EH-Net

Ethical Hacking Discussions and Related Certifications => Mobile => Topic started by: pseud0 on August 10, 2011, 10:50:23 AM



Title: Defcon 19: 4G and CDMA hack
Post by: pseud0 on August 10, 2011, 10:50:23 AM
If this is accurate then the mobile industry just got kicked in the teeth.  Out of an abundance of caution I'm re-imaging my phone.

http://mobile.slashdot.org/story/11/08/10/1338201/4G-and-CDMA-Reportedly-Hacked-At-DEFCON
 
http://seclists.org/fulldisclosure/2011/Aug/76


Title: Re: Defcon 19: 4G and CDMA hack
Post by: j0rDy on August 11, 2011, 02:52:07 AM
again, another big PWND at a security conference. remember the fake atm at blackhat last year? (if i remember correctly) next time not only take a clean laptop, but a clean phone also.


Title: Re: Defcon 19: 4G and CDMA hack
Post by: tturner on August 11, 2011, 07:51:26 AM
So far I've not seen any confirmation of this. It is possibly a hoax. Can't believe everything you read on FD.

Can anyone confirm?


Title: Re: Defcon 19: 4G and CDMA hack
Post by: pseud0 on August 11, 2011, 06:05:45 PM
There is some anecdotal confirmation from various folks but nothing I'd consider hard proof.  I saw various update alerts on my phone on Saturday but I ignored them, and I was getting certificate errors when I started to browse to my junk mail bucket (hotmail) at which point I killed the session.  Some other folks have posted that they had more explicit events (emails from themselves and such), but still nothing outrageous.  The laptop I had tethered to my droid was a blank/patched ubuntu install that was nuked 5 minutes after I walked back into my house. As for the phone, well, it was time to try out cyanogenmod 7 anyway.


Title: Re: Defcon 19: 4G and CDMA hack
Post by: H1t M0nk3y on August 11, 2011, 06:36:00 PM
Me, I received some emails twice and they arrived quite late (6 hours after they have been sent to me). But hey, I was expecting this to happen!