Note: SOTI has fixed this security
issue in v5.05
Airscanner Mobile Security Advisory: Remote “Hard Reset” Data Wipe and DoS of Pocket Controller v5.00 (#AS05080401)
Date of discovery: August 4, 2005
Product:
Pocket Controller-Professional V5.00 (fixed
in v5.05)
Platform:
Windows Mobile .NET, Windows Mobile Pocket PC, Windows Mobile 5.0
Requirements:
Windows Mobile
Credits:
Jonathan Read (CISSP) and Seth Fogie
Airscanner Mobile Security
http://airscanner.com/security/www.airscanner.com
Mobile Antivirus Researcher's Association
http://www.mobileav.org/
Severity:
Medium to High since any PDA running the application can be “hard
reset” (up to complete loss of all data and installed applications)
using a remote connection. This vulnerability can also be exploited
over a wireless connection.
Summary:
Pocket Controller Professional is a popular, powerful remote control
and management program that allows a user to remotely control a PDA
from their PC computer. See http://www.soti.net/ for more information.
Several feature of this program is that it can remotely turn off,
reboot, and reset the PDA. We discovered that these commands can be
performed without the client program sending only three packets to the
target PDA.
Details:
Connect to port 5492 on PDA that is running the target client program.
First send an initialization packet to the PDA. Next send a packet
containing the desired command (turn off, reboot, hard reset) to the
PDA. Finally, create a new socket and reset the intitialization packet.
Upon receipt, the PDA will perform the selected function. PoC is
available for MARA members.
Workaround:
No work around available.
Initial Vendor Notification: August 4, 2005
Initial Vendor Response:Vendor corrected problem. SOTI has fxed this security
issue in v5.05. Please upgrade.
Legal:
Copyright (c) 2005 Airscanner Corp.
Permission is granted for the redistribution of this alert electronically. It may not be edited in any way without the express written consent of Airscanner Corp. If you wish to reprint the whole or any part of this alert in any other medium other than electronically, please contact Airscanner Corp. for permission.
Disclaimer: The information in the advisory is believed to be
accurate at the time of publishing based on currently available
information. Use of the information constitutes acceptance for use on
an AS IS condition. There are no warranties with regard to this
information. Neither the author nor the publisher accepts any liability
for any direct, indirect, or consequential loss or damage arising from
use of, or reliance on, this information.