← Back to context

Comment by kevcampb

8 years ago

Can you post the SMS opt-in message you received? Curious as to whether this is exploitable as well

LocationSmart: Reply YES or YES LS to confirm consent for cloud location & messaging demo. Reply HELP for help, Reply STOP to cancel. Msg&Data Rates may apply.

That is what I was sent.

I'm betting the opt-in is something along these lines

"FirstName LastName wants to obtain your location..."

Also betting that you can put 160 characters into those fields, so effectively a blank SMS is received

Betting further still that you can just spoof the SMS reply