Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

PalmOS crashes receiving SMS images using Handspring VisorPhone
From: Brian Wright <commorancy () yahoo com>
Date: Mon, 22 Oct 2001 14:20:15 -0700 (PDT)

Hello,

A friend and I were playing around sending SMS
messages the other day between a Nokia 3390 and his
Handspring VisorPhone/Visor Prism combo.  Sending text
messages seemed to work just fine.  However, on the
Nokia, there is an option of sending SMS images. 
Apparently, they are fairly large as they take a while
to send.  

The VisorPhone appears capable of accepting these
messages, but the VisorPhone database inside the
PalmOS isn't (at least, the version he had loaded). 
Whenever it transfers the image into the VisorPhone
database, it fatally crashes PalmOS and leaves the
VisorPhone database corrupted.  In order to recover,
he had to reboot the Visor (which disconnects the
call) and then attempt to delete the phone database
(which includes SMS messages).  This has the affect of
deleting all VisorPhone information (call logs, SMS
archived messages, custom messages, etc).  I doubt it
touched the standard PalmOS contacts database.

I tested it twice with the same results.  So, if
you're into crashing VisorPhones, try sending an SMS
image from a Nokia. :)  This vulnerability may also
exist when sending custom ringtones and other Nokia
specific SMS messages.

I don't know the exact version of the VisorPhone
software/hardware nor the exact version of PalmOS
running on the Visor Prism, but it's likely to work
with what's shipping today.  I also haven't tested on
anything other than the Visor as I don't have access,
but other PalmOS based phones may be vulnerable.


=====
--
Brian Wright <commorancy () yahoo com>

__________________________________________________
Do You Yahoo!?
Make a great connection at Yahoo! Personals.
http://personals.yahoo.com


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]