mobiletech
Twitter & Jott Vulnerable to Spoofing
Filed in archive Mobile Technologies by tom on April 18, 2007
I've just noticed a post over on ONLamp.com (via Twitterati) which talks about vulnerabilities in the Twitter and Jott systems.

This is something close to my interests, as spoofing text from another user is something I take very seriously in all the community services I work on or build. I tried to replicate the vulnerability explained in the O'Reilly piece with Pitch, and it's thrown up an interesting side piece in relation to these services: You can spoof the sender MSISDN when sending an SMS message to a UK long number, but not to a shortcode. It seems shortcodes - at least if properly configured and managed - will set the sender MSISDN to the real sender MSISDN, as the numbers come across the cellular network, not the IP network, and require verification as they can be used for premium billing.

So as long as Twitter uses a shortcode in the UK, they can't, as far as I know, be spoofed.



Related Entries:

Permalink: Twitter & Jott Vulnerable to Spoofing
Tags: twitter  spoofing  mobile  2007  wireless  twitter+jott  jott+vulnerable  vulnerable+spoofing 
Trackback: http://publish.creative-weblogging.com/publish/mt-tb.pl/64349
img Addthis img Ask img Blinklist img del.icio.us img Digg img Fark img Facebook img Google img Lycos img Ma.gnolia Add this page to Mister Wong Mr Wong img Netscape img Netvousz img Newsvine img Reddit img StumbleUpon img Slashdot img Tailrank img Technorati img Wink img Yahoo

Vote for Twitter & Jott Vulnerable to Spoofing:

  • Currently 7.40/10
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
Rating: 7.40 out of 5 vote(s) cast.
 
Subscribe
Share It
RSSrss
See all blog subscribe options
Google google
What is RSS?
Yahoo! yahoo
Addthis Subscribe using any feed reader!
Bloglines Bloglines
Newsletter

TwitterFollow us on Twitter!