Unstructured Supplementary Service Data (USSD) is used by many banks as a method to provide mobile banking services in the region.
I was wondering if there is any way of intercepting the data and tampering with it over the wire.
Since USSD uses the normal GSM channels, I found this document the most useful so far:
http://events.ccc.de/congress/2010/Fahrplan/attachments/1783_101228.27C3.GSM-Sniffing.Nohl_Munaut.pdfCan anyone shed more light on how to test USSD services?