Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Cantv/Movilnet's Web SMS vulnerability. |
|---|---|
| Date: | Mon, 27 Mar 2006 12:57:25 -0400 |
Quick Summary: ************************************************************************
Product : Movilnet's Web SMS. Version : In-production versions. Vendor : Movilnet - http://www.movilnet.com.ve/ Class : Remote Criticality : High Operating System(s) : N/A.
Synopsis ************************************************************************
Movilnet is an affiliate of Cantv, the largest private telecomunications company in Venezuela.
Movilnet's Web SMS is a very popular Short Messages System that allows web surfers to send short text messages directly to Movilnet's mobile phone subscribers.
Notice ************************************************************************
Vendor Status ************************************************************************
SNSecurity has contacted Movilnet, who already knew about the problem and is currently dealing with the issue.
2/21/2006 Vendor is contacted about the vulnerability.
2/23/2006 Vendor informs the vulnerability was already known and asks
for a 30 day period before publication.
3/17/2006 Vendor agrees to make the advisory public at the date agreed
upon.
3/27/2006 Advisory is made public.Basic Explanation ************************************************************************
Proof Of Concept Status ************************************************************************
No proof of Concept will be released until the provider has sorted out the issue.
Work Around ************************************************************************
No work around is possible to prevent abusers to spam or sms-bomb mobile customers. If you are sms-bombed you can only turn off your mobile phone and ask a Movilnet representative to have your entire short text message queue deleted.
Corrective Measures ************************************************************************
Replace the captcha module for a stronger and more robust implementation.
Credits ************************************************************************
This vulnerability was discovered by Ruben Recabarren and Leandro Leoncini at SNSecurity's Research Lab.
Disclaimer ---------------------------------------------------------------------- This advisory was released by SNSecurity as a matter of notification to help administrators protect their systems and to warn mobile customers against the described vulnerability. Exploit source code is never released in our advisories but can be obtained under contract. Contact our sales department at info (at) snsecurity (dot) com for further information on how to obtain proof of concept code.
---------------------------------------------------------------------- SNSecurity. http://www.snsecurity.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote "CreateTextRange()" Code Execution), Determina Secure |
|---|---|
| Next by Date: | Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow), Gadi Evron |
| Previous by Thread: | Determina Fix for CVE-2006-1359 (Zero Day MS Internet Explorer Remote "CreateTextRange()" Code Execution), Determina Secure |
| Next by Thread: | Re: Cantv/Movilnet's Web SMS vulnerability., raven |
| Indexes: | [Date] [Thread] [Top] [All Lists] |