Security Researcher Uncovers Apple iOS SMS Bug
Vulnerability in Apple's iOS platform could allow hackers to send phishing messages via text, but there's no need to panic. Yet.
Text messages are of course bits of text sent between cellphones. Americans send billions and billions of them to one another each month. They're such a common form of communication that most people probably never stop to think that they might be insecure.
In a post on his blog, pod2g explains that text message are converted from the original text to PDUs (protocol description units), which are sent to the baseband and then fired off across the network.
"In the text payload, a section called UDH (user data header) is optional but defines [a] lot of advanced features not all mobiles are compatible with," wrote pod2g. "One of these options enables the user to change the reply address of the text. If the destination mobile is compatible with it, and if the receiver tries to answer to the text, he will not respond to the original number, but to the specified one. Most carriers don't check this part of the message, which means one can write whatever he wants in this section: a special number like 911, or the number of somebody else."
Why is this particular bug cause for concern?
Pod2g believes that ne'er-do-wells could send phishing messages via SMS. In one case, a person could receive a message that would appear to come from their bank, requesting information or sending them to a website. If they respond to the message, the reply wouldn't go to the bank, but instead to the phisher. If you're fool enough to send personal information via SMS, then you could be in a bit of trouble.
[ So much for Apple's walled-garden security approach. Apple Security Talk Suggests iOS Limits. ]
For the CSI lovers out there, pod2G also explains that bad guys could send spoofed messages to your device that would appear to have come from you. In other words, pirates or other nefarious types could plant false evidence on someone's iPhone.
Apple hasn't acknowledged the bug, but there's little reason to worry right now. Most financial or other businesses that might send a text message to an iPhone are delivering information, not requesting it. As long as you don't respond to such messages, you'll be fine.
One of the biggest challenges facing IT today is risk assessment. Risk measurement and impact assessment aren't exact sciences, but there are tools, processes, and principles that can be leveraged to ensure that organizations are well-protected and that senior management is well-informed. In our Measuring Risk: A Security Pro's Guide report, we recommend tools for evaluating security risks and provide some ideas for effectively putting the resulting data into business context. (Free registration required.)