
Attack Surface Analysis of BlackBerry Devices
Backdoor
Worm
PIM Data (Personal Information Manager Data)
The PIM Database stores Contacts, Events, and To-Do lists. The table below outlines some of the informa-
tion these lists contain:
Table compiled from reading RIM API documentation.
5
The data outlined above can only be read, modified, and deleted by a signed application via the packages
javax.microedition.pim and net.rim.blackberry.api.pdap.
24
IT Policy
Application Controls "Message Access" = Not Permitted
Device Firewall Block Incoming Messages > BlackBerry Internet Service = Ticked
Application Permissions User Data > Email = Deny
Other Device Settings
IT Policy "Disallow Third Party Application Download " = True
Application Controls "Message Access" = Not Permitted
Device Firewall Block Incoming Messages > BlackBerry Internet Service = Ticked
Application Permissions User Data > Email = Deny
Other Device Settings
Contacts Events To-Do's
Name Alarm Confidential
Title Busy Private
Organisation Free Public
Address Out Of Office Completed
Telephone Number Start Completion Date
Email Address End Due
Notes Location Note
BlackBerry PIN Attendees Priority
User Defined Fields Confidential Revision
Private Summary
Public
Note
Revision
Summary
Commenti su questo manuale