SYMBIAN OS SECTION
  -My-Symbian.com-
MAEMO  SECTION
-My-Maemo.com-
SOFTWARE STOREFORUMCONTACT

My-Symbian.com Forums
Symbian Partner

 
My-Symbian & My-Maemo
Symbian & Maemo based Communicators and Smartphones Info Center
since 1999
 
 Watched TopicsWatched Topics   FAQFAQ   SearchSearch   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   RulesRules   Log inLog in 
Lightweight, simplified version of the forumsMobile version   Support this website to keep it aliveRemove all adverts!  
 
S60 Vulnerability Advisory: Curse of silence

 
Post new topic   Reply to topic    My-Symbian & My-Maemo Forum Index -> Symbian OS S60 3rd Edition Communicators
View previous topic :: View next topic  
Author Message
grmmpf
Forum Newbie



Joined: 25 Oct 2007

Posts: 24
Location: Germany
Phone: E61, E90

PostPosted: Wednesday, 31.Dec.2008 14:49    Post subject: S60 Vulnerability Advisory: Curse of silence   Reply with quote   

Hi all,

I just read about this vulnerability discovered by the german CCC in what it seems concerns all S60 variants. I'll also crosspost in S60v3-Communicators.

In Essence:
if your s60v3-handset gets hit by this kind of SMS your handset won't receive any SMS or MMS any further. The source explains that you have to reset your handset to factory defaults in order to recover the full functionality again.
The Security-Company FortiGate already introduced a tool against this vulnerability.

But read for yourself:
Original source:
https://berlin.ccc.de/~tobias/cursesms.txt
German article at Golem:
http://www.golem.de/0812/64345.html
Fortigate-Tool FortiCleanup against vulnerability:
http://fortiguardcenter.com/advisory/FGA-2008-31.html

I just installed the tool on my E90.

Regards
Back to top
My-Symbian
Sponsored links









PostPosted: Wednesday, 31.Dec.2008 14:49    Post subject: Sponsored links      

Back to top
Michal Jerz
Admin/Founder/Owner



Joined: 01 Sep 1999

Posts: 24212
Location: Poland
Phone: N900, Omnia HD, E90, N97, 5800 XM, Xperia X1 and some more

PostPosted: Wednesday, 31.Dec.2008 15:32    Post subject:   Reply with quote   

Quote:

The Security-Company FortiGate already introduced a tool against this vulnerability.

Was it also them who invented the SMS? Laughing

Quote:

https://berlin.ccc.de/~tobias/cursesms.txt

Security Certificate error Razz Had to use http:// instead of https://
Back to top
grmmpf
Forum Newbie



Joined: 25 Oct 2007

Posts: 24
Location: Germany
Phone: E61, E90

PostPosted: Wednesday, 31.Dec.2008 15:44    Post subject:   Reply with quote   

Hi Michal,

yepp, I noticed the security certificate error also. I copied the link from the article at golem.de. Sorry for not changing the link from https to http (classic copy-n-paste-error).

Anyway, I guess we will be seeing some SMS originating from some script kiddies with this kind of content. Maybe there will even be the possibility of worse exploitation like buffer overflows or similar.

We'll see.
Regards
Back to top
im92109210
Forum Veteran



Joined: 03 Mar 2003

Posts: 1305
Location: United Arab Emirates , Dubai
Phone: E90 Black, 5800, N97, N97 Mini, N900

PostPosted: Wednesday, 31.Dec.2008 18:38    Post subject:   Reply with quote   

I sense alot of sarcasm from Michal... Is this risk a hoax or something Michal?
Back to top
My-Symbian
Sponsored links









PostPosted:     Post subject: Sponsored links      

Back to top
grmmpf
Forum Newbie



Joined: 25 Oct 2007

Posts: 24
Location: Germany
Phone: E61, E90

PostPosted: Wednesday, 31.Dec.2008 19:34    Post subject:   Reply with quote   

Hi im92109210,

just look at the links. The guys at CCC have a pretty good reputation and FortiGate is a wellknown security company (I do work with some of their appliances). So be assured it is no hoax (at least in my opinion).

Anyway if you want, you can try it out by yourself (of course only on your own devices). The description of how to do it, is in the original source link.

Regards
Back to top
grmmpf
Forum Newbie



Joined: 25 Oct 2007

Posts: 24
Location: Germany
Phone: E61, E90

PostPosted: Thursday, 01.Jan.2009 17:50    Post subject:   Reply with quote   

Hi all again,

First of all: I just want to present the worst case which hopefully won't happen but anyway I want to get people thinking a bit and Nokia maybe some more. So this is just my opinion.

I think IMHO that there might even be more coming after this (although I might be wrong). This is, as already mentioned, a bad glitch in the operating system uncovered by the guys at CCC. I myself am working for a security company and I usually take those vulnerabilities serious since these glitches might also lead to buffer or heap overflows which then again might lead to remote code execution.
Okay this of course is worst case and might not happen BUT on the other hand S60v3 is a platform which is widely used in cellphones not a lot unlike windows on PCs. So just painting the worst case, improbable as it may be, further: what if mobile phones might be used as a vehicle for anonymizing whatever form of criminal actions by hijacking them with remotely executable code? What if using remotely executable code as a man-in-the-middle attack in online banking done on cellphones? You can think of a lot of szenarios.

