture and replay traffic
  • Sniff Traffic - Pass on the traffic, while logging it. Use the creds to gain access to any other applications that are AD integrated such as Outlook Web Access or the internal domain through some other path (pysical access, wireless, etc.) <br /> Request Replay - Send emails (SPAM), retrieve emails, retreive attachments, search for contacts (mirror address book) <br /> Response Replay - Kill Response replay - explain - (central management function to deal with lost or stolen devices)
  • Overview of what is going to take place when executing kill command replay <br /> <br /> as we know the user can&#x2019;t be relied upon to decide if a cert is valid or not, especially when very little information is provided like on mobile devices <br /> <br /> so how to each of the platform react when presented with a wildcard ssl cert?
  • -in response to any request we reply with this...
  • -in response to any request we reply with this...
  • - can view cert details (cn name etc.) <br /> - default action is continue
  • - can view cert details (cn name etc.) <br /> - default action is continue
  • The user is only prompted once <br /> <br /> iPhone OS 2.1 doesn&#x2019;t prompt when presented with invalid cert
  • The user is only prompted once <br /> <br /> iPhone OS 2.1 doesn&#x2019;t prompt when presented with invalid cert
  • 0x80072F17 = Unsupported Digital Certificate installed. If you installed a digital certificate that supports wildcards from a certifying digital certificate provider, this certificate will install however using the certificate is not supported. <br /> <br /> - in reality this just means that the device won&#x2019;t accept the dodgy cert. <br /> - user isn&#x2019;t given the option to accept the cert
  • 0x80072F17 = Unsupported Digital Certificate installed. If you installed a digital certificate that supports wildcards from a certifying digital certificate provider, this certificate will install however using the certificate is not supported. <br /> <br /> - in reality this just means that the device won&#x2019;t accept the dodgy cert. <br /> - user isn&#x2019;t given the option to accept the cert
  • - the device is nuked <br /> - reset to factory state (everything is gone!!!) <br /> - your high scores on your driving game (gone!)
  • - ensure devices are secure adequately (jailbroken iphones, first person to exploit this was a dutch hacker charging 5 euros to fix it) <br /> - only windows mobile supports enforced encryption <br /> - so instead of vodafone.net.nz your APN would be some company name for example <br /> Device policy at a minimum: <br /> - Enforce device password is set to TRUE <br /> - Minimum password length is 7 characters <br /> - Alphanumeric passwords is enforced <br /> - Maximum password age is set to 90 days <br /> - Password history is set to 12 remembered <br /> - Account lockout threshold is set to 3 <br /> - Idle session timeout is set to 20 minutes
  • Pretty standard for web applications <br /> <br /> This way the user&#x2019;s credentials don&#x2019;t need to be sent to the server with each request.
  • 3G Micro Cells have recently become available to AT&T customers in the U.S. <br /> They cost US$149. <br /> How long before these are hacked and used to perform 3G MITM attacks? <br /> Kiwicon 2010 anyone? <br /> <br /> Are we going to have people sitting in airport lounges <br /> with micro cells, MITM 3G connections, exploiting SSL and sitting <br /> between cell phone users and their internet banking?

Transcript

  • 1. Mobile ActiveSync Russian Roulette Presented by Oliver “deathflu” Greiter assurance
  • 2. Assurance / Oliver Greiter Assurance = compliance { penetration testing/ethical “hacking”, review, audit }, wireless & mobility, UNIX/ Windows/network and security consulting/support Oliver = professional bio author and breaker of stuff assurance
  • 3. Exchange ActiveSync - Based on HTML and XML - Platforms with Exchange ActiveSync compatible client - Allows users to access their e-mail, calendar, contacts, and tasks stored on Exchange server - Cheaper solution to implement (at first glance) when compared to other solutions such as BlackBerry - “Good” way to encourage (enslave) users to check corporate email on their own time assurance
  • 4. Simple Diagram assurance
  • 5. Default security configuration - SSL transport layer protection (HTTPS) - Basic Auth - Device ID - “Enforced” Device Security Policy assurance
  • 6. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 7. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 8. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 9. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 10. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 11. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 12. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 13. Sample Sync Request POST /Microsoft-Server-ActiveSync?User=krudd&DeviceId=IMEI351878010074274 &DeviceType=IMEI351878010074274&Cmd=Sync HTTP/1.1 Host: autodiscover.dept.gov.au Accept-Encoding: gzip, deflate, x-gzip, identity; q=0.9 Accept-Language: en-us Authorization: Basic UE1ca3J1ZGQ6V2FsbGFiaWVzIQ== Expect: 100-continue User-Agent: NokiaE61i/2.09(158)MailforExchange Content-Type: application/vnd.ms-sync.wbxml MS-ASProtocolVersion: 12.1 X-MS-PolicyKey: 1799664318 Content-Length: 68 jEOK1643522697R5U50WX2EF1G3072[1 assurance
  • 14. autodiscover.{domain}.com Approximately 30% of “Top 500 domains”* had an autodiscover hostname in DNS *http://www.seomoz.org/top500 assurance
  • 15. assurance
  • 16. assurance
  • 17. MITM Attack ARP spoof? DNS poisoning? Fake WiFi Hotspot? Port re-direction? assurance
  • 18. MITM Fun Sniff Traffic - Emails, Contacts, Notes, User credentials (AD domain) Client Request Replay - Generate your own requests and replay them to the server Server Response Replay - Generate your own responses and replay them to the client assurance
  • 19. Kill Command Replay assurance
  • 20. Sample kill response HTTP/1.1 449 Retry after sending a PROVISION command Connection: Keep-Alive Date: Fri, 20 Nov 2009 22:29:31 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 MS-Server-ActiveSync: 8.1 X-Powered-By: ASP.NET Content-Encoding: gzip Vary: Accept-Encoding Content-Length: 70 ã …HUH.-.…œUH-* /R»ÕO)ÕIUH…O-V»À/Q(JMŒOœÀ¨JU(…»,Ü(“Á‘…n6 assurance
  • 21. Sample kill response HTTP/1.1 449 Retry after sending a PROVISION command Connection: Keep-Alive Date: Fri, 20 Nov 2009 22:29:31 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 MS-Server-ActiveSync: 8.1 X-Powered-By: ASP.NET Content-Encoding: gzip Vary: Accept-Encoding Content-Length: 70 ã …HUH.-.…œUH-* /R»ÕO)ÕIUH…O-V»À/Q(JMŒOœÀ¨JU(…»,Ü(“Á‘…n6 assurance
  • 22. Sample kill response HTTP/1.1 449 Retry after sending a PROVISION command Connection: Keep-Alive Date: Fri, 20 Nov 2009 22:29:31 GMT Content-Type: text/html Server: Microsoft-IIS/6.0 Cache-Control: private X-AspNet-Version: 2.0.50727 MS-Server-ActiveSync: 8.1 X-Powered-By: ASP.NET Content-Encoding: gzip Vary: Accept-Encoding Content-Length: 70 ã …HUH.-.…œUH-* /R»ÕO)ÕIUH…O-V»À/Q(JMŒOœÀ¨JU(…»,Ü(“Á‘…n6 assurance
  • 23. Symbian OS Nokia N95 Mail for Exchange v2.9.158 assurance
  • 24. Symbian OS Nokia N95 Mail for Exchange v2.9.158 assurance
  • 25. iPhone OS iPhone 3G iPhone OS v3.1.2 assurance
  • 26. iPhone OS iPhone 3G iPhone OS v3.1.2 assurance
  • 27. Windows Mobile 6.1 Dell AXIM X51v PDA Windows Mobile 6.1 assurance
  • 28. Windows Mobile 6.1 Dell AXIM X51v PDA Windows Mobile 6.1 assurance
  • 29. What just happened? assurance
  • 30. In an ideal world... - Valid SSL Certificate on server - Unique Client Certificate on each device - Device (and storage card) encryption - Access to restricted to private Cell Network Access Point Name (APN) - HTTP Digest authentication - Exchange ActiveSync domain segregation - User education assurance
  • 31. Application Improvement How about introducing session management as a default component of the application? assurance
  • 32. Where to from here? 3G MITM Attacks? assurance
  • 33. Danke - y011 - kiwicon crüe assurance
  • 34. Questions? oliver.greiter@assurance.com.au assurance