Reply
Thread Tools
longcat's Avatar
Posts: 333 | Thanked: 153 times | Joined on Feb 2010 @ blah blah
#1
Original here - http://www.theregister.co.uk/2010/08...id_sms_trojan/

Can someone explain how is this possible if you're phone is not rooted ?

Is this possible for maemo ?
 
ToJa92's Avatar
Posts: 1,091 | Thanked: 323 times | Joined on Feb 2010 @ ~
#2
Well, the user can send a SMS and so can apps you install. Granted you grant it permission do that, of course.
 
Posts: 56 | Thanked: 50 times | Joined on Apr 2010 @ leigh-on-sea, UK
#3
Having used Android as my primary mobile OS in the past, I'd have to say in it's defence that it gives you the options to

a) reject any apps that aren't approved by the Android Market Place
b) gives you a list of functions that the app requests permissions to access
c) gives you a further warning right before installation if you opt out of option a

I wouldn't knock a point off of Android's tally because of this, but that's just my opinion.

Interesting stuff though!
 
Posts: 45 | Thanked: 45 times | Joined on Jul 2010 @ Berlin
#4
Originally Posted by longcat View Post
Original here - http://www.theregister.co.uk/2010/08...id_sms_trojan/

Can someone explain how is this possible if you're phone is not rooted ?
There was an interesting talk of Collin Mulliner at a hacking conference in 2009:
Fuzzing your phone with SMS:
http://www.youtube.com/watch?v=QnHZhO7Ktfk
http://www.youtube.com/watch?v=lMNBIHW-B78
http://www.youtube.com/watch?v=L-rRNdIZPtM
http://www.youtube.com/watch?v=RG9MNswnpw0
or just:
http://ftp.uni-kl.de/CCC/26C3/mp4/26...your_phone.mp4

http://mulliner.org/security/sms/

Mulliner researched iPhone, Android and Windows Mobile - but not N900

Originally Posted by longcat View Post
Is this possible for maemo ?
Personally, I think that the N900 has also bugs in the SMS application. Unfortunately, Nokia does not publish the source code.

Therefore we need some white hat binary hackers that create a fuzzing framework for the SMS applications.

I already contacted "Reggie" to create a new forum [Security] - but no reply until now .

Last edited by TorstenT; 2010-08-18 at 21:34.
 
tso's Avatar
Posts: 4,783 | Thanked: 1,253 times | Joined on Aug 2007 @ norway
#5
imo, the two device setup of smart tablet (n8x0 style) and dumb phone makes sense.

sure hope some company embrace meego as a pmp base.
 
Reply


 
Forum Jump


All times are GMT. The time now is 03:03.