Wii, cellphone net surfers face attack risk: researcher
Last Updated: Monday, April 23, 2007 | 4:18 PM ET
CBC News
Related
External Links
(Note: CBC does not endorse and is not responsible for the content of external sites - links will open in new window)
People who surf the internet with Nintendo's Wii video game console or on some cellphones may risk seeing their devices crashing or being hijacked, security experts say.
According to researchers at security software company McAfee Inc., the potential problem stems from a flaw in versions of the Opera web browser that may be in use on the Wii or come preinstalled on some cellphones, or that are available as a free download from Opera Software ASA of Oslo, Norway.
"Don't worry — your Wii is not in grave danger," David Rayhawk wrote in a cautionary note posted to the security firm's McAfee Avert Labs blog on Friday.
| Net security jargon |
|---|
|
BOTNETS are networks of computers that have been hijacked by malicious groups or individuals to do their bidding. Their owners are usually unwitting victims who have no idea their machines have been infected and turned into so-called zombies. Botnet operators often rent time or bandwidth on their networks to spam e-mail marketers and phishing scam artists. MALWARE is a catch-all term for malicious software such as computer viruses, spyware and so on that compromise the security or function of people's computers. Phishing is a technique in which criminals try to trick people into disclosing sensitive information such as online banking names and passwords and is often conducted through e-mails. TROJANS are programs that appear to perform one function in order to hide a malicious one. Like the mythological Trojan horse such programs are named after, the deception tricks people into granting them access to a computer. ZOMBIES are computers that have been hijacked by attackers to perform commands and functions issued to them, often without the owners' knowledge. They are typically infected by Trojans that enable attackers to use them in a botnet, which are used to distribute spam phishing e-mails, or viruses and Trojans that let them hijack other computers. An infected computer is sometimes referred to as a bot — short for robot. |
The security vulnerability in versions of the Opera browser prior to version 9.10 stems from the way in which the software handles specially crafted or corrupted JPEG images. The problem can cause the program to crash, exposing machines running an unpatched version of Opera to attack.
The risk to the Wii is only found in the original or trial version of the console's Internet Channel that was available before April 12, according to Rayhawk.
Although there are no confirmed reports of people's Wii consoles being taken over in this manner, the exploit is similar to ones used on desktop and laptop computers that can allow an attacker to gain control of a machine and remotely run software used in phishing scams or botnets, for example.
"Folks that have downloaded the original Internet Channel for the Wii have this vulnerability," he wrote. "That means it's theoretically possible to run malcode — and according to the hacker conversations they are trying hard to do exactly that."
Rayhawk explained that the console's browsing software can only be updated manually and that users should do so as soon as possible.
But the risk doesn't end there, he said, noting that McAfee researchers were able to use the vulnerability to successfully crash the browser on cellphones running Opera.
Opera may come pre-installed on some Nokia and Kyocera cellphones. Versions of the browser are also available for phones that run on the Symbian Series 60, Microsoft Corp.'s Windows Mobile, and the UIQ operating systems.
Nokia cellphones run on Series 60, while Windows Mobile is used on Motorola Inc.'s Q, Palm's Treo 700wx and other devices, and UIQ handsets include phones by Motorola and Sony-Ericsson.
No phones offered by Rogers Wireless or Bell Mobility come with Opera pre-installed, company spokespeople told CBC News Online. Spokespeople for Telus did not immediately respond to CBC's inquiry.
An Opera spokeswoman told CBC News Online that the company was looking into the matter.
CBC News Online was not immediately able to reach Nintendo spokespeople.
Share Tools
Top News Headlines
- Rescue attempt over for New Brunswick fishermen
- The rescue attempt for two missing fishermen has been called off in New Brunswick, hours after one body was found. more »
- Car drives into crowd at Virginia parade
- About 50 to 60 people were injured after a driver described by witnesses as an elderly man drove his car into a group of hikers marching in a parade in a small Virginia mountain town. more »
- Spectator killed at Edmonton Jeep event
- A 20-year-old woman died Saturday during an event for Jeep enthusiasts held in a parking lot just west of downtown Edmonton. more »
- Astronaut Chris Hadfield adjusts to 'earthling' life
- Canada's space ambassador, Chris Hadfield, is still readapting to life on this planet after spending 146 days in zero gravity as commander of the International Space Station. For now, though, he's taking his homecoming one step at a time. more »
Must Watch
Latest Technology & Science News Headlines
- High Arctic research station saved by new funding
- Canada's northernmost research lab won't have to shut down after all and will be able to resume year-round operations, with the help of a new grant from the federal government. more »
- 2 earthquakes felt in Ontario and Quebec
- Two earthquakes near the Ontario-Quebec border could be felt across both provinces this morning. more »
- Chris Hadfield's translator: Q&A with Canadian astronaut Jeremy Hansen
- While Chris Hadfield was returning from the International Space Station on Monday night, another Canadian astronaut was offering his own unique play-by-play of the action as the Soyuz capsule plunged to Earth. more »
- Why some Canadians want to die on Mars
- More than 80,000 people have applied for a Dutch non-profit organization's proposed one-way trip to Mars. Anna Maria Tremonti, host of The Current, spoke to four Canadians — two Mars one applicants, a member of the Mars One team, and astronaut Julie Payette — about whether it's a good idea. more »
Bob McDonald's Blog
Chris Hadfield: The gravity of gravity May. 17, 2013 9:58 AM After five months of being Superman and a media superstar, Canadian astronaut Chris Hadfield is now beginning the challenging task of adapting his mortal body and brain to life back on Earth.
Quirks & Quarks
- May 18: Apps for Apes May. 17, 2013 4:26 PM Scientists at more than 2 dozen zoos around the world, including the Toronto Zoo, have been using computer tablets to stimulate our bright orange primate cousins, the orangutans. And the orangutans have been loving it.
Latest Features
- Spectator killed at Edmonton Jeep event
- Car drives into crowd at Virginia parade
- Toronto Mayor Rob Ford cancels weekly radio show
- Winning ticket sold in Florida for $590M Powerball jackpot
- Rescue attempt over for New Brunswick fishermen
- Email is proof Senate greenlit expenses, Brazeau says
- Astronaut Chris Hadfield adjusts to 'earthling' life
- 1 person hurt after trains collide near Medicine Hat
- Afghan legislators block law protecting women

