Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

SMS smrti (sms-o-death)

[es] :: Advocacy :: SMS smrti (sms-o-death)

[ Pregleda: 2273 | Odgovora: 3 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

Horvat

Član broj: 17332
Poruke: 3042
dynamic-78-30-143-91.adsl.eunet.rs.



+165 Profil

icon SMS smrti (sms-o-death)05.01.2011. u 12:10 - pre 162 meseci
Citat:
Simplest Phones Open to ‘SMS of Death’

* By John Borland Email Author
* December 28, 2010 |
* 2:20 pm |
* Categories: Chaos Computer Club
*

BERLIN — It’s a scene from an as-yet-unmade thriller: Across a country, tens of thousands of cellphones all blink white at the same, and turn themselves off. Calls are lost, phones are rendered useless, and the affected mobile operator is forced to pay a ransom or lose customers.


Once phones, now glowing bits of plastic.

It hasn’t happened yet. But speaking at the Chaos Computer Club Congress here, German researchers showed how vulnerabilities in some the simplest, but most common phones in the world could conceivably lead to just such a scenario.

Mobile phone security has been a growing concern due to the increasing popularity of smartphones, whose web-browsing and app-running capabilities allow attacks similar to those made against computers. Yet more than 85 percent of the world’s cellphones are feature phones — simple devices with the ability to play MP3s or browse the web, but without the power of the iPhone or Android-based handsets.

Vulnerabilities have been found in this type of phone before, but new open source tools allowing individuals to set up their own private GSM networks have helped researchers find a host of bugs ranging from pesky to serious in many of the world’s most common handsets.

“With the openness in the GSM on the network side, we can look at the closed stuff now,” said Collin Mulliner, a researcher at Berlin’s Technical University. “And if we’re able to look at closed stuff, it usually breaks.”

Mulliner and colleague Nico Golde set up their own GSM network in their lab, allowing them to freely test the effects of sending SMS messages containing a variety of potentially damaging payloads.

The result was bugs, and plenty of them. Popular models of phones from Nokia (the S40 and related models, except for the very newest release), Sony Ericsson (w800 and several related models), LG (LG 320), Samsung (S5230 Star and S3250) Motorola (the RAZR, ROKR, and SVLR L7) and India’s Micromax (X114) all proved susceptible to what researchers termed an “SMS of death.”


The exact results differed for each phone. In the worst cases, including the Nokia and Sony Ericsson, the message would disconnect the phone and force it to reboot, without registering the fact of the message’s receipt — in most cases forcing the operator’s network to continue sending the message and triggering the shutdown cycle again. Fixing the problem required putting the SIM card into a new, unsusceptible phone.

In the other cases, the payload-laden messages forced the phones’ interfaces to shut down, and disconnected the devices from the network. The researchers stressed that other phones likely had similar problems, but their research had focused on these common models.

At first glance, these problems appear to be relatively minor compared to the botnet or trojan susceptibilities of smartphones. But these simple attacks could cause serious problems, potentially for a single well-chosen target, or — more disturbingly — if launched on a large scale.

This could be relatively easily done, Mulliner said. In Germany, for example, mobile-phone-number prefixes are associated with specific operators, allowing large-scale attacks to be mounted on a single operator’s customer base relatively easily. Bulk SMS messages tailored to attack specific common phones by the thousands could be sent using commercial SMS spam services, by activating botnets hiding on mobile phones, or even by an insider at a telephone company.

This kind of large-scale attack potential raises the possibility that a telco itself could be held hostage by an outsider threatening to flood its customers with reboots or even broken phones, researchers said.

Alternately, some police forces around the world rely on cellphones to communicate in areas where their two-way radios function poorly. An attack on a common model used by a police force could disrupt communications at a critical time.

The problem is these problems aren’t easy to fix. Inexpensive “feature phones” rarely if ever receive firmware updates today. But the potential for abuse of bugs that are becoming easier to find means this practice might have to change, the researchers said.

“Manufacturers need to find a way to do firmware updates, and make sure to advertise them,” Mulliner said.

izvor


link do dogadjaja

link do sirovog snimka prezentovanja
 
Odgovor na temu

mmix
Miljan Mitrović
Profesorkin muz
Passau, Deutschland

SuperModerator
Član broj: 17944
Poruke: 6042



+4631 Profil

icon Re: SMS smrti (sms-o-death)05.01.2011. u 13:54 - pre 162 meseci
Tja, kod nas se to desava non-stop i bez sms-of-death :)
Sloba je za 12 godina promenio antropološki kod srpskog naroda. On je od jednog naroda koji je bio veseo, pomalo površan, od jednog naroda koji je bio znatiželjan, koji je voleo da vidi, da putuje, da upozna,
od naroda koji je bio kosmopolitski napravio narod koji je namršten, mrzovoljan, sumnjicav, zaplašen, narod koji se stalno nešto žali, kome je stalno neko kriv… - Z.Đinđić
 
Odgovor na temu

xtraya
Vladanko Vladanovic
Belgrado

Član broj: 323
Poruke: 1011
85.222.218.*

ICQ: 6072593


+49 Profil

icon Re: SMS smrti (sms-o-death)05.01.2011. u 14:47 - pre 162 meseci
najbolja fora je sto su kontaktirali sve proizvodjace (cije su aparate koristili)putem emaila , pa su samo nokiu uspeli nekako preko veze da kontaktiraju... sve ostale srpski recheno "zabole" sto su im lesh aparati bushni ko sito ...
Hmmm , na VIP-u 3G preko iphone-a 2,6 Mbps DL i 1,4 UP ...
 
Odgovor na temu

Horvat

Član broj: 17332
Poruke: 3042
dynamic-78-30-143-91.adsl.eunet.rs.



+165 Profil

icon Re: SMS smrti (sms-o-death)05.01.2011. u 14:57 - pre 162 meseci
nokia se javila,a sony e. su preko neke veze nasli
motorolin [email protected] "ne radi", tj to niko ne cita
a ostali ni nemaju kontakt vezan za bezbednost aparata :D

a problem se javlja i jos zbog "brendiranih" telefona, kao i zakljucanih, jer se izmenom firmware-a moze anulirati to
 
Odgovor na temu

[es] :: Advocacy :: SMS smrti (sms-o-death)

[ Pregleda: 2273 | Odgovora: 3 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.