PDA

View Full Version : SMS DoS on SL45i


Kuhout
03-10-2003, 15:04
Recently I red an article on URL=http://www.securityfocus.com/archive/1]BugTraq[/URL] about SMS Denial of Service on *35 and *45 - this means SL45i too. I dont know if it is known here - send a "%English"(or another language in phone - in SL45i case only english - the others are on MMC) string via SMS, the phone will freeze and you must reset it and delete the SMS. The solution - changing the English string in fw to something else. But I dont know what to change. Can someone please post a patch?
Thx a lot.

Kuhout


BTW Sorry for my English

JaZ
03-10-2003, 21:30
Hi, Siemens AG announced (as are people said in Service centers etc), that it will not release any patch for this. Maybe after the users' reaction they will, but probably not for older models like SL45.
The problem is that mobile phone freezes after 'reading' the "%language" message, where language is the lng you're currently using (and/or maybe also English,doesn't matter). This word ("english" , "polski", "cesky", without the quotes) is stored in firmware and the point of the 'patch' is that you CHANGE this word. For example my case: I use English lng in my phone, so only problem word is English, so i change it in firmware to Inglish for example. The problem is still there, but the phone now freezes after receiving message with "%Inglish" . Of course no-one but you know this word (or maybe password :) ), so you're 99.99999% safe from all sms-bombers...you need UniSiemens and Siemens language editor for this...detail process described in czech (by me :) on http://www.volny.cz/****head in 2 hours...

Kuhout
03-10-2003, 21:43
So I only need to change the languague name - but I dont know which part of flash I need to download and how to get it into lng. editor. But your web page is not there.

JaZ
03-10-2003, 23:44
yes, i saw it now... instead of **** there should be "hovno" in english, it's censored, don't know why...and you need to download whole flash...

Kuhout
03-11-2003, 19:49
:) :) :) Thank *** I know Czech.

Kuhout
03-11-2003, 19:52
:confused: :confused: :confused: It censores even g_o_d. Why?

Kuhout
03-11-2003, 19:53
Btw thanks :)