Log in

View Full Version : SMS Vulnerability For GSM Phones


Ed Hansberry
08-05-2009, 09:30 AM
<div class='os_post_top_link'><a href='http://arstechnica.com/apple/news/2009/07/iphonegsm-phones-vulnerable-to-sms-hacks-patch-coming-soon.ars' target='_blank'>http://arstechnica.com/apple/news/2...coming-soon.ars</a><br /><br /></div><p><em>"Demonstrations at the Black Hat computer security conference revealed that smartphones based on iPhone OS, Android, and Windows Mobile are indeed vulnerable to hacking via SMS messages. Those aren't the only phones that are vulnerable, though, and security experts are working with mobile carriers and handset vendors to patch the problem."</em></p><p>It looks like a general security breach in how almost all phones handle SMS. I'll be curious to see what patch is necessary and how far back Microsoft and their partners will go to fix the problem. My guess is, WinMo 5 devices won't get any on-device fix. We'll see. Because it involves the way SMS messages are crafted, it is possible the network could be modified to detect and trap the messages rather than allowing them to make it to your phone.</p>

TOCA
08-05-2009, 11:00 AM
Yet an other Proof of Concept, but how serious is this, how deep can they hack it, and how scarred do we need to make the general public.

Can it be hacked into an expensive paperweight, or does it give the hacker the full controll and/or full access to the content, or are they "only" able to leave stupid messages on the display?

Do the hacker need some special equipment, or is it doable from any PC or even handheld devices?

BevHoward
08-05-2009, 06:12 PM
The registry dwords under the key HKLM\Security\Policies\Policies noted in the article at http://www.silentservices.de/adv01-2008.html don't exist in the (old) PDA2k

Anyone know if they should be added or is the general lack of entries in the key a factor?

Beverly Howard

T_Scheen
08-06-2009, 10:57 AM
Well, the registry entries on my FSC Loox T830 (WM5.0) were set unsafe.
I directly corrected them according to the article. Many thanks for the tip !!