Feeds

Nexus phones carry SMS crash bug vuln

You have 1 new message: You've been p0wned

Intelligent flash storage arrays

A Romanian security researcher has published a vulnerability that allows someone to crash a remote Nexus 4 or Nexus 5 phone – by sending them a crafted “Class 0” text message.

Instead of falling into a user's inbox and waiting for someone to read the message, a Class 0 or “flash message” pops up immediately as a message window that the user is supposed to decide whether or not to save.

On the Nexus phones, according to Levi9's Bogdan Alecu, the flash message is displayed above all active windows, with a semi-transparent overlay dimming them.

The bug that turns this into a vulnerability is this: Nexus 4 and Nexus 5 don't give audio notifications of incoming flash messages. So an attacker can pile message upon message on a victim until the phone begins to misbehave.

In this presentation to DefCamp 2013, Alecu identified various impacts of an attack in which more than 30 messages are sent to a target: either the messaging application crashes, or the phone reboots, or Internet access collapses.

If the victim's phone has SIM PIN-protection enabled, the phone will stop responding to the network.

Class Zero Attack

Alecu complains that Google has known of the flax for more than a year with no fix announced. In the absence of an official fix, he points to this app, which is designed to act as a firewall against Class 0 messages. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
BlackEnergy crimeware coursing through US control systems
US CERT says three flavours of control kit are under attack
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
Protecting against web application threats using SSL
SSL encryption can protect server‐to‐server communications, client devices, cloud resources, and other endpoints in order to help prevent the risk of data loss and losing customer trust.