Sprint Picture Mail bug allows password-less logins
Before we bring you any details about this rather
serious security failure someone just discovered (and we've verified) concerning Sprint's online Picture
Mail service, we'd like to implore everyone reading this to maintain a sense of civility and not to immediately go
breaking into every account they can think of. That being said, we've been tipped by numerous people to a Howard Forums
thread that claims entering any Sprint phone number into the Picture Mail login page on PC and mobile browsers and
clicking OK will gain you access to the account -- no password necessary. Not only are Sprint customers' pictures and
videos completely unprotected, the bug also allows anyone to view the email address associated with the given phone
number (even if he/she doesn't upload photos) -- thereby assembling your digits, your name, and pictures of yourself
and your family into one handy, stalker-friendly package. We hope that publishing this major flaw will allow our
readers to take down any pics they may want to remain private,
and more importantly, that it will cause Sprint to fix this problem ASAP.Update: Mark Z. informed us that the Picture Mail login option has been replaced with a generic maintenance page. We'll save you the specifics, because the real message is written between the lines: "Please excuse our appearance while our PR team finishes with damage control."
[Thanks to everyone who sent this in]
















Reader Comments (Page 1 of 1)
Justin Gehring @ Mar 23rd 2006 12:57AM
I knew there was a reason i didn't go with sprint...
Brian @ Mar 23rd 2006 1:40AM
Seems to be fixed (just checked against my own Sprint PCS number).
jeff @ Mar 23rd 2006 1:53AM
i just confirmed the bug. It definitely is NOT fixed. (give me your sprint phone number and i'll prove it to you.)
that's crazy. how horribly pathetic. you're SPRINT, for god sakes, cant you use real security?
Any dumbass with my number could delete the last 4 years of images. that's nuts. (i keep local copies, but that's still just unheard of.)
april medellin @ Feb 20th 2008 8:32PM
check mine send me an email and I will give you the numbers to check
keats @ Mar 23rd 2006 1:56AM
oh sh*t. it still works. but only accessable from a phone. on my laptop it didn'y work from my treo 650. worked just fine...
better go erase SOME photos...
Steve @ Mar 23rd 2006 2:02AM
sites down now
keats @ Mar 23rd 2006 2:03AM
picturemail site just went down. lets hope they are fixing it right now....
let's also hope no one grabbed any pictures... my fiancee might get mad...
SL @ Mar 23rd 2006 2:38AM
Wow... that's pretty insane. Almost just as bad as that one guy that got into all those governmental computers because the admin accounts had blank passwords associated with them.
Needless to say... Someone at Sprint is in deep... stuff.
Raghu @ Mar 23rd 2006 2:43AM
What's more insane is that there enough people awake past 2 AM EST to follow this as a breaking story. Just hope most of you are not in Eastern zone and working like sorry*** me
Casey @ Mar 23rd 2006 5:34AM
Sprint Picture Mail site: "The site is temporarily unavailable due to routine maintenance and enhancements. We apologize for the inconvenience. Please come back soon!"
Vic @ Mar 23rd 2006 7:11AM
Well thanks guy's PM is now down for me so there is no free push mail for me today!
Mr Wave Theory @ Mar 23rd 2006 7:28AM
Mr Wave Theory thinks that there is a Bubble 2.0 for Web 2.0 and Most Analysts Are Overestimating the Size of Google's Total Addressable Market for Internet Advertising
I am sick and tired of hearing analysts make wild projections about Google's growth prospects based on wild projections about the size of Google's total addressable market.
Continued ...
Mr Wave Theory @ Mar 23rd 2006 7:29AM
Mr Wave Theory thinks that there is a Bubble 2.0 for Web 2.0 and Most Analysts Are Overestimating the Size of Google's Total Addressable Market for Internet Advertising
I am sick and tired of hearing analysts make wild projections about Google's growth prospects based on wild projections about the size of Google's total addressable market.
http://mrwavetheory.blogspot.com/2006/03/bubble-2.html
Edfox @ Mar 23rd 2006 10:00AM
I just tried it, and it's working. If you type in a password it will tell you it's wrong or if you leave it empty, it says that you didn't enter a password. I tried it at work with my own number.
mobile_guy @ Mar 23rd 2006 7:56PM
This post seams to be like a rumour, i checked i cannot breakinto picture mail system without mdn and right password.
Dav @ Mar 29th 2006 8:42PM
This is funny because January 2006 was supposed to be Sprint's "Commitment to Security". pfff
via this link:
http://www2.sprint.com/mr/cda_pkDetail.do?id=1100
jimmy @ Aug 7th 2007 7:01PM
what ups i like it.
rsleewa2004 @ Jul 19th 2008 1:11AM
it is good