Again, these scenarios are maybe improbable but still though: a glitch is a glitch and this one in my opinion is a bad one because it can be done remotely. And of course: remote exploits always begin like that: someone finds a glitch and someone else finds a way to possibly exploit this glitch.

So in my opinion we and of course especially Nokia should take this glitch seriously and fix it. Such glitches should not be underestimated since there are some people around which might try to exploit it.

I for myself am thankful that FortiNet introduced a tool to prevent the CurseSMS: http://fortiguardcenter.com/advisory/FGA-2008-31.html (I'm not in whatever form related to FortiNet).

Regards
Back to top
ukjeeper
Forum Newbie



Joined: 01 Apr 2008

Posts: 32

Phone: E90, N73, N810

PostPosted: Friday, 02.Jan.2009 19:36    Post subject:   Reply with quote   

Interesting article regarding this on Symbian Guru.com Worth a read:

http://www.symbian-guru.com/welcome/2008/12/f-secure-announces-curse-o f-silence-sms-s60-exploit.html
Back to top
Anagarika
Site supporter



Joined: 08 Jan 2007

Posts: 2785
Location: GMT +7
Phone: Currently: HTC TyTn II; Previously: M600i R6A16

PostPosted: Saturday, 03.Jan.2009 15:07    Post subject:   Reply with quote   

I believe F Secure has been providing antivirus for non-existent virus .. ?
Back to top





ceroberts75
Site supporter



Joined: 11 Nov 2006

Posts: 1625
Location: San Jose, Ca.
Phone: n900, e90, 5800, e71-1, 9500

PostPosted: Saturday, 03.Jan.2009 21:22    Post subject:   Reply with quote   

i finaly downloaded the f-secure, just to see what it is and what it does.


it was in the downloads section from the start...though, at least here in the US, we don't really run into cellular bugs. so after having it scan and getting "zero" bugs 2 times, i don't really see a use for it.

is it different from outside the US?

do you receive bluetooth bugs and other bugs there?
Back to top
BentL
MODERATOR



Joined: 24 Oct 2002

Posts: 16003
Location: Norway
Phone: N900, E90, 9300i, 9300, 9210

PostPosted: Sunday, 04.Jan.2009 00:33    Post subject:   Reply with quote   

ceroberts75 wrote:
is it different from outside the US?

do you receive bluetooth bugs and other bugs there?

F-Secure for S60 3rd Edition has been discussed in this thread and this thread. There are no viruses for the S60 3rd Edition platform. The special SMS message that turns off some of the Messaging application is most likely some bug that will get corrected in firmware updates, at least for the newer devices.

--
Bent Laursen
Back to top
BentL
MODERATOR



Joined: 24 Oct 2002

Posts: 16003
Location: Norway
Phone: N900, E90, 9300i, 9300, 9210

PostPosted: Tuesday, 06.Jan.2009 14:56    Post subject:   Reply with quote   

Nokia has issued a statement on this issue. Excerpt:
    NOKIA STATEMENT ON S60 SECURITY
    We have received the following statement on this issue:

    Nokia has received an S60 on Symbian OS related vulnerability notice from the Chaos Computer Club (http://www.ccc.de/?language=en). The notice claims that devices with certain versions of S60 on Symbian OS are vulnerable to a remote Denial-of-Service (DoS) attack by sending of e-mails via SMS protocol.

    Nokia is not currently aware of any malicious incidents on the S60 platform related to this alleged issue and we do not believe that it represents a significant risk to customers’ devices.

    Nokia takes security very seriously in all phases of the mobile communication systems development process, and has been investigating the allegation made, using our normal processes and comprehensive testing.

    Our testing has been concentrating on products that might have this issue. Based on the testing, Nokia believes that the vulnerability may be valid for some of the S60 on Symbian OS products. We are also working with the Symbian team to further investigate the alleged vulnerability. For example, the products running S60 3rd edition, feature pack 2, are unaffected by the alleged issue.

    The alleged issue can be proactively prevented by network filtering. According to our knowledge, many operators are already implementing or looking to implement network filtering to prevent the issue.

    Nokia is committed to continuously develop its products and services offerings to ensure a positive and secure user experience.

    If you require further information, please contact your local Nokia Care
So the solution seems to be network filtering at the operators, at least until new firmware updates are released.

--
Bent Laursen
Back to top
Display posts from previous:   
Post new topic   Reply to topic    My-Symbian & My-Maemo Forum Index -> Symbian OS S60 3rd Edition Communicators All times are GMT + 2 Hours
Page 1 of 1

 
Jump to:  
View previous topic :: View next topic

Posting/discussing/exchanging warez/cracks/serial numbers/links to web sites offering such resources and/or any other illegal content
is FORBIDDEN on this forum and results in an immediate BAN.


Symbian and all Symbian-based marks and logos are trade marks of Symbian Software Limited.
This website is not in any way endorsed or supported by Symbian Software Limited.    (C) 2001 My-Symbian.com All Rights Reserved