spoofing Twitter and other SMS-based services

Sunday, April 8th, 2007

in case you haven’t been aware how easy it is to fake the originating number (’from’) of an SMS message, ONLamp features a step-by-step guide on spoofing Twitter (and similar services involving authentication mechanisms solely based on the senders phone number). this basically means that attackers only need to know a users associated cellphone number and an SMS-service like FakeMyText to post messages in his name. there goes your identity… ;)