Joke Collection Website - Blessing messages - What is the principle of SMS bombing and how to prevent it?

What is the principle of SMS bombing and how to prevent it?

Principle of SMS bombing:

SMS bombing refers to sending HTTP requests through malicious programs, and sending a dynamic short message (such as verification code message) to users each time by using the dynamic short URL found on various websites (such as the URL sent by verification code) and the mobile phone number of the attacked person input by the front end.

The end result is to send a lot of verification code messages to many unrelated mobile phone users. As a result, mobile phone users are harassed.

Methods to prevent short message bombing;

Malicious attackers use malicious tools to call the "dynamic verification code short message acquisition interface" to send dynamic short messages. The reason is that the attacker can automatically make a lot of calls to the interface.

Using the picture verification code can effectively prevent the automatic calling of malicious tools, that is, the picture verification code pops up before the user performs the "dynamic verification code short message sending" operation, and the server sends a dynamic short message to the user's mobile phone after asking the user to input the verification code. This method can effectively solve the problem of being used to carry out bomb attacks.

Extended data

Many SMS bombs use this mobile phone verification code mechanism to make lists with many websites and send verification code messages to designated mobile phone numbers. The author of SMS Bomb can quickly realize that a single website can send multiple pieces of verification code information to the same mobile phone number through the "send mobile phone verification code" interface of these registered websites.

Submitting a large number of short messages in a short time will use a large number of server equipment and operator equipment of the target website. Perhaps the target website or operator can solve the bombing behavior in some way. Through this principle, we can think of other types of bombers, who can't quickly add these verification code messages to the blacklist, but can temporarily reject the messages.