<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; fuzzing</title>
	<atom:link href="https://blog.m-sec.net/tag/fuzzing/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>SIM Toolkit Attack</title>
		<link>https://blog.m-sec.net/2011/sim-toolkit-attack/</link>
		<comments>https://blog.m-sec.net/2011/sim-toolkit-attack/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 18:03:04 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[GSM]]></category>
		<category><![CDATA[Phone]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[alecu]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[deepsec]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[recording]]></category>
		<category><![CDATA[sim toolkit]]></category>
		<category><![CDATA[sms]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=86</guid>
		<description><![CDATA[Hi all, I must say it was a real pleasure to attend the DeepSec 2011 edition. I&#8217;ve met a lot of interesting people and all the talks were great. Since it was my first time I held an international talk with such large audience, I was a little bit excited, but no matter what, I [...]]]></description>
			<content:encoded><![CDATA[<p>Hi all,</p>
<p>I must say it was a real pleasure to attend the <a title="DeepSec website" href="http://deepsec.net/" target="_blank">DeepSec</a> 2011 edition. I&#8217;ve met a lot of interesting people and all the talks were great. Since it was my first time I held an international talk with such large audience, I was a little bit excited, but no matter what, I still consider I did a pretty good job. By now I only got positive feedback <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>To answer some of the frequently asked questions:</p>
<p>1. The attack I showed has nothing to do with knowing the security keys as the response to the command is being sent even if there&#8217;s an error</p>
<p>2. The live demo worked &#8211; too bad I didn&#8217;t have a webcam to show you the target phone</p>
<p>3. There was no planning on who should volunteer for the live demo</p>
<p>4. The number you&#8217;ve seen during the demo is not the real number (only the first 3 digits were) and also wasn&#8217;t charged with 5 EUR &#8211; all it was just for the fun of it <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>5. The quickest way to protect is to change your phone to one that asks for your permission before allowing the SIM card to do something, or switch to another operator that doesn&#8217;t provide SIM cards with Toolkit Application on them &#8211; in Austria it&#8217;s at least one, as well in Romania <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>6. Pay attention to dual-SIM phones: some of them are not showing you the extra-menu belonging to the SIM application, so don&#8217;t get comfortable thinking that you&#8217;re protected</p>
<p>7. I&#8217;m not a hacker / cracker how the media likes to call the security specialists most of the times. My purpose was to make you aware of the danger of just using something like SMS</p>
<p>I was happy that right after the talk I&#8217;ve been contacted by <a title="Research In Motion" href="http://www.rim.com" target="_blank">RIM</a> in order to send them the details to fix this. It&#8217;s good to see that someone pays attention to these details. As long as they agree, I&#8217;ll keep you up to date with how the things are going.</p>
<p>Thank you Lynx, MiKa, Manuela for this opportunity! I&#8217;m pretty sure I&#8217;ll see you next year also <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I also hope that next year there will be more people from Romania in the audience.</p>
<p>Below it&#8217;s a recording of my talk SMS fuzzing, SIM Toolkit Attack &#8211; I hope you&#8217;ll ignore my excitement <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<iframe src="http://player.vimeo.com/video/32481186" frameborder="0" width="550" height="470"></iframe></p>
<p>The slides from the talk can be found here (<a title="SIM Toolkit Attack slides" href="http://prezi.com/lmmptb0qldfb/sim-toolkit-attack/" target="_blank">click me</a>).</p>
<p>I wait for your feedback!</p>
<div id="tweetbutton86" class="tw_button" style=""><a href="http://twitter.com/share?url=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fsim-toolkit-attack%2F&amp;via=msecnet&amp;text=SIM%20Toolkit%20Attack&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=https%3A%2F%2Fblog.m-sec.net%2F2011%2Fsim-toolkit-attack%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('https://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>https://blog.m-sec.net/2011/sim-toolkit-attack/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
	</channel>
</rss>
