|
| |
|
Code of MMS Exploit for Windows Mobile released - but STILL no patch available December 30, 2006 [General] | By Edward J. R. Bascially the actual code required to exploit a security vulnerability in the MMS client on Windows Mobile has been released. Shortly speaking: now malware writers can use that code and write such software that upon opening of MMS message is getting access to all your data. Collin confirmed this in his presentation and also released a working exploit for the vulnerability to liven things up a little. So let’s summarize:
Collin also mentions in his presentation, “User only needs to view the message to trigger exploit.” So I would add, only view MMSs from trusted sources. To learn more or to download the code click here. To download the exploit directly click here. Clearly this vulnerability is being ignored by everybody - Microsoft, hardware manufacturers, mobile operators and distributors - probably because most users of Windows Mobile phones is using rather email than MMS anyway...
|
| ||||||
| |