Windows Phone 7.5 Susceptible to SMS Hack.
Windows Phone 7.5 Susceptible to SMS Hack.
Phones running Microsoft's
newly released Windows Phone 7.5 mobile operating system are vulnerable to
having their text messaging service's knees kicked off in a denial of service
attack.
The flaw is simple as pie to exploit: An attacker simply sends
an SMS to a Windows Phone user. According to WinRumors's tests, Windows Phone 7.5 devices will
reboot, but the messaging hub will fail to load even after multiple attempts.
WinRumors's Tom Warren reported that they tested the attack on a
range of Windows Phone devices, including HTC’s TITAN and Samsung’s Focus
Flash, with some of the devices running the 7740 version of Windows Phone 7.5
and others on Mango RTM build 7720. The bug isn't fussy about which
device you have, Warren says; rather, it comes down to how the Windows Phone
messaging hub handles messages. He notes that messages sent via Facebook chat
or Windows Live Messenger also trigger the bug.
If a user has pinned a friend
as a live tile on their device and the friend posts a particular message on
Facebook then the live tile will update and causes the device to lock up.
Thankfully there’s a workaround for the live tile issue, at initial boot up you
have a small amount of time to get past the lock screen and into the home
screen to remove the pinned live tile before it flips over and locks the
device.
It's been a glum few days for
smartphone security, and Microsoft is certainly not the only manufacturer to
get punched.
According to Computerworld, Google has pulled 22
malicious apps from the Android Market following a spate of malicious game clones.
Apple, for its part, was hit by
the "SMS of death" problem, uncovered by security researchers Charlie
Miller and Collin Mulliner, way back in 2009.
But while all three major mobile players have suffered mobile OS
maladies, not all have cackled so loudly at each other's affliction as
Microsoft did at Google's expense.
It was Ben Rudolph, Microsoft's Windows
Phone "evangelist," who recently, gleefully Tweeted the offer for a free Windows Phone for the five tellers of the most
succulent tales of Android malware woe.
Hark: the cackling has turned into Microsoft's own SMS death
rattle. As Sophos's Graham Cluley o-so-crystal-ballishly writes, one mustn't
throw stones if one lives in a glass house.
Woe, o woe, indeed. It would be kharmic justice if it weren't
actual users who suffer.
WinRumors is now disclosing the bug to Microsoft in cooperation
with Khaled but reported that there doesn't yet seem to be a workaround to fix
the messaging hub, aside from a hard device reset and wiping the device.
Comments