Advertisement
Promo

Mobile devices Toolkit

Mobile phone vulnerable to DoS attack

Patrick Gray ZDNet Australia

Published: 26 Feb 2003 14:23 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

US-based security company @stake has released a security advisory detailing a Denial of Service (DoS) vulnerability in the Nokia 6210 GSM mobile phone, and although the flaw isn't serious it could be a sign of worse things to come.

The advisory, posted to the bugtraq security mailing list, describes how a prankster could use the vulnerability to crash a potential victim's phone.

"There is a vulnerability which allows an attacker to send a malicious vCard to a handset, causing (it) to crash," the advisory said.

If an attacker has been successful in crafting the malicious vCard and sending it to the handset, the phone may behave strangely, freeze or stop accepting vCards.

"This is a good example of why all newly introduced product functionality should be reviewed to ensure that no new security vulnerabilities are introduced. A cursory source code audit would find an error of this type," the advisory said.

The vulnerability is not serious -- affected users can simply "reboot" their phones, but the flaw has sparked renewed interest in the issue of security vulnerabilities in increasingly complicated mobile phones.

Even though similar vulnerabilities have been found in the past, the increasing complexity in mobile handsets means this latest discovery is more relevant than ever, according to John Papandriopoulos, a Melbourne based wireless communications researcher.

"As these handsets get more complex, it's hard to have no faults at all," he told ZDNet Australia.

"I think the number of (exploits) will increase over time," he added.

Papandriopoulos says that current generation handsets are not necessarily a popular target because there's little that can be done even if an attacker is able to compromise them.

"I think it's more likely that the motivation would be to inconvenience people," he said.

As for a mobile phone worm, spreading by sending itself to phonebook entries, John says this isn't likely to happen for some time.

"At this stage, that's not realistic, but who knows in five years' time?" he said.

However as standardised client software becomes a feature on mobile handsets it's only a matter of time before malicious hackers start paying more attention to wireless worms, according to Sydney-based security consultant Daniel Lewkovitz.

"The wider the deployment of any given software, the proportionally larger attention certain people pay to breaking it," Lewkovitz said.

Lewkovitz also says that the rush to get wireless software into the marketplace may result in deficient security testing regimes being passed off as acceptable.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
61 out of 104 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Ion-toting Eee 1201N to hit UK in Janu...

Asus has confirmed its long-rumoured Eee PC 1201N, the first in the company's line of netbooks to use Nvidia's Ion graphics platform. The 1201N will also be one of the first netbooks... More

2 comments

WorkSnug for iPhone now available

A little while ago I blogged about an iPhone application called WorkSnug. It is a free tool that finds public Wi-Fi locations in London and uses augmented reality to display them... More

Post a comment

Toshiba TG01 running Windows Mobile 6....

When we first saw the TG01 from Toshiba we were both delighted and displeased. There was a lot to like, but Toshiba’s cranky front end to its operating system Windows Mobile 6.1 Professional... More

Post a comment

Discussions

roger andre roger andre

The importance of copyleft

Sunday 22 November 2009, 11:16 PM

1 comment
hkommedal hkommedal

I have this funny feeling that Goebbel...

Saturday 21 November 2009, 10:45 PM

2 comments
Simon Bisson and Mary Branscombe Simon Bisson and Mary Branscombe

indeed

Saturday 21 November 2009, 7:26 PM

9 comments
mdgreaney mdgreaney

From a resident

Saturday 21 November 2009, 7:23 PM

4 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters