<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mobile Security &#187; proof</title>
	<atom:link href="https://blog.m-sec.net/tag/proof/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.m-sec.net</link>
	<description>When security is not enough</description>
	<lastBuildDate>Tue, 13 Nov 2012 20:58:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>About SIM card tracker app</title>
		<link>https://blog.m-sec.net/2012/about-sim-card-tracker-app/</link>
		<comments>https://blog.m-sec.net/2012/about-sim-card-tracker-app/#comments</comments>
		<pubDate>Fri, 07 Sep 2012 13:14:22 +0000</pubDate>
		<dc:creator>m-sec.net</dc:creator>
				<category><![CDATA[GSM]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[orange]]></category>
		<category><![CDATA[proof]]></category>
		<category><![CDATA[sim tracker]]></category>

		<guid isPermaLink="false">http://blog.m-sec.net/?p=115</guid>
		<description><![CDATA[Yesterday a tweet got my attention: &#8220;sim card tracker found on all orange sim cards. sends location, IMEI to operator, without your knowledge&#8220;.  As I am a little bit suspicious about this kind of things, I have asked to define &#8220;all&#8221; and &#8220;without your knowledge&#8221;. Immediately came the reply which confirmed my feeling: &#8220;the smart card [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday a tweet got my attention: &#8220;<em>sim card tracker found on all orange sim cards. sends location, IMEI to operator, without your knowledge</em>&#8220;.  As I am a little bit suspicious about this kind of things, I have asked to define &#8220;all&#8221; and &#8220;without your knowledge&#8221;. Immediately came the reply which confirmed my feeling: &#8220;the smart card sends it via SMS to the operator from the OS on the card&#8221;.</p>
<p>This tweet came during a great speech of Behrang Fouladi at 44con conference regarding .NET smart cards. His research is great and I want to make it clear from the beginning that I appreciate his work. The only thing that I don&#8217;t like is that generally people are trying to make a mountain out of a molehill from the fact that SIM sends a message to the operator.</p>
<p><strong>What is it about</strong>? SIM card has an app written on it and, when put into a different phone, it will automatically send a message to the operator informing it that now the customer uses another phone. Why this? Well the operator will automatically send you the MMS/Internet settings for this new phone so that you will not have to struggle with manual setup.</p>
<p><strong>Where is the tracking?</strong> Or how can we think about tracking when you are actually using the operator&#8217;s network and that at anytime the operator knows where you are, with a few meters precision, specially in a big city where they have more BTSs?</p>
<p>Some said this is the first time someone discovers such SIM app. I disagree &#8211; <a title="Bogdan Alecu - SIM Toolkit Attack" href="https://vimeo.com/37593949" target="_blank">I spoke about</a> this exactly behavior last year, at DeepSec 2011 conference. I haven&#8217;t given too much attention to it as I am inside the operator&#8217;s network and the SIM is sent to a number belonging to the operator. Here is the proof that people should&#8217;ve already knew about it:</p>
<p><iframe src="http://player.vimeo.com/video/49014603" frameborder="0" width="500" height="281"></iframe></p>
<p><a href="http://vimeo.com/49014603">Automatic SMS &#8211; Deepsec 2011</a> from <a href="http://vimeo.com/user7865508">Msec Net</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p><strong>What about the message that is being sent? What does it contain?</strong><br />
Before answering this, I have to make a note: it might be possible that in another country Orange SIM cards to send some more details, so I can&#8217;t certainly say that the info is incorrect. Last time I checked, one year ago, SIM card was sending the IMEI only. This morning I performed another trace to find out if anything changed, but it didn&#8217;t. Even if it might request for the Cell ID also, that information is not sent in this message.</p>
<p>Here is the SMS SUBMIT captured data</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_1.png"><img class="alignnone size-medium wp-image-116" title="autosms_1" src="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_1-300x225.png" alt="Automatic SMS -1" width="300" height="225" /></a></p>
<p>Here is the destination number to where the message was sent &#8211; this case 5692</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_2.png"><img class="alignnone size-medium wp-image-117" title="Auto SMS sent - 2" src="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_2-300x225.png" alt="" width="300" height="225" /></a></p>
<p>Now here is the data inside it, containing the IMEI of my phone</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_3.png"><img class="alignnone size-medium wp-image-118" title="Auto SMS send - 3" src="http://blog.m-sec.net/wp-content/uploads/2012/09/autosms_3-300x225.png" alt="" width="300" height="225" /></a></p>
<p>In the worst case scenario we could think about this message as &#8220;tracker&#8221; if it was sent regularly, at specific time frames. But guess what -<strong> it isn&#8217;t</strong>! <strong>It is sent only when you turn on the phone and that&#8217;s it</strong>.  The good question is indeed why would the operator need this when they already know your phone&#8217;s IMEI, without making the SIM supply it in a message? I can only speculate on this, but I think the explanation is that a long time ago the operator asked for this as a convenience &#8211; maybe for law enforcements or not &#8211; in order to not search to deep in the log files.</p>
<p><strong>Is this thing new?</strong><br />
You will actually be surprised to find out that it&#8217;s started back in 2005 &#8211; at least in Romania. Searching for that 5692 number on the web, I found an <a title="Automatic message topic on Softpedia" href="http://forum.softpedia.com/lofiversion/index.php/t7860-8750.html" target="_blank">old topic</a> from a Romanian forum which was discussing about this automatic message:</p>
<p><a href="http://blog.m-sec.net/wp-content/uploads/2012/09/Softpedia_5692_message.png"><img class="alignnone size-medium wp-image-119" title="Softpedia_5692_message" src="http://blog.m-sec.net/wp-content/uploads/2012/09/Softpedia_5692_message-300x141.png" alt="" width="300" height="141" /></a></p>
<p>As you can see, the topic date is <strong>26 December 2007</strong>!</p>
<p>Here are some excerpts from this topic, translated into English:</p>
<blockquote><p>six: Why on the Orange network, when I put my SIM card in a new or different phone I get on my Nokia display a message saying &#8220;Allow SIM card to send message&#8221;?</p>
<p>ionut.tabacaru: Starting 2 years ago, all these SIM cards automatically send a message to Orange, to a free of charge number 5692</p>
<p>kaytar: 3 days ago I&#8217;be put my SIM card into a different phone and I&#8217;ve received a message saying that in a few moments I will receive the WAP/MMS settings &#8230; and indeed I did get them</p>
<p>andreic: I am curious to find out what this SMS does</p>
<p>mailman: It communicates that the phone has changed and the network sends you the connection details for wap, mms</p></blockquote>
<p>If you don&#8217;t trust me, <a title="SMS topic" href="http://forum.softpedia.com/lofiversion/index.php/t7860-8750.html" target="_blank">open the topic</a> and use Google translate <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now about that &#8220;without your knowledge&#8221; thing. If you look closely on the above video you will notice that on Nokia phones you have the option to ask you about when the SIM cards wants to perform an action &#8211; you could allow it or not. Also during <a title="Bogdan Alecu - SIM Toolkit Attack" href="https://vimeo.com/37593949" target="_blank">my presentation</a> I said that these SIM toolkit messages generally inform the user by displaying &#8220;Sending message&#8221; info on the phone display. Not all phones can ask you if you allow the SIM to do that, but if you keep your eyes on the phone in the first few minutes after you turned it on, most probably you will notice this message being sent.</p>
<p>Finally I would like again to underline that I have nothing personal with Behrang, I appreciate all his findings, but this Orange SIM card tracker thing went a little bit too far.</p>
<p>Waiting for your comments <img src='https://blog.m-sec.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div id="tweetbutton115" class="tw_button" style=""><a href="http://twitter.com/share?url=https%3A%2F%2Fblog.m-sec.net%2F2012%2Fabout-sim-card-tracker-app%2F&amp;via=msecnet&amp;text=About%20SIM%20card%20tracker%20app&amp;related=&amp;lang=en&amp;count=horizontal&amp;counturl=https%3A%2F%2Fblog.m-sec.net%2F2012%2Fabout-sim-card-tracker-app%2F" class="twitter-share-button"  style="width:55px;height:22px;background:transparent url('https://blog.m-sec.net/wp-content/plugins/wp-tweet-button/tweetn.png') no-repeat  0 0;text-align:left;text-indent:-9999px;display:block;">Tweet</a></div>]]></content:encoded>
			<wfw:commentRss>https://blog.m-sec.net/2012/about-sim-card-tracker-app/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
