online security computer security vulnerabilities information security
pix Xatrix Security
 
pix
Main
Security
Downloads
Forum
Free e-books
Security
Advisories
Vulnerabilities
IT News
Virus Central
Services
Advertise
Newsletter
Shop
Search
Wap-PDA/mobile
Other
Affiliates
Contact
RSS feeds
Computer, Online and Information Security News
  Show printable version  Show printable version  |   Send this article to a friend  Send this article to a friend  

Spamming through SMS

Posted by: Phiber on Februrary 16, 2001

Any html or javascript included in a GSM SMS (short message service) message, sent or
recieved, will be activated when a person enters the page with the message on it (Inbox
or Outbox)....
<b>Impact - spamming</b>
I haven´t tested this, but in theory it is possible for spammers with a SMS spam program to send messages, including the meta refresh code, to all of the users of mtnsms.com. The result would be that when a member enters their inbox he or she will directly be sent to the website chosen by the spammer. It will also be very difficult, specially if a high speed connection is used, to remove the spam for the user.

<b>Impact - individual/mass sabotage</b>
Instead of spamming, the sender could include malicious code in the message causing the browser to crash or the computer to freeze. One method is to include the meta refresh code, sending a member
to a webpage with, for example, the "Self Referenced Frames Crash" which affects various o/s and/or the "Invalid WAVE Crash" (Bugtraq June 1999).

<b>Impact - sender generated</b>
The really annoying part when it comes to security is that the users themselves often cause more
problems then outside attackers. This is the issue here as well. If a user sends a message containing
code, the code will activate when the users visits the Outbox page.

<font size="1"><center>Contributed by Thomas Sjorgen on a Bugtraq mailing list</center></font>
Xatrix Security
Show printable version  Show printable version  |   Send this article to a friend  Send this article to a friend  
Latest information, online and computer Security News
Hack Attack: Get Windows XP SP3 Throu...  (Nov 29, 2007)
TPB files charges against media compa...  (Sep 22, 2007)
Storm worm: again.  (Aug 7, 2007)
Onslaught on .ORGs  (Feb 7, 2007)
OpenOffice.org insecure  (Aug 12, 2006)
Latest Vendor Advisories
Firefox vulnerabilities
Ruby safe-level vulnerability
Seamonkey critical security vulnerabilities
Drupal several remote vulnerabilities
Kernel local race condition
  Our Services     Information     Our Online Shop     Community Forum Topics
  Free weekly Newsletter
Advertise on Xatrix
Monthly News Archive
Community Forum
  Impressum/about
Contributing
Newsletter archive
Latest bugs
  Top sellers
New Items
Books
Software
  Remote control app!
The Ultimate Proxy
What do you hate ab...
How do you hack &qu...
Our Privacy Policy | Contact Us
Powered by TiP / Rapid IT | HITB.org
All contents © 2000 - 2006 Xatrix Security. All Rights Reserved.
Get news on your PDA or mobile phone Latest events Search our extensive database Get the latest books and software Download the latest tools Contact Us Advertise on Xatrix Security