7 ms·
Binary SMS – The old backdoor to your new thing
- locknload 8y agoSMS was always an effective procedure writing to certain parts of the phone without checks
- donttrack 8y agoI wonder why we haven't seen more exploits targeting SMS PDU mode. Is it the barrier for script kiddies just too high? You would probably need a network tester of some kind to properly try to find exploits. I used to work for a big mobile phone manufacturer and once in a while we would get "secret" fixes to merge into the source. The commit message would be something unrelated and the builds would be pushed silently without much fanfare. I was in charge for the merging, which is how I know this. Some of those fixes were for SMS PDU mode or related to stuff happening when PDUs were received. Not sure how phones handle these messages today, but I assume they follow spec, which means there are certain SMS PDUs which will be reacted on silently in the background (stuff in the PDU body is parsed and applications launched if necessary). I should try to get an old R&S tester from eBay maybe. Could be fun to try to explore this area. Could be a nice security business niche to get into.
- IronBacon 8y agoI think I've seen a presentation from CCC years ago where they demonstrated an "SMS of death" (similar to the "ping of death") where they rebooted various brands of phones. I don't have a link at hand, I recall they used a SMS modem and they didn't reveal a lot of details (I'm not even sure if they rebooted or bricked the receiving phones) for abuse concerns, but it should probably easy to find. edit: it was easier than I thought, first hit on Google: https://media.ccc.de/v/27c3-4060-en-attacking_mobile_phones https://media.ccc.de/v/27c3-4060-en-attacking_mobile_phones
- HillaryBriss 8y agoLaw Enforcement can track a phone with 'silent' SMS messages designed not to alert the user. well, that's something i didn't know
- War_tijn 8y agoAs far as I know they can only see to which tower your phone is connected, so it's not too accurate. I'm not an expert in this field though.
- adrianN 8y agoWhen I was playing around with that about ten years ago you could triangulate the position using multiple towers to narrow it down to a radius of a few dozen meters. It depends of course on the density of towers around the phone.
- chatmasta 8y agoIf you repeatedly triangulate a phone at < 100m resolution for a few hours, it should become trivial to identify its exact location. The more people in the area, the less reliable the method is. But in rural or suburban areas, it's going to be pretty good. See the LocationSmart stories the past few days for more on this.
- tinus_hn 8y agoIt isn’t like they track the phone using the messages, instead you can more accurately track the phone if it is sending and receiving things; the network needs to know more to make the connection work. So sending the phone things that don’t do anything puts it in a state where you can track it more accurately, and then you need to cooperate with the provider to actually track it. They can track you the same way if they would just call you. That would be kind of conspicuous so that’s why they use silent messages instead. But it isn’t like you can send a message that tells the phone to reports its location.
- ian0 8y agoGenerally you wouldn't need any type of messaging to the handset for this. As the phone periodically reports the signal strengths of surrounding cells for the purposes of handover just taking a glimpse of this is enough to triangulate well. As long as your phone is on your broadcasting. Indeed I think there are cases of tracing where the phone is switched off too, though not sure if they used historical cell data to guess at its location or there is some secret sauce. But - as you mention, you require to have connections into an operator to do all this.
- peterburkimsher 8y agoAre there tools available to monitor if I receive a silent SMS? I think it's safe to assume that all popular brands of phone are compromised and exploitable with these SMS PDUs. If I buy a Seeed Rephone open-source DIY kit and use it as a GSM-to-WiFi modem, will that be any more secure? I guess that reverse triangulation from cell towers is still possible to determine my location.
- mlaretallack 8y agoWhile not directly silent SMS, SnoopSnitch can check mobile network security and monitor for dome of the message types - https://f-droid.org/app/de.srlabs.snoopsnitch https://f-droid.org/app/de.srlabs.snoopsnitch
- crtasm 8y agoInteresting. Requires root and a Qualcomm chipset, compatible device list here: https://opensource.srlabs.de/projects/snoopsnitch/wiki/DeviceList https://opensource.srlabs.de/projects/snoopsnitch/wiki/Devic...
- frankzinger 8y agohttps://www.bladox.com/products.php?lang=cz https://www.bladox.com/products.php?lang=cz, see "Turbo SIM" (the others' pictures may confuse the idea). It's an ATMega128 which sits between the phone and SIM, intercepting all comms. It runs C code and provides an API which lets you read, manipulate or send any kind of SMS. Specifically, you can edit or prevent messages or any kind of SMS from reaching the SIM and thus your mobile operator's "secret" SIM apps. I used it at a previous job and can vouch for it. Doesn't look like they have versions for smaller SIMs, however.
