Microsoft dissecting Windows Phone messaging bug
- 15 December, 2011 03:27
- Comments
Microsoft Windows Phone engineers are reviewing a report that various messaging technologies can be used to send the phone into a reboot and then freeze its messaging center, or hub.
Currently, the only "fix" is a hard reset and wipe of the phone, according to WinRumors.com, which reported the attack on Tuesday, after it was contacted by a Windows Phone user who discovered the problem. A short video by WinRumors' Tom Warren shows the results of the attack but no details of how it actually succeeds.
The Website says it is talking privately with Microsoft about what it found.
ALL WINDOWS ALL THE TIME: Visit Network World's Microsoft Subnet
WINDOWS PHONE SHUFFLE: Microsoft re-orgs Windows Phone group
Though now widely labeled an SMS attack, the WinRumors story discloses the problem can be triggered also by messages created with Facebook chat or Windows Live Messenger. "The attack is not device specific and appears to be an issue with the way the Windows Phone messaging hub handles messages," writes Warren.
It's not clear from Warren's account whether there's a bug in the OS that's randomly triggered by any of these messages, or whether the message has to be somehow deliberately designed to leverage the flaw.
"The flaw appears to affect other aspects of the Windows Phone operating system too. If a user has pinned a friend as a live tile on their device and the friend posts a particular message on Facebook then the live tile will update and causes the device to lock up," Warren reported. There is a short time during initial boot up when a user can "get past the lock screen and into the home screen to remove the pinned live tile before it flips over and locks the device."
Microsoft issued a generic statement about the reported attack via a spokesman's email to PhoneScoop.com: "We are aware of the issue and our engineering teams are examining it now. Once we have more details, we will take appropriate action to help ensure customers are protected."
John Cox covers wireless networking and mobile computing for Network World.
Twitter: http://twitter.com/johnwcoxnww
Blog RSS feed: http://www.networkworld.com/community/blog/2989/feed
Read more about anti-malware in Network World's Anti-malware section.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Microsoft Subnet: An independent Microsoft community
- Windows Research Center - Network World
- Windows Phone SMS attack discovered, reboots device and disables messaging hub : WinRumors
- Microsoft's latest Windows Phone move: Changes at the top
- Microsoft Examining SMS Bug (Phone Scoop)
- Wireless Research Center - Network World
- The ultimate Twitter quiz
- John Cox's blog
- Anti-malware Research Center - Network World
-
How to implement next-generation storage infrastructure for Big Data
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Pfizer's Future Depends on IT Transformation
-
Apple aims iPads at High Schools
-
Securing SOA and Web Services with Oracle Enterprise Gateway
Companies worldwide are actively deploying service-oriented architecture (SOA) infrastructures using web services, both in intranet and extranet environments. While web services offer many advantages over traditional alternatives (e.g., distributed objects or custom software), deploying networks of interconnected web services still presents key challenges, especially in terms of security and management. -
The Big Six: The CIO Executive Council’s Frameworks for IT Value and Leadership
This overview of six of the CIO Executive Council’s most important pieces of intellectual capital represents the thought leadership of literally hundreds of global CIOs spanning over half a decade. It is intended to convey the Council’s position on the current and future CIO role and the value that IT should be creating for the enterprise. We hope that it offers the IT community an intriguing and comprehensive roadmap for continued success. -
Gartner MarketScope for Application Life Cycle Management
Organisations adopting agile practices, utilising global and distributed teams, or exploiting complex processes and technologies are most likely to benefit from using ALM tools to plan, manage and report on their development activities. This MarketScope assesses the market offerings and their providers.
-
Wiley Plus/WebCT Stand-alone to Accompany Big Java 3E for Java 5 and 6
-
Microsoft Office Publisher 2007 for Dummies
-
Filemaker Pro 8.5 Bible
-
Mastering System Center Data Protection Manager 2007
-
Mastering Maya 2009
-
Programming Languages Concepts 3E
-
Access 2003 for Dummies
-
Scanners for Dummies, 2nd Edition
-
Computer Simulation in Business 2E








Comments
Post new comment