Feeds

The SMS of DEATH - Can it crash your phone?

Bog standard mobes menaced by evil txt

Remote control for virtualized desktops

Many mainstream mobiles can be crashed after opening a maliciously constructed SMS message.

The so-called 'SMS of death' attacks affects mobiles from Samsung, Sony Ericsson, Motorola and LG, among others. Details of the attack, a variant of earlier attacks along the same lines, were outlined by security researchers Collin Mulliner and Nico Golde during a presentation at the Chaos Communication Congress (27C3) in Berlin.

Mulliner and Golde tested a range of feature phone for bugs in supported Java apps used to display business cards, support longer texts sent in one than one part or other features. Crashing any particular application on a phone tends to crash the phone or force its disconnection from a mobile network. The researchers set up a test bed before sending thousands of malformed messages to each device and recording the effects, if any.

Golde said that Samsung mobiles were particularly vulnerable to multi-part text messages, for example. LG phones were often bowled over by maliciously constructed MMS messages. Nokia and Sony Ericsson phones often crashed before confirming the receipt of a rogue text. This means that the network attempts to resend a killer text after a user reboots a crashed mobile. Restoring normality involves transferring a SIM card onto a non-vulnerable phone and deleting the poison pill text message.

The range of flaws ought to concern network operators as well as handset manufacturers. Mulliner said that by sending a range of attacks a miscreant might create a situation where thousands of users attempt to reconnect with the network at around the same time, straining network infrastructure and possibly causing secondary (possibly cascading) problems. Targeting attacks against a particular individual - providing it was known which model of phone he was using - might also be possible.

A lot of effort in security circles over recent months has gone into discovering flaws in Android, iPhone and other smartphones by 84 per cent of phone in use are less advanced feature phones. The two security researchers hope their research will help address this knowledge imbalance.

Both researchers called for suppliers to increase the frequency of security updates as well as making updates easier to apply. ®

Internet Security Threat Report 2014

More from The Register

next story
Broadband sellers in the UK are UP TO no good, says Which?
Speedy network claims only apply to 10% of customers
YOU are the threat: True confessions of real-life sysadmins
Who will save the systems from the men and women who save the systems from you?
Virgin Media struck dumb by NATIONWIDE packet loss balls-up
Turning it off and on again fixes glitch 12 HOURS LATER
Facebook, working on Facebook at Work, works on Facebook. At Work
You don't want your cat or drunk pics at the office
Soz, web devs: Google snatches its Wallet off the table
Killing off web service in 3 months... but app-happy bonkers are fine
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Simplify SSL certificate management across the enterprise
Simple steps to take control of SSL across the enterprise, and recommendations for a management platform for full visibility and single-point of control for these Certificates.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.