Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: SYMSA-2007-007: Palm OS Treo Smartphone Denial of Service

From: Michael Bednar <MBEDNAR(at)katz.pitt.edu>
Date: Mon Aug 20 2007 - 17:21:08 EDT

 

        When I tested this on my Treo over Verizon's network, only one packet with the prescribed parameters was needed to force a soft reset of my phone rather than the flood described in CVE-2003-0293. When I notified Verizon of this, they were completely unaware of this vulnerability -- well, at least their help desk people were. I'm hoping they'll take steps to filter this kind of traffic on their network.

        On a side note, when I was testing this vulnerability, I tried varying the size of the ICMP packet. Strangely enough, I got no response if the packet was of size 1469 bytes, or 1471 bytes. There must be something special about 1470 byte ICMP packets. Anyone have any ideas?

Mike

--

Michael C Bednar
Katz IT Services
319 Mervis Hall
University of Pittsburgh
Pittsburgh, PA 15260

-----Original Message-----

From: Stuart Moore [mailto:smoore.bugtraq@securityglobal.net] Sent: Monday, August 20, 2007 16:13
To: research@symantec.com; bugtraq@securityfocus.com Subject: Re: SYMSA-2007-007: Palm OS Treo Smartphone Denial of Service

Hi. Is this fundamentally different than the previously reported PalmOS

Do you need help?X

ICMP denial of service bug (CVE-2003-0293)?

Thanks,

Stuart Received on Tue Aug 21 12:43:41 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:12:56 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library