Mobile phone hacking set to spread: AU experts

Patrick Gray
26 February 2003 12:50 PM
Tags: hacking, mobile, phone, nokia, gray, patrick, vulnerable, vcard
United States-based security company @stake (atstake.com) has released a security advisory detailing a Denial of Service (DoS) vulnerability in the Nokia 6210 GSM mobile phone, and although the flaw isn't serious it could be a sign of worse things to come.

The advisory, posted to the bugtraq security mailing list, describes how a prankster could use the vulnerability to crash a potential victim's phone.

"There is a vulnerability which allows an attacker to send a malicious vCard to a handset, causing [it] to crash," the advisory said.

If an attacker has been successful in crafting the malicious vCard and sending it to the handset, the phone may behave strangely, freeze or stop accepting vCards.

"This is a good example of why all newly introduced product functionality should be reviewed to ensure that no new security vulnerabilities will also be introduced. A cursory source code audit would find an error of this type," the advisory said.

The vulnerability is not serious - affected users can simply "reboot" their phones, but the flaw has sparked renewed interest in the issue of security vulnerabilities in increasingly complicated mobile phones.

Even though similar vulnerabilities have been found in the past, the increasing complexity in mobile handsets means this latest discovery is more relevant than ever, according to John Papandriopoulos, a Melbourne based wireless communications researcher.

"As these handsets get more complex, it's hard to have no faults at all," he told ZDNet Australia .

"I think the number of [exploits] will increase over time," he added.

Papandriopoulos says that current generation handsets are not necessarily a popular target because there's little that can be done even if an attacker is able to compromise them.

"I think it's more likely that the motivation would be to inconvenience people," he said.

As for a mobile phone worm, spreading by sending itself to phonebook entries, John says this isn't likely to happen for some time.

"At this stage, that's not realistic, but who knows in five years' time?" he said.

However as standardised client software becomes a standard feature on mobile handsets it's only a matter of time before malicious hackers start paying more attention to wireless worms, according to Sydney-based security consultant Daniel Lewkovitz.

"The wider the deployment of any given software, the proportionally larger attention certain people pay to breaking it," Lewkovitz said.

Lewkovitz also says that the rush to get wireless software into the marketplace may result in deficient security testing regimes being passed off as acceptable.

Advertisement

Talkback 1 comments

    how to hack information or send a virus to others mobileAnonymous -- 17/06/03

    how to hack information or send a virus to others mobile


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured