skip to main |
skip to sidebar
According to experts, 113 devices are lost or stolen
every minute in the Unites States. Because of the large number of
incidents, many phone owners deploy some sort of anti-theft/anti-loss
solutions to protect their data or to track down their smartphones in
case they get lost.
In the case of Samsung smartphones, the service is called Samsung
Dive. The system allows the phone’s owner to pinpoint the whereabouts of
the device via GPS and other location acquisition techniques.
In case of Phone theft the Thief can simply broadcast a fake location on
Samsung tracking server and mislead Original Phone User/Owner to
believe that the phone is genuinely at fake location. The locations can
be faked continuously to random places anywhere in the world.
All this happens because Samsung’s Location API’s are completely
vulnerable to be manipulated by installing commonly available simple GPS
location spoofer on the device.
Another noteworthy thing is that Samsung’s tracking application shows
notifications when the device is being remotely monitored.
This simply alerts the hacker or thief. This defeats the very
fundamental principal and purpose of a tracking application, which
should always work on the principal of hidden remote tracking in case of
theft.
Though other applications like AVG and famous tracking application
like Lookout also provide similar Services were are also vulnerable to
location spoofing but Samsung's own tracking service becomes far more
critical and important as Samsung is the device Manufacturer and
tracking module comes inbuilt in the phone and most widely used. Since
such tracking applications also provide remote data wipe service also,
Phone owners always prefers device manufacturers solution instead of a
Third party tracking application
Apart from this Location spoofing Vulnerability, To make thing worse,
Samsung tracking application also shows notification that device is
being tracked remotely. This simply alerts the hacker or thief. This
defeats the very fundamental principal and purpose of a tracking
application, which should always work on the principal of hidden remote
tracking in case of theft.
We’ve contacted Samsung to find out if they’re aware of this issue and
if they plan on doing anything to address it. We’ll return with more
details once they become available.
The researcher Atul Alex has presented at last edition of
International Malware Conference (MalCon) how it is possible to attack
every mobile devices with a special hardware designed using common
electronic components.
Atul Alex presented a paper
that covers “abusing voice dialing and combining Arduino /
Microcontroller to steal private data on iphone, Android, Windows Phone
and Blackberry using only the Audio jack.
Mobile devices are sophisticated devices that manage a huge quantity
user’s information and their exploit could open the door to a mine of
sensible data, due this reason the expert provides that in incoming
months defense system will be reinforced and it will be more difficult
in the future software based attacks.
It must be considered that an efficient attack on large scale against
mobile world have to be able to infect multi platform devices.
During its presentation Atul Alex explained how to transform any
mobile device into a spy tool, avoiding the installation of any
malicious software on it, abusing voice dialing feature which is enabled
by default on all mobile platforms.
Modern devices are equipped with powerful software able to interpret
user’s vocal commands, the hardware device proposed by Alex Atul is able
to mimic them to give orders to the device. The functionality opens
future scenarios in which hackers are able to control phone simply
sending unauthorized text messages to steal sensible data.
Almost all events on the mobile are notified to the user with the
help of corresponding tones/sounds, the researched has demonstrated that
adding a microcontroller to the headset’s circuit is possible to:
- Initiate phone calls without user interaction.
- Note duration of phone calls.
- Detect incoming/outgoing calls, sms & so on.
In the future versions the hardware could also integrate more complex
functionalities such as recording of phone calls or remote activation
of the device.
For sure similar devices will represent in the future a privileged option for cyber espionage
operations and more in general for cyber operations. Many governments
are working or financing projects for development of new cyber tools.
Government agencies have massively invested in programs to “violate”
citizen’s privacy in the name of national security, world is changed from 11/9 and the risk of a new dramatic cyber attack is high.
The Defense Advanced Research Projects Agency (DARPA) is one of the
most advanced agency in this sense, it is responsible for the
development of new technologies for use by the military and recently it
has proposed a device called the Power Pwn
designed by Pwnie Express company that apparently look like a surge
protector, but it’s a powerful tool to infiltrate networks allowing
remote access to every machine.
How to defend our device from similar attacks? In the future every
interface of mobile device have to be properly designed, every input
must be validated by a specially designed circuitry.
Another factor to consider as critical is the qualification
of hardware for devices similar to the one described in the research ,
different compromised components may invade the consumer market with
disastrous consequences, it is necessary a great effort to avoid
dangerous incidents.
A French hacker has released a tool capable of sending SMSes with
spoofed sender details on the iPhone 4. The sendrawpdu command line
interface tool allows users to customise the reply number on SMSes and
could be ideal for phishing attacks.
Researcher revealed an SMS spoofing flaw
that affects every version of Apple’s mobile OS. Using the flaw,
hackers could spoof their identities via text and send messages asking
for private information (by pretending to be from a users’ bank, for
example), or direct users to phishing sites.
pod2g highlights several ways in which malicious parties could take
advantage of this flaw, including phishing attempts linking users to
sites collecting personal information or spoofing messages for the
purposes of creating false evidence or gaining a recipient’s trust to
enable further nefarious action.
In many cases the malicious party would need to know the name and
number of a trusted contact of the recipient in order for their efforts
to be effective, but the phishing example shows how malicious parties
could cast broad nets hoping to snare users by pretending to be a common
bank or other institution.
French hacker has published on his blog that he developed iPhone SMS
security app and called it Sendrawpdu. The tool is designed for iPhone
4, and can be downloaded free of charge from the service repository
Github where you can find the app.
Download
https://github.com/pod2g/sendrawpdu
Main types of known Attacks :-
Rogue Base station Attacks
- GSM standards mandate authentication of mobile devices by the network but not vice-versa.
- Attackers run their own BSS with powerful radio antennas and using
proximity, fools a mobile device into attaching to itself instead of a
legitimate BSS.
- Base Station hardware and Open Source software (e.g. OpenBTS, OpenBSC) are available in public.
- Allows an attacker to intercept outbound voice, identify subscriber’s geo-location and capture a subscriber’s IMSI.
Track Location Attacks
- An attacker’s objective is to identify a subscriber’s geo-location.
- For attacking wider areas, MSC information can be leaked from HLR. For local area attacks, a rogue BSS can be used.
- Obfuscated MSC code is stored inside the HLR, each of which has mapping to a physical area.
- Rogue BSS can be used to launch active or passive attacks for the purpose of knowing subscriber’s geo-location
- Active Attack: a rogue BSS can send RRLP (Radio Resource Location
services Protocol) request and the phone will return the geo-location.
Also the BSS can force a handset into a higher power level and can
calculate the location from its electro-magnetic signature.
- Passive: by intercepting TA (Timing Advance) and Power Level data
send from mobile phone. In GSM, TA is the length of time a signal takes
to reach from a mobile device to the BSS. Each mobile device transmits
periodically less than 1/8th of the eight TDMA time slots. Since each
device is at a different distance and the signal travels at a finite
speed, the precise arrival time within a time slot allows BSS to
determine the distance of the device.
Attacks on Subscriber Information
- An attacker’s objective is to know the billing entity name for a given MSISDN number.
- Caller ID query on CNAM can reveal the organization, individual and business details.
- Caller ID databases are generally accessible through VoIP.
Encryption Attacks
- Mobile networks communicate with mobile devices with TMSI. A TMSI is mapped to MSISDN.
- An attacker’s objective is to find the MSISDN, then read the traffic and decrypt.
- TMSI can be discovered by a number of techniques. Two of the common known techniques are: Silent Paging and Silent SMS:
- Silent Paging: to Page a device silently, an adversary calls the
target MSISDN and hangs up before the BSS initiates the process to alert
the called device. Then the adversary scans the PCH (Paging Channel)
for incoming call broadcasts. From that, it retrieves the TMSI or IMSI.
- Silent SMS: the adversary sends a specially crafted silent SMS which
is acknowledged by the device without displaying it. This is possible
by changing the “data_coding” attribute of GSM 03.38 to ’0xC0′. When
the mobile device receives an SMS with data_coding set to the value, it
sends a delivery notification but discards the message and hence it is
never displayed. The adversary then scans the PCH and captures the TMSI
or IMSI.
- Knowing TMSI allows an adversary to monitor specific target MSISDN.
Then using cryptanalysis the adversary cracks the session key and
records the call content.
- The adversary typically requires a set of RF equipment and a cracking infrastructure:
- RF Equipments: Universal Software Radio Peripheral, Wide-band
receiver and low-cost mobile phone with custom firmware (e.g.
OsmocomBB).
- Cracking Infrastructure: FPGAs (Field Programmable Gate Arrays), low cost PCs and Rainbow table.
Attacks on Mobile Devices
- Compromising a targeted mobile device gives an adversary easy access to user information.
- Typically, the following types of attacks are known to be
successfully used: Baseband Attack, Messaging Attack, Application Attack
and a Mixed Attack.
- A Baseband Attack targets the underlying RTOS operating system of a
device. Most of them are written in C and Assembly language for which an
adversary has access to publicly available vulnerability information
and exploits. Many of the RTOS lack security features like stack
protection, address space layout randomization etc.
- A Messaging Attack targets protocol and/or architectural vulnerabilities and implementation vulnerabilities.
- WAP and OTA push enables delivering unsolicited data to mobiles.
This can be and had been the source of some attacks e.g. DoS attack
using malformed WAP payload (ref: MSL-2008-001).
- MMS Spoofing can be achieved for example, by using vulnerabilities
in a web application’s session management. The adversary attempts to
illegitimately charge a victim for MMS sent.
- A number of vulnerabilities occur due to faulty implementation of a
protocol or technology standard. Some of the known examples are iPhone
SMS attack (by Collin Mulliner and Charlie Miller), SMS curse of
silence (by Tobias Engel)
- With increasingly powerful smart phones, mobile applications are
becoming attack vectors (Pwn2Own attack on iPhone Safari browser by
Ralf- Philipp Weinmann and Vicenzo Lozzo)
- There are other types of known attacks e.g. iPhone PHP Perl
Compatibility Regular Expression vulnerability (for iPhone 1.x)
discovered by Charlie Miller.
Denial-of-Service Attacks
- DoS can be launched against network or a targeted mobile device.
- BSS has a limited number of control channels (RACH- Random Access
Channel). By flooding the channels, the services in an area can be
rendered unusable.
- IMSI Detach message is used to tear down a mobile device call from
the network. An adversary spoofs a detach message by using the IMSI of a
target device which will disconnect the device from the network making
the device useless for telephony activities.
SMS (Short Message Services) has become an extended part of modern day
life. Initially created to send non-sensitive information using spare
space in signaling channels, it has now evolved into a feature-rich
service.
How SMS is used to track the location of a mobile device
The law enforcement agencies used the basic principle that every time
a mobile device performs any activity, it exposes its presence to the
Cell tower. If the mobile network can force the mobile device to some
very short activity without making it perceptible to the user, then
using Radiolocation technologies, the mobile device can be tracked. To
do that, a special type of SMS known as “Silent SMS” is used. Every time
a silent SMS is delivered, the mobile silently acknowledges. This
creates activities for a mobile which is tracked by a LMU (Location
Measurement Unit) at BTS (Base Transceiver Station) by using a variety
of multilateration methods.
A commonly used technique for tracking location in GSM network is
called E-OTD (Enhanced-Observed Time Difference of arrival) . This is a
network-based location tracking method. In this technique, the signal
arrival time from the mobile device is measured from 3 BTS/LMUs’. The
position of the ME (Mobile Equipment) is determined by comparing the
time differences between two sets of timing measurements. The accuracy
is between 50 – 200 meters. More accurate location measurement is
possible using A-GPS (Assisted GPS) based systems.
In the past using Cell Tower log generated by forcing the target mobile
device into some activities, a target’s locations and movements were
accurately reconstructed and identified. In the USA vs. Forrest case,
police used similar techniques
The SMS message is specified by the ETSI in documents GSM 03.38 and
GSM 03.40. It can be up to 160 characters long, where each character is 7
bits. Eight-bit messages can contain up to 140 characters and are
usually not viewable by the phones as text messages. Instead they are
used for data in e.g. smart messaging (images and ringing tones) and
Over The Air (OTA) provisioning of Wireless Application Protocol (WAP)
settings.
Silent messages, often referred to as “Silent SMS” or “Stealth SMS”
is a type of SMS message which when received by a mobile device does not
notify either by the display or by a sound. GSM 03.40 describes a
Short Message of type 0 which indicates that the mobile equipment must acknowledge receipt of the short message but may discard its contents.
How to create Silent SMS
To create Silent SMS, the SMS PDU (Protocol Data Unit) needs to be
manipulated. It is best done from an application that communicates with
SMSC (SMS Center) using a protocol called SMPP. To send a SMS, the
application need to send SMPP GSM 03.38 encoded Submit_Sm PDU. A sample Submit_Sm PDU is shown below:
Encoding PDU Header . .’ command length ’ , ( 7 1 ) . . . 00 00 00 47
’ command id ’ , ( 4 ) . . . 00 00 00 04
’ command s t a tus ’ , ( 0 ) . . . 00 00 00 00
’ sequence number ’ , ( 1 ) . . . 00 00 00 01
Encoding PDU Body . .
’ service type ’ , ( 0 ) . . . 30 00
’ source_add r_ t o n ’ , ( 1 ) . . . 01 __ ’ source_ addr_ npi ’ , ( 1 ) . . . 01 **
‘source_ addr ’ , (27829239812) . . . 32 37 38 32 39 32 33 39 38 31 32 00
’dest_addr_ton ’ , ( 1 ) . . . 01 **
’dest_addr_npi ’ , ( 1 ) . . . 01 **
’dest_ addr’ , (27829239812) . . . 32 37 38 32 39 32 33 39 38 31 32 00
’esm_ class ’ , ( 0 ) . . . 00
’protocol_ id ’ , ( 0 ) . . . 00
’priority_flag ’ , ( 0 ) . . . 00
’schedule_delivery_time ’ , ( 0 ) . . . 30 00
’validity_period ’ , ( 0 ) . . . 30 00
’registered_delivery ’ , ( 1 ) . . . 01
’replace_ if_ present_fl ag ’ , ( 0 ) . . . 00
’data_coding ’ , ( 0 ) . . . 00
’sm_default_msg_ id ’ , ( 0 ) . . . 00
’sm_length ’ , ( 0 ) . . . 00
’short_message ’ , ( xyz..etc ) . . . 69 76 69 7A 73 65 63 75 72 69 74 79 2E 63 6F 6D
Full PDU ( 70 o c t e t s + + ) . . 00 00 00 47 00 00 00 04 00 00 00 00 00 00
00 01 30 00 01 01 32 37 38 32 39 32 33 39 38 31 32 00 01 01 32 37 38
32 39 32 33 39 38 31 32 00 00 00 00 30 00 30 00 01 00 00 00 00 73 61
74 6E 61 63 2E 6F 72 67 2E 7A
** ( 0 ) indicates local numeric numbering formatting
( 1 ) indicates international numeric number formatting
++ Octet is a group of 8 bits , often referred to as a byte
There are many different ways to manipulate SMS PDU but many of them
may cause mobile device malfunctioning. The two techniques described by N.J Croft and M.S Olivier ["A
silent SMS denial of service (DoS) attack," Proceedings of the Southern
African Telecommunication Networks and Applications Conference 2007
(SATNAC 2007), Sugar Beach Resort, Mauritius, September 2007 (Published
electronically)] were used and found working are: Manipulating Data Encoding Scheme and Manipulating Timing in a WAP Push Message.
In the first technique, the data_encoding attribute of SMS
PDU was set to 0xC0. This sets the MWIG (Message Waiting Indication
Group) identifier that as per GSM 03.38 translates to “Discard Message”.
The mobile device on receiving the message discards it after sending
delivery acknowledgement.
In the second technique, the scheduled_delivery_time is
set to a date and time before today in the format “YYMMDDhhmmsstnn”. It
was observed that the message was delivered, delivery acknowledgement
was sent by the mobile device but the message was never displayed.