<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet href="http://blogs.forum.nokia.com/styles/rss.css" type="text/css"?>
<rdf:RDF
 xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
 xmlns="http://purl.org/rss/1.0/"
 xmlns:dc="http://purl.org/dc/elements/1.1/"
>
 <channel rdf:about="http://blogs.forum.nokia.com/rss.php?profile=rss10&amp;op=ArticleComments&amp;postId=">
  <title>Gabor Torok's Forum Nokia Blog - Mobile worm, Yxes.A - an analysis</title>
  <description>Forum Nokia Blogs</description>
  <link>http://blogs.forum.nokia.com/summary.php</link>
  <items>
    <rdf:Seq>
                          
      <rdf:li rdf:resource="http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24869" />
                          
      <rdf:li rdf:resource="http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24809" />
        </rdf:Seq>
  </items> 
 </channel>
                
  <item rdf:about="http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24869">
   <title></title>
   <dc:title></dc:title>
   <description>&lt;p&gt;1) Actually Mark they are even more stupid than what you believe... :D&lt;br /&gt;
There are some sites (eg. http://cer.s603rd.cn/) which purpose is to create and distribuite DevCert to the users...&lt;br /&gt;
The main problem with this practice is that they have to distribute also the PRIVATE KEY (.key file) in order to allow users to use the DevCert.&lt;br /&gt;
With a simple search on TrustCerter database is then possible to obtain the PublisherID and then proceed with the ExpressSigned certification.&lt;/p&gt;
</description>
   <link>http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24869</link>
      <dc:date>2009-02-24T00:18:45Z</dc:date>
   <dc:creator>ilsocio</dc:creator>
  </item>
                
  <item rdf:about="http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24809">
   <title>A very interesting test case...</title>
   <dc:title>A very interesting test case...</dc:title>
   <description>&lt;p&gt;Given our recent discussion of the merits of Publisher IDs, this makes an interesting test case.&lt;/p&gt;
&lt;p&gt;1) I&#039;d love to find out where the Publisher ID that was used for signing this application can be traced to - I very much doubt there is any obvious connection to the author or any cyber criminals - they&#039;re just not that stupid.  If they managed to do this once, surely they can do it again, and so can others...&lt;/p&gt;
&lt;p&gt;2) I agree about OCSP checking but I think you&#039;ll find there&#039;s more than just enabling the feature in phones missing.  As with most PKI stuff, the idea is good in theory but it doesn&#039;t work in practice.&lt;/p&gt;
&lt;p&gt;3) Possibly this is 3rd Edition only and is using the old PlatSec exploits to escalate its capabilities.  The example of an FP1 phone given in the report is the N73, which is plain 3rd Edition MR.&lt;/p&gt;
&lt;p&gt;Mark&lt;/p&gt;
</description>
   <link>http://blogs.forum.nokia.com/blog/gabor-toroks-forum-nokia-blog/2009/02/20/mobile-worm-yxes.a-an-analysis#comment24809</link>
      <dc:date>2009-02-20T14:52:04Z</dc:date>
   <dc:creator>Sorcery-ltd</dc:creator>
  </item>
  </rdf:RDF>