spoofing Twitter and other SMS-based services

in case you haven’t been aware how easy it is to fake the originating number (’from’) of an SMS message, ONLamp features a step-by-step guide on spoofing Twitter (and similar services involving authentication mechanisms solely based on the senders phone number). this basically means that attackers only need to know a users associated cellphone number and an SMS-service like FakeMyText to post messages in his name. there goes your identity… ;)

Related Posts:

RSS feed | Trackback URI

2 Comments »

See my profile on MyBlogLog.com!
Collapse Comment by Joan Young Subscribed to comments via email
2007-05-02 00:33:08

This exploit is also being helped by hoaxmail (http://www.hoaxmail.co.uk)

These websites should be closed down, your cell phone number and email address is yours and should not be copied by others.

 
See my profile on MyBlogLog.com!
Collapse Comment by Johnny D Subscribed to comments via email
2007-07-31 15:45:00

Yeah your right that hoaxmail is quite poor, fakemytext.com seems quite nice though.

 
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.