The Register® — Biting the hand that feeds IT

Feeds

The SMS of DEATH - Can it crash your phone?

Bog standard mobes menaced by evil txt

Cloud storage: Lower cost and increase uptime

Many mainstream mobiles can be crashed after opening a maliciously constructed SMS message.

The so-called 'SMS of death' attacks affects mobiles from Samsung, Sony Ericsson, Motorola and LG, among others. Details of the attack, a variant of earlier attacks along the same lines, were outlined by security researchers Collin Mulliner and Nico Golde during a presentation at the Chaos Communication Congress (27C3) in Berlin.

Mulliner and Golde tested a range of feature phone for bugs in supported Java apps used to display business cards, support longer texts sent in one than one part or other features. Crashing any particular application on a phone tends to crash the phone or force its disconnection from a mobile network. The researchers set up a test bed before sending thousands of malformed messages to each device and recording the effects, if any.

Golde said that Samsung mobiles were particularly vulnerable to multi-part text messages, for example. LG phones were often bowled over by maliciously constructed MMS messages. Nokia and Sony Ericsson phones often crashed before confirming the receipt of a rogue text. This means that the network attempts to resend a killer text after a user reboots a crashed mobile. Restoring normality involves transferring a SIM card onto a non-vulnerable phone and deleting the poison pill text message.

The range of flaws ought to concern network operators as well as handset manufacturers. Mulliner said that by sending a range of attacks a miscreant might create a situation where thousands of users attempt to reconnect with the network at around the same time, straining network infrastructure and possibly causing secondary (possibly cascading) problems. Targeting attacks against a particular individual - providing it was known which model of phone he was using - might also be possible.

A lot of effort in security circles over recent months has gone into discovering flaws in Android, iPhone and other smartphones by 84 per cent of phone in use are less advanced feature phones. The two security researchers hope their research will help address this knowledge imbalance.

Both researchers called for suppliers to increase the frequency of security updates as well as making updates easier to apply. ®

SaaS data loss: The problem you didn’t know you had

Nothing new here

"Many mainstream mobiles can be crashed after opening a maliciously constructed SMS message."

Well, I managed to crash my Sony-Ericsson cheapo phone by sending it a slightly-wrongly (not maliciously) constructed SMS. Only moving the SIM card to another phone, then clearing out the message brought relief.

Companies should really stop using stressed-out underpaid monkeys to write protocol code.

6
0
Anonymous Coward

Crash a Smartphone

I've got an iPhone 3GS.

I don't need to receive a malicious crafted SMS message to make it crash. Just use it to make a phonecall and it'll crash within 3 minutes.

I think it might be a feature to stop people running up huge call bills.

9
4
Anonymous Coward

A title is required

Is it just me that thinks "a dodgy translator" sounds like someone you could have a lot of fun with?

3
0

More from The Register

1,000 O2 staff chose redundancy over Capita
Betrayal, or just decent terms?
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
Now you can use your phone instead of your wallet at the ATM, too
Blimey, these little paper towels out of the vending machine are really expensive
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?
 breaking news
White Space wonga time: White House tips $100m into next-gen comms
Empty frequencies right place for tomorrow's mics, phones and fridges