CDMA and 4G fall at DEF CON?

Post » Tue Dec 06, 2011 2:29 pm

http://seclists.org/fulldisclosure/2011/Aug/76

some characteristics:

- full active MitM against CDMA and 4G connections from Rio to carriers.

- MitM positioning for remote exploitation to ring0 on Android and PC.

- fall back to userspace only or non-persistent methods when
persistent rootkit unattainable.

- many attack trees and weaponized exploits. escalation from easy pwns
up to specialized techniques and tactics until success is achieved.

- simultaneous attack across CDMA and 4G connections using full power
in these LICENSED bands.

- operated continuously (except for outages :) from early Saturday
until 8am Monday.

- designed with intent: mass exploitation, reconnaissance,
exfiltration, eavesdropping.


It's not clear yet just how bad this is. Whether eavesdropping in on phonecalls is possible with this hasn't been made clear yet. There seems to be a non-disclosure agreement keeping the exploit details from being published at the moment, or otherwise it hasn't been released yet (it wasn't a panel).

What this potentially means is that cellphones are completely and undeniably the biggest security and privacy risk for anyone. CDMA had thus far stood up as being resiliant to all attempts to break in. The entry costs were huge and the crpto seemed good. Only time will tell if this is as bad as the GSM hack (GSM can be eavesdropped on for as little as $200 with enough effort, otherwise $2000 will get a person the equipment necessary to eavesdrop, reroute phonecalls, read text messages, drop your service, potentially gain access to your phone's contacts and other personal information, etc --- Yeah, GSM is a totally broken horse, BTW: This has been true for about 3 years now, 6 years if you had a better budget)

So maybe it's time to start considering carrier pigeons again? :P At the least, please be aware that your phone conversations are easily compromised and be careful ;)


Oh, and of course this means nothing to Europeans: You guys are completely stuck with the totally-utterly-ridiculously broken GSM that all your phonecalls are probably being recorded already :P
User avatar
Petr Jordy Zugar
 
Posts: 3497
Joined: Tue Jul 03, 2007 10:10 pm

Post » Tue Dec 06, 2011 7:01 am

I have no idea what I just read... but I'm frightened by it.
User avatar
-__^
 
Posts: 3420
Joined: Mon Nov 20, 2006 4:48 pm

Post » Tue Dec 06, 2011 2:13 pm

As long as it only affects cell phones then I'm not affected, but this seems like it could be a very bad thing if it's widespread.
User avatar
Carlos Vazquez
 
Posts: 3407
Joined: Sat Aug 25, 2007 10:19 am

Post » Tue Dec 06, 2011 3:46 pm

I have no idea what I just read...

THIS!
I'm guessing the government (or someone else) is spying on cell phones. Nothing new here.
User avatar
Kirsty Wood
 
Posts: 3461
Joined: Tue Aug 15, 2006 10:41 am

Post » Tue Dec 06, 2011 5:50 am

THIS!
I'm guessing the government (or someone else) is spying on cell phones. Nothing new here.

Someone else, basically anyone else. 4G being hacked would mean someone could redirect your mobile web browsing and send you to phishing sites. They then get your username and password and, since most people use the same password for all sites, they could then go steal money from their bank account and do all sorts of other fun things.
User avatar
Conor Byrne
 
Posts: 3411
Joined: Wed Jul 11, 2007 3:37 pm

Post » Tue Dec 06, 2011 12:21 am

Well damn.

Thankfully, I use a password manager now. And I use KeePassDroid on my phone.

But seriously? Ring 0? Geez...
User avatar
Haley Merkley
 
Posts: 3356
Joined: Sat Jan 13, 2007 12:53 pm

Post » Tue Dec 06, 2011 9:05 am

So maybe it's time to start considering carrier pigeons again? :P


Nah, during WW2 germans trained falcons to catch allies carrier pidgeons. If you want to communicate safely, talk to yourself in a soundproof room :teehee:
User avatar
Amelia Pritchard
 
Posts: 3445
Joined: Mon Jul 24, 2006 2:40 am

Post » Tue Dec 06, 2011 1:11 am

Nah, during WW2 germans trained falcons to catch allies carrier pidgeons. If you want to communicate safely, talk to yourself in a soundproof room :teehee:

http://www.youtube.com/watch?v=HwBmPiOmEGQ
User avatar
Philip Rua
 
Posts: 3348
Joined: Sun May 06, 2007 11:53 am

Post » Tue Dec 06, 2011 3:03 pm

http://www.youtube.com/watch?v=HwBmPiOmEGQ


In a windowless soundproof room?
User avatar
bimsy
 
Posts: 3541
Joined: Wed Oct 11, 2006 3:04 pm

Post » Tue Dec 06, 2011 8:48 am

Well damn.

Thankfully, I use a password manager now. And I use KeePassDroid on my phone.

But seriously? Ring 0? Geez...

One of my favorite panels from the Chaos Communication Congress last year was Baseband Apocalypse. Part of it covered how to run arbitrary code and do buffer overflow attacks over GSM against iPhones (and a few other potential phones) All for only $1000. Another part of it covered briefly a potential use to remote control other people's cars that are GSM-enabled... while they are still in it.

http://www.youtube.com/watch?v=TzR7R6fBr00&t=50m10s
User avatar
Adrian Morales
 
Posts: 3474
Joined: Fri Aug 10, 2007 3:19 am


Return to Othor Games