The video provides demonstration of an attack based on the vulnerability
"HTC Touch vCard over IP Denial of Service"
Advisory at: http://www.mseclab.com/index.php?page_id=110
Two targets, a HTC Touch Pro (right) and a Cruise (left), are connected to a local network via WiFi, when the attack starts. The SMS inbox suddenly starts filling and the SMS count rises to very high values in a short time.
During the video recording session a problem has likely occurred on the Touch Pro user interface (at 00:35 seconds), the usual display changes, leaving only the incoming SMS counter on the screen.
The SMS incoming ringtones have been left enabled, but they could have been remotely disabled by choosing the proper size for incoming vCards.
Link to this comment:
All Comments (0)