Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Justifying Application Vulnerability Assessments | Main | Old Malware Threats Re-Emerge »

Gphone in 2 weeks rumors, Malware and Mobile Attacks are the Real News

Stories are just starting to circulate about the release of the Gphone in as little as two weeks. (Others argue, no way, the source article is wrong and Business 2.0 gives cogent arguments why it won't happen). Regardless of the accuracy, the rumors will get a lot more attention than the research coming out of UPenn and UC, Davis reported by McAfee's Avert Labs on mobile malware and other attacks. The McAfee blog credits the popularity of the iPhone with an increase interest among hackers for mobile phone hacking. Watch what happens when low cost Gphones hit the street.

Here's the Gphone news from Rediff:

Google, the nearly $13.5 billion search engine major, is believed to be a fortnight away from the worldwide launch of its much-awaited Google Phone (Gphone) and has started talks with service providers in India for an exclusive launch on one of their networks. ... Sources close to the development said a simultaneous launch across the US and Europe is expected, and announcements would be sent to media firms in India and other parts of the world. US regulatory approval, which is expected soon, is the only hurdle that Google is waiting to cross, they added. Google plans to invest $7-8 billion for its global telephony foray.

Not to rain on the parade (whether is starts in 2 weeks, 2 months or 2 years), but heres some findings on mobile attacks from Avert Labs:

Several works in the academic area have pointed this out, and some have successfully exploited the cellular network via the Internet to cause a denial of service. Penn state’s paper used SMS, which can be sent freely on the Internet, to cause DoS on the cellular network. They exploit the fact that cellular networks, when sending SMS, use the same, narrow bandwidth control channel as phone calls. By flooding a service area with SMS messages, they can effectively block incoming and outgoing phone calls. UC Davis’ paper, on the other hand, used MMS to cause DoS on the host. They discovered that an outside server can obtain information from MMS messages from mobile devices, and attackers can use this information to send rogue packets to the phone, causing the battery life to decrease significantly. Furthermore, Sprint’s and Penn State’s papers further discuss the vulnerabilities on the cellular network that makes these attacks possible.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/390

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net