[Security Alert] SMS Spoofing & Facebook | BEWARE!

Gaurish

ex-Mod
What I am about to tell is scary!

Recently, my friend updated my Facebook status without my permission to play a prank on me. yesterday my status update read "I am an idiot" :p

so logined into my fb account; deleted the status update,changed all passwords(facebook & email), also changed the security questions. thinking I have all bases covered, slept:cool2:

Later, found same status update was posted(again). So this time i asked my friend how is he doing it. it turns out, he used sms spoofing.

Q) So, what is sms spoofing?

Ans: It allows to set who sent the message by replacing the

originating mobile number (Sender ID) with a fake number.

So it turns out, he sent those updates via Text Messages to facebook(9232232665) and in From: he entered my mobile number. so facebook thought I was updating the status.Now I didn't believe him at first & told him its not possible. But later is sent me a text message, which appeared to be sent from my own number:no: but I didn't sent it. Hence, it was clear that he indeed used sms spoofing.

later, I forced him to tell me how he did it. And I was amazed that how easy it is that I am worried now that even a 10year old can misuse this; for illegitimate uses such as impersonating another person, company,

product etc. apparently there is some website, using which spoofed text msg can be sent(Not posting the site name on purpose)

I would like to know if anyone else experienced this or general thoughts.

[Update]

Here is a proof:

sKvsl.png


news in dainik bhaskar on 17 feb 2011. Check the Top-right section
 
Wow...!! Thanks for sharing. Didn't know about this thing.

Well, not asking to PM the link as I know you won't do it :D

Lets google my way out :p

Well, I won't be spoofing. Just for knowledge. I believe in "Never use science for destruction" :eek:hyeah:
 
Gaurish said:
In that case, I have PMed you the site url;)
Thanks, tried to sent a sms to my number from my number, it's working.

So if I guessed it right all the sites which can be used to send anonymous sms'es which take sender number as input can be used to do these things.

Looks really like a big security issue.

--- Updated Post - Automerged ---

Well, the 1st step I can think of is : Remove mobile number from facebook.

Though this won't stop the whole loophole, which can be misused for sending prank sms'es to others.
 
is this already reported to Facebook?? Ask him to report this thing.

Though I think Facebook can't do anything here. As they will be checking the sender number, they can't stop this sms spoof loophole right?? It has nothing to do with facebook itself, this thing can be misused for other intensions.

--- Updated Post - Automerged ---

ragzdiablo said:
googled it..tried a couple of site..all paid sites..

no free ones...

please share.. :p
lol...there are free ones. Search with Anonymous SMS, and you'll get it.

Or wait for @OP to PM, I can't do that without his permission.
 
This is an old 'trick' that even Fb admitted to be true sometime back. Theres no way out of this one unless you deactivate the mobile phone privileges via your FB privacy settings .....
 
I don't remember, but there is one site (maybe 160by2)... my friend A used to send me sms impersonating as my friend B.. as he has registered with B's mobile no...
 
Isn't there an option on facebook like twitter where you prefix a pin code to your sms before it gets published to the main page ?
 
bottle said:
Isn't there an option on facebook like twitter where you prefix a pin code to your sms before it gets published to the main page ?
Nopes:)

10chars

[Edit]

For now, only way is to TURN OFF sms notifications, or get add mobile number into facebook that nobody else is aware of
 
Back
Top