28C3: New attacks on GSM mobiles and security measures shown (The H)
[Posted December 28, 2011 by corbet]
28C3: New attacks on GSM mobiles and security measures shown (The H)
[Security] Posted Dec 28, 2011 20:43 UTC (Wed) by corbet
The H reports
from the Chaos Communication Congress; the open-source Osmocom package
appears to be serving its intended purpose and finding vulnerabilities in
the cellphone network. "The researchers explained and then
demonstrated how, using the above technique and easily procurable tools,
attackers are able to emulate a mobile phone to make phone calls and send
text messages. They noted that some users have already received bills
totalling thousands of euros for calls and texts to Caribbean premium rate
services. In many cases, an attacker can, by simulating a GSM mobile, also
query that subscriber's mailbox providing they know the subscriber's
location and the key has not been changed."
Comments (35 posted)