Home > Security News > Siemens S55 phones send unauthorized SMS messages
Security News:
EMAIL THIS

Siemens S55 phones send unauthorized SMS messages

By Edmund X. DeJesus, Contributing Writer
04 May 2004 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Siemens S55 cellular phones have a vulnerability that can cause the phone to send Short Message Service (SMS) protocol messages that the user doesn't intend. But first the user must be tricked into running malicious Java code to exploit the vulnerability.

The Siemens S55 includes Java technology that supports a number of applications for business, travel, entertainment and games. The cell phone's Java virtual machine includes a full-featured API so that third-party software developers can create additional applications. SMS permits sending messages no longer than 160 alphanumeric characters with no images or graphics.

The Phenoelit Group of gray-hat hackers has discovered that there are problems in the Siemens S55 time.jar java file. Usually, sending SMS messages or placing calls via Java applications requires user permission, which is obtained through an on-screen dialog. However, filling the screen with other items obscures this dialog, so that the user may unwittingly approve sending SMS messages to another number. For this to work, the attacker must trick the user into installing the malicious Java software, which isn't a difficult feat. Members of Phenoelit originally presented this vulnerability at a black hat convention in Las Vegas in 2003.

While not a critical security vulnerability, this problem does represent a security bypass, and may be the first of similar exploits on cellular phones and other devices sophisticated enough to use Java technology. As always, users should not download and run untrusted applications, even on their phones.

Tags: Wireless Network Protocols and StandardsWireless LAN Design and SetupWeb Server Threats and CountermeasuresWeb Application and Web 2.0 ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless Network Protocols and Standards
Wireless Security Lunchtime Learning
An introduction to wireless security
A wireless network vulnerability assessment checklist
Lesson 1: How to counter wireless threats and vulnerabilities
Lesson 1 quiz: Risky business
Wireless Security Lunchtime Learning Entrance Exam
Risky Business: Understanding WiFi threats
Study reveals lack of financial wireless computer security
Preparing enterprise Wi-Fi networks for PCI compliance
Cracks in WPA? How to continue protecting Wi-Fi networks

Wireless LAN Design and Setup
A list of wireless network attacks
Wireless Security Lunchtime Learning
An introduction to wireless security
Hunting for rogue wireless devices
A wireless network vulnerability assessment checklist
Lesson 1: How to counter wireless threats and vulnerabilities
Risky Business: Understanding WiFi threats
Wireless Security Lunchtime Learning Entrance Exam
Lesson 1 quiz: Risky business
Study reveals lack of financial wireless computer security
Wireless LAN Design and Setup Research

Web Server Threats and Countermeasures
Latest DDoS attacks extremely unsophisticated, experts say
Stolen FTP credentials likely in massive website attacks
Microsoft warns of IIS zero-day vulnerability
How to find and stop automated SQL injection attacks
How to spot attacks through Apache Web server log analysis
Symantec acquires Mi5 Networks, bolsters Web security
How to harden Linux operating systems
How to clear out anonymous Web proxy servers in the workplace
Information security book excerpts and reviews
Is it more secure to have a mainframe or a collection of servers?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
evil twin  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts