Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
Username: Password: Auto login:
Did you know you can browse Geekzone without ads by Subscribing?
You haven't logged in yet. If you don't have an account you can register now.
  MMS exploit in the wild for Windows Mobile devices

Posted on 31-DEC-2006 06:36. | Tags Filed under: News.





The Symantec Security Response Weblog has posted a note warning that an exploit is in the wild that uses the multimedia messaging service (MMS) as a vector. MMS are similar to the SMS but carry multimedia information such as text, sound, pictures and short videos.

The warning is a follow up on a previously disclosed vulnerability found by researcher Collin Mulliner, who gave an updated version of his presentation titled "Advanced Attacks Against PocketPC Phones".

One of the vulnerabilities he discussed had not been patched, and since Collin has released a working exploit for the vulnerability. A malformed MMS message can execute arbitrary code on a mobile device, simply by having a user view the message.

Messages sent through MMS to mobile devices can cause the device to freeze due to flaw on rendering content.

The Symantec blog claims the vulnerability has been publicly disclosed for over six months and there is no patch for it.

One of the recommendations is to install firmware updates when available, but the blog fails to mention that this is not an OS vulnerability, since MMS clients on Windows Mobile are supplied by third party developers. The client is generally available from manufacturers and consumers should put pressure on these to have the software updated.






More information: http://www.symantec.com/enterprise/security_r...




Other articles related to News



Comments

cesarbremer
  send private message user's profile
Comment posted by cesarbremer on 3-JAN-2007 12:39
Could we deactivate the MMS?
freitasm
 open user's web page send private message user's profile
Comment posted by freitasm on 4-JAN-2007 06:29
You can't remove the program, but if you configure it with an invalid WAP gateway then the program won't be able to download any MMS, making it secure. But then you don't get the messages...


cesarbremer
  send private message user's profile
Comment posted by cesarbremer on 4-JAN-2007 07:46
This is enough for my clients that are using my secure phone application ( see at http://www.raseac.com.br ).
Regards.
Cesar.
Post a commentPlease login or register to post a comment on this article.