ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile devices Toolkit

Mobile phone vulnerable to DoS attack

Patrick Gray ZDNet Australia

Published: 26 Feb 2003 14:23 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

US-based security company @stake has released a security advisory detailing a Denial of Service (DoS) vulnerability in the Nokia 6210 GSM mobile phone, and although the flaw isn't serious it could be a sign of worse things to come.

The advisory, posted to the bugtraq security mailing list, describes how a prankster could use the vulnerability to crash a potential victim's phone.

"There is a vulnerability which allows an attacker to send a malicious vCard to a handset, causing (it) to crash," the advisory said.

If an attacker has been successful in crafting the malicious vCard and sending it to the handset, the phone may behave strangely, freeze or stop accepting vCards.

"This is a good example of why all newly introduced product functionality should be reviewed to ensure that no new security vulnerabilities are introduced. A cursory source code audit would find an error of this type," the advisory said.

The vulnerability is not serious -- affected users can simply "reboot" their phones, but the flaw has sparked renewed interest in the issue of security vulnerabilities in increasingly complicated mobile phones.

Even though similar vulnerabilities have been found in the past, the increasing complexity in mobile handsets means this latest discovery is more relevant than ever, according to John Papandriopoulos, a Melbourne based wireless communications researcher.

"As these handsets get more complex, it's hard to have no faults at all," he told ZDNet Australia.

"I think the number of (exploits) will increase over time," he added.

Papandriopoulos says that current generation handsets are not necessarily a popular target because there's little that can be done even if an attacker is able to compromise them.

"I think it's more likely that the motivation would be to inconvenience people," he said.

As for a mobile phone worm, spreading by sending itself to phonebook entries, John says this isn't likely to happen for some time.

"At this stage, that's not realistic, but who knows in five years' time?" he said.

However as standardised client software becomes a feature on mobile handsets it's only a matter of time before malicious hackers start paying more attention to wireless worms, according to Sydney-based security consultant Daniel Lewkovitz.

"The wider the deployment of any given software, the proportionally larger attention certain people pay to breaking it," Lewkovitz said.

Lewkovitz also says that the rush to get wireless software into the marketplace may result in deficient security testing regimes being passed off as acceptable.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
55 out of 98 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

IPCC Engineer Needed ASAP

Main skills: - IPCC Call Center Software (Ideally Version 6) - ARC (Ideally Version 5) - End to End experience in rolling out Telephone Handsets - ...

Software Engineer Telecomms, Birmingham

The company is a leading developer in handset development and seeks an energetic engineer who wishes to be challenged on a daily basis. A protocol ...

Application Consultant

IBM in the marketplace. The mission of this Practice is to provide business-oriented IT solutions to our clients allowing them to reduce the ...

On The Road Blog

Mobile Surfin’ USA

If everybody had a mobile – across the USA… OK, I’ll stop there. Actually, I’m not much of a Beach Boys fan. But betwixt a number of US-based events as I am, I think I’m more acutely... More

Post a comment

Gizmo Adds Business Enhancements and M...

Gizmo5 (formerly The Gizmo Project) has been my preferred program for IM text chat and audio calls (including PSTN calls worldwide) for quite some time now. The chat interface is clean... More

Post a comment

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment