Categorized | Security

‘SMS of Death’ and GSM Eavesdropping Revealed in Berlin

Thumbnail image for gsmbasestation.jpgThe annual Chaos Communication Congress (CCC) in Berlin has seen revelations of an ‘SMS of Death’ attack against many conventional non-smartphones and a toolkit for eavesdropping on calls and text messages ob any GSM network.

The SMS of Death involves a malicious SMS text message to a phone which can effectively ‘brick’ the phone (make it useless). The research focused not on smart phones like the iPhone, but on less sophisticated phones like the Nokia N40, the Motorola RAZR and the Samsung S5230 Star and S3250. In some cases, the attack would disconnect the phone and force it to reboot; but since the phone did not acknowledge receipt of the message, the network would continue sending it.

The attack probably isn’t as scary as the name implies. Attacks like this have been found many times in the past and are always dealt with by network providers by filtering at their end. This may have already been done in the case of the SMS of Death.

The GSM attack, described in this BBC story. GSM (Global System for Mobile communications) is the most popular network architecture for mobile telephone systems, servicing an estimated 5 billion devices and dominant outside of the US. Researchers Karsten Nohl and Silvain Munaut demonstrated at the CCC a kit which can locate any GSM phone by taking its unique ID and using it to intercept data transferred between the phone and base. They decrypt this transmission using a decryption tool using a ‘rainbow key’. If such a technique works, it probably indicates a fundamental weakness in GSM encryption.

Hat tip on the GSM issue to Threatpost.



Full story: Security Watch

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago