GPRS billing hack is disclosed

GPRS (a cellular data service) has been compromised — apparently for quite some time, though the disclosure only comes today. The hack that everyone's worried about is one that allows hackers to bill arbitrary services to any GRPS handset:

There are lots of potential issues, but the one which has forced the phone networks to acknowledge that there is a problem, is a scam where a company obtains IP addresses that the GPRS operators own, in the "cellular pool" and start pinging those addresses.

When one of them responds, the scam operator knows that a user has been assigned the address. And, unbelievably, there was nothing to stop them simply providing services direct to that IP address – and taking the money out of the GPRS billing system to pay for it.

Link

(via Interesting People)