|
How to crash a Windows mobile using MMS - TechAmok
How to crash a Windows mobile using MMS - [security] 03:49 PM EST - Jan,02 2007 - post a comment Security researchers have released
proof-of-concept code that exploits vulnerabilities in MMS implementations
in mobile phones running mobile versions of Windows. The vulnerability was
discovered six months ago by security researcher Collin Mulliner, who published
the exploit at the Chaos Communication Congress in Berlin last week in a bid to
force manufacturers to deal with the issue.
The proof-of-concept exploits target vulnerabilities in the SMIL presentation
control language in MMS messages. Region tags in MMS SMIL are vulnerable to
buffer overflow causing arbitrary code execution. In other words, if those tags
get too large in content it makes it to possible for a malicious MMS message to
execute code on the target device.
It is still unknown which phones are vulnerable to this exploit. Collin's
research has confirmed a vulnerability in the IPAQ 6315 and i-mate PDA2k, but it
is quite likely that all Pocket PC 2003 and Windows Smartphone 2003 devices are
also vulnerable.
The good news is that the only devices for which the proof-of-concept code is
available are the IPAQ 6315 and i-mate PDA2k. And even in those devices the
attacker needs to guess the correct memory slot where the MMS processing code is
executing and send correctly crafted exploit code. This means that a malicious
MMS message will most likely only be able to crash the device, not to to exploit
it.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
Mar,28 2024 Intel's Battle Has Just Begun Mar,27 2024 Unreal Physics is a new free game on Steam Mar,27 2024 Is The World's Cheapest Hardware Wallet SafePal S1 Worth It? Mar,27 2024 Yes, this was a Bad Idea (Emergency Wall-Mounted PC Build) Mar,27 2024 11 Cool Command Line Programs You Need to See Mar,26 2024 When you Accidentally Compromise every CPU on Earth Mar,24 2024 Everyone Who Tried This Has FAILED - Khadas Mind Modular PC Mar,24 2024 Air Cooling is Dead Mar,24 2024 US Justice Dept. Sues Apple for Monopolistic Behavior in Smartphones Mar,24 2024 Beetlejuice Beetlejuice - Official Teaser Trailer (2024) Michael Mar,22 2024 Alien: Romulus | Teaser Trailer Mar,22 2024 NVIDIA Is On a Different Planet Mar,21 2024 Everyone Needs This and it's Under $10 - Handy Tech Under $100 Mar,21 2024 20 COOL GADGETS FOR 2024 Mar,21 2024 Nvidia's 5090 Is Built From WHAT?! Mar,20 2024 Parasyte: The Grey | Official Trailer | Netflix Mar,20 2024 Fastest m.2 on Planet EARTH | Crucial T705 Nvme Review Mar,20 2024 LG's new 480Hz OLED dual-mode monitor Mar,19 2024 First 9.1 GHz CPU (overclocked 14900KS) Mar,18 2024 Haley Messick - Saatisfaction @bennybenassi - In10sive Mastercamp Mar,18 2024 1000W CPU: The Most Powerful Desktop Processor Mar,18 2024 Expands Snapdragon 8 Series to Cover More Price Points Mar,17 2024 Train Vs Lamborghini Mar,16 2024 Don't use a Microsoft Account! Mar,16 2024 This Ghillie Made from MIRRORS is SHOCKINGLY GOOD Mar,16 2024 How Hackers Deliver Malware to Hack you using Social Media Mar,15 2024 Call of Duty: Warzone Mobile - Launch Trailer Mar,14 2024 Intel's 4th Attempt At Beating Ryzen - "New" 6.2GHz Core Mar,14 2024 Asus Goes Big with Zenfone 11 Ultra Mar,14 2024 House Passes Bill to Force Sale of TikTok Mar,14 2024 Motorola Brings More Affordable 5G Phones to its 2024 Lineup Mar,14 2024 Capristan Swim - Miami Swim Week | Art Basel Miami Mar,11 2024 The Most Stunning All SSD NAS Ever? Inside QNAP's All-SSD Mar,11 2024 M2 vs M3 MacBook Air - ULTIMATE Comparison! Mar,11 2024 Risky PC Experiment: Direct CPU Water-Cooling! Can It Survive? Mar,11 2024 SpaceX Falcon 9 rocket launches 23 Starlink satellites from Mar,10 2024 I tried the Cheapest Arduino Alternative (that Nobody heard of) Mar,10 2024 This is the WEIRDEST PC I've ever seen. Mar,10 2024 Nvidia Retires GTX 16 Series, GDDR7 Arrives, FSR Upscaling Going AI? Mar,09 2024 The New BIOS Hack That Bypasses Every Antivirus
>> News Archive <<
| |
|