1. xkarel's Avatar
    Hi, my Classic running 10.3.2.2886 is listening on port 443 TCP and accepts incoming SSL connections. There is a weird self-signed certificate with following subject matching wireless MAC address in XX :

    Research In Motion Limited, CN = PlayBook: XX:XX:XX:XX:XX:XX

    Web server accepts just incoming TLS 1.0 connections.

    What's that and how to get rid of it? Phone is not attached to any Enterprise service and nor debug/devel mode is enabled.

    Thanks!

    Karel

    P.S. I've posted this on official BB forums with no response
    BallRockReaper likes this.
    07-17-16 04:01 PM
  2. Morten's Avatar
    I nelieve that is the port Blackberry use for their blackberry services/UDS etc - to keep the device connected with blackberry

    Dont think you can block the port on the device itself - doit on your router if yo have concerns
    07-17-16 05:27 PM
  3. Richard Buckley's Avatar
    I haven't looked at this myself, but most SoHo or consumer routers would block incoming connections to port 443, unless UPnP has turned it on. I disable UPnP on all my routers and haven't noticed any lack of functionality. No, I would suspect it is for Blend. If I have time I will look into it tonight.

    LeapSTR100-2/10.3.2.2876
    07-17-16 06:11 PM
  4. rockitnyc's Avatar
    I believe that is the certificate created by BlackBerry Bridge for authentication when connectting to a PlayBook tablet which shares services and media between the two devices.

    Posted via CB10
    BallRockReaper likes this.
    07-19-16 12:04 AM
  5. xkarel's Avatar
    Hi, thanks for responses. I never installed anything like BlackBerry Bridge or PlayBook related things.

    nmap scanner tool is identifying that as:
    443/tcp open ssl/http Blackberry Universal Device Service

    Also it was never attached to any BlackBerry enterprise server software.

    Any hints how to get rid of that? Wondering why should my device run HTTPS server, especially with some insecure crypto settings ...

    How can I start investigation on QNX shell? I've been using BGShellPlus tool for SSH - that one has QNX shell however netstat version in use doesn't reveal PID and also shell session is not privileged enough.

    Thanks!
    08-05-16 02:43 PM
  6. yessuz's Avatar
    U do not need BlackBerry enterprise services in order to utilise this service.

    See the nice 4 dot BlackBerry logo near the network connection indicator on the screen?
    There u have it

    Posted via CB10
    rthonpm likes this.
    08-06-16 08:39 AM
  7. xkarel's Avatar
    OK. However why would there need to be any service accepting inbound connections to handset? There is usually NAT between the handset and Internet services. Everything works without technologies allowing connections from outside to device subjected to NAT.

    Remember qconnDoor remote root vulnerability - that's btw. another concern of mine as that service is accepting connections to port 4455 TCP without enabled debug mode.

    Does anyone care about serious lock-down of the device from networking perspective?

    Thanks!
    08-06-16 11:39 AM
  8. rthonpm's Avatar
    It's a necessary connection for the handset. It's no different than an Android handset needing a connection back to Google, or an iOS device needing to poll Apple servers. Why make a mountain out of a molehill, or overthink the situation?

    Posted via CB10
    Farzeen25 likes this.
    08-07-16 04:52 PM
  9. gariac's Avatar
    Hi, my Classic running 10.3.2.2886 is listening on port 443 TCP and accepts incoming SSL connections. There is a weird self-signed certificate with following subject matching wireless MAC address in XX :

    Research In Motion Limited, CN = PlayBook: XX:XX:XX:XX:XX:XX

    Web server accepts just incoming TLS 1.0 connections.

    What's that and how to get rid of it? Phone is not attached to any Enterprise service and nor debug/devel mode is enabled.

    Thanks!

    Karel

    P.S. I've posted this on official BB forums with no response
    Is this on the USB port?

    Posted via CB10
    08-12-16 01:55 AM
  10. Farzeen25's Avatar
    It's a necessary connection for the handset. It's no different than an Android handset needing a connection back to Google, or an iOS device needing to poll Apple servers. Why make a mountain out of a molehill, or overthink the situation?

    Posted via CB10
    So true, I think the OP is over reacting to this situation! Stay calm brotha. You have a secure device at your disposal.

    Posted via CB10
    08-12-16 04:10 AM
  11. tipplex's Avatar
    Create a ticket @ BlackBerry

    Posted via CB10
    08-12-16 04:16 AM
  12. xkarel's Avatar
    Ok, will take this path. There are some people here who don't understand the difference between outbound connecting to BB services and listening sockets on their handsets.

    Btw. with a little effort the 443 TLS 1.0 service presenting Playbook certificate can be shot down. There is some apparent bug. TCP 4455 doesn't seem to have any limits and when you flood it a little it's ACKing nicely. Resulting in CPU load and battery drain at minimum. What a mess....
    08-17-16 08:08 AM
  13. Superdupont 2_0's Avatar
    Ok, will take this path. There are some people here who don't understand the difference between outbound connecting to BB services and listening sockets on their handsets.

    Btw. with a little effort the 443 TLS 1.0 service presenting Playbook certificate can be shot down. There is some apparent bug. TCP 4455 doesn't seem to have any limits and when you flood it a little it's ACKing nicely. Resulting in CPU load and battery drain at minimum. What a mess....
    Could it have something to do with video call?

    The PlayBook has an app for video calls.

    I can make video calls from the PlayBook to
    a) other PlayBooks and to
    b) BBM on BB10 devices

    and normally it worked also for video calls from BBM (on BB10) to the PlayBook.

    It is actually a very nice feature.

    However, I speculate this feature only works if the device is listening for any incoming calls from PlayBooks.
    08-18-16 03:08 AM

Similar Threads

  1. plus-net server emails on to BB Q10
    By Maggiedd in forum BlackBerry Q10
    Replies: 1
    Last Post: 07-18-16, 01:52 PM
  2. Why can't I change time and date on my 9720?
    By CrackBerry Question in forum Ask a Question
    Replies: 1
    Last Post: 07-17-16, 07:47 PM
  3. How to I activate 4g on my z10
    By samyag Shah in forum Ask a Question
    Replies: 2
    Last Post: 07-17-16, 02:06 PM
  4. Replies: 1
    Last Post: 07-17-16, 01:21 PM
LINK TO POST COPIED TO CLIPBOARD