Switch to Linear ModeSwitch to Hybrid ModeSwitch to Threaded Mode
Printer Friendly View | Email this page | Register Now to start posting!
eventer Registered User


Join Date: Nov 2008
Posts: 3,328
Trade rep: 0 (0%)
Infractions: 0/0 (0)
SMS, iPhone, Android Under Attack at Black Hat eventer Jul 31st, 09, 01:00 PM #1



Quote:
LAS VEGAS – SMS is a standard feature on hundreds of millions of phone globally and according to a series of researchers it's also insecure. At the Black Hat security conference, multiple researchers took the stage to detail how they were able to use to take over a users phone by way of a simple SMS message. Researchers Zane Lackey and Luis Miras took specific aim at the carrier side of the problem while Charlie Miller and Collin Mulliner took aim at the iPhone itself. "The cool thing is that you only need the phone number in order to start your attacks," Miller told the audience.

Both sets of researchers began their talks by explaining how the SMS system generally works and why it is an attractive target for security research. An SMS message gets to an end-user eventually, even if they're not currently on their phone, it will show up when the user starts their phone. Miller said he informed Apple of the flaw in late June and demonstrated today with a live phone in the audience that the iPhone attack works today. An Apple spokesperson wasn't immediately available for comment. The flaw enabled Miller and Mulliner to perform a denial of service attack on the user's iPhone after the user received an initial text message.
....
SMS, iPhone, Android Under Attack at Black Hat - InternetNews.com


sg.png
Lyfeforce
Lyfeforce's Avatar
Abolisher of E|ektronics


Join Date: Mar 2007
Location: Tampines
Posts: 3,627
Trade rep: 2 (100%)
Infractions: 0/0 (0)
Lyfeforce Jul 31st, 09, 02:23 PM #2
In the last paragraph:

Quote:
"Do not try this at home," Miras said. "This is a carrier issue, we disclosed to them and they are working on a fix – and the flaw will probably work for a while. Carriers are monitoring their subscribers and they are looking for this."
A blade cuts both ways. So why take the risk? Stab instead.



sg.png
babybearbear
babybearbear's Avatar
Registered User


Join Date: Jan 2009
Posts: 3,288
Trade rep: 0 (0%)
Infractions: 0/0 (0)
babybearbear Jul 31st, 09, 06:45 PM #3
Quote:
Originally Posted by Lyfeforce View Post
In the last paragraph:
So we no need to switch of our iPhone until a patch is out?
sg.png
babybearbear
babybearbear's Avatar
Registered User


Join Date: Jan 2009
Posts: 3,288
Trade rep: 0 (0%)
Infractions: 0/0 (0)
babybearbear Aug 1st, 09, 10:06 PM #4
iPhone patch is out Apple Releases iPhone OS 3.0.1 to Address SMS Security Vulnerability - Mac Rumors
sg.png
Lyfeforce
Lyfeforce's Avatar
Abolisher of E|ektronics


Join Date: Mar 2007
Location: Tampines
Posts: 3,627
Trade rep: 2 (100%)
Infractions: 0/0 (0)
Lyfeforce Aug 2nd, 09, 01:15 PM #5
Apple developers are kinda slow, aren't they? -_-"
A blade cuts both ways. So why take the risk? Stab instead.



sg.png
New Thread | ↑↓ Similar Threads
Similar Threads Thread Starter Forum Replies Last Post
Ah Beng Newsroom 13 Feb 23rd, 09
04:00 AM
bigsale News around the web! 2 Oct 24th, 06
02:54 PM
Thread Tools Display Modes
Linear Mode Linear Mode