- derefr 8y agoI’ve always wanted to play around with raw SMS PDUs. You could construct MMSes “from scratch”, for example; or send “ephemeral alert” messages that (at least by the standard) don’t get stored in SMS conversation history, just popping up and then disappearing instead. Does anyone know, then, why Twilio and its like don’t let you construct/send raw binary PDUs? If it was a matter of cellular network security, well, that was already out the window once you let people with rooted phones into the network. Why not give virtual “phones” the same capability?
- donttrack 8y agoBinary PDUs can be tricky to send between operators - especially when those operators are in different countries. Often you will find that the PDU messages simply disappear. Internally within an operator network there shouldn’t be any problem usually. That is probably why twilio doesn’t support it.
- robert_tweed 8y agoBack around 2000, shortly after The Matrix came out and everyone was buying "those" Nokia phones, I was tasked with writing a couple of applets for a certain UK mobile phone operator. One applet was to design operator logos. The other was to compose ringtones. Both popular things at the time. I was given access to an SMS gateway, a PDF of the Nokia message format and a deadline. The exact UI was phone-dependent, but typically these updates would pop up a confirm box saying "Accept new ringtone?" or something similar. I was surprised to discover that this was triggered by sending an SMS, because there was usually no indication that a message had been received. If you were lucky you would be told where the file had come from, but often the phone just assumed it was an update from the network. On some phones there wasn't even an alert, it would just obey, silently. The message just had to start with "//SCKL", followed by a code, followed by some data. That's it. On first reading I assumed the "header" part would require direct access to the SMS gateway, like the SMTP HELO or similar. Nope. First thing I tried once I had some PoC data was to send a message from my phone directly to a colleague. It worked. Over the course of that project I sent so many of those text messages I still can't get the code //SCKL1581 out of my head. JFTR, sending someone a really awful ringtone (a single diminished fifth or something) is way more annoying than sending them "0" as an operator logo, especially if their phone only has one ringtone. https://www.activexperts.com/sms-component/sms/sckl/ https://www.activexperts.com/sms-component/sms/sckl/
- kuschku 8y agoDo you know if it’s possible to change the displayed operator name with this, and if yes, how? Every since a few years ago my SIM believes its operator to be a random sequence of characters that’s definitely not the operator, and I’d love to fix that.
- robert_tweed 8y agoDepends on the phone. I don’t think any modern phones support this, but you could try. The prefix for the logo is //SCKL1581 and IIRC all you need is an unencoded bitmap in hex. I.e., “0” is 4 black pixels and “f” is 4 white (or vice versa). The data format for ringtones is a lot more complicated. In theory you can just hex dump a monochrome bmp file of the correct size, although the byte order may be wrong and you’ll need to strip the headers. However you also need to know the codes for the network/country. If the first link doesn’t cover it I found another one here: https://www.csoft.co.uk/archive/sckl#an-operator-logo https://www.csoft.co.uk/archive/sckl#an-operator-logo IIRC images are zero-padded automatically so you can send in a single message as long as it’s not full size. The other problem is that modern phones handle multipart SMS automatically, so it might mangle the preamble. You might have more luck sending from an ancient phone or going via an SMS gateway API directly.
- secstu 8y agoNice little write up. Rather than using the USRP I'd probably use a LimeSDR, if you can get hold of one.
- noir-york 8y agoGreat article! Thanks for posting.
- codedokode 8y ago> Setting the PID to 0x64 would be a silent SMS known as a 'type 0' SMS which all handsets receive and must acknowledge without indicating its receipt to the user. As previously mentioned, this has been used by law enforcement to actively 'ping' a handset on a network. I don't like that. Why should a device that I have paid for contain this backdoor? Manufacturers should not forget from whom they get the money. It might be difficult to fix in hardware but if it is handled in software then open source projects like Android could do it and do not reply to silent SMS or display them to the user.
- donttrack 8y agoActually the reply to the ping originates from the network itself and not the phone and it would work with any class of SMS - you just need to set the “delivery receipt” bit in the SMS. Then the network will send a receipt to the sender when the message has been delivered.
- pmlnr 8y agoBecause SMS originally is not for user use, but for GSM network test messages.
- app4soft 8y agoIt just remind me dirty 'hack' from 2005-2010: if you set format for SMS as "E-Mail" on Siemens C65/C72 phone, then send SMS from this Siemens phone to SonyEricsson K210/K750 phone -- this SMS on SonyEricsson phone shown as sent from anonymous ;-)
- donttrack 8y agoThat might be my fault. I worked on the tcpip and sms protocol stacks for the 55 and 65 series Siemens phones.. Sorry.. I know of at least one small Easter egg if anyone has a S65 lying around somewhere. I don’t believe it was discovered by anyone before. Might also work on the 55 devices - don’t quite remember as it was a long time ago.
- ComputerGuru 8y agoIsn’t it a bug on the Sony Ericsson phone? I mean the non-standard message went via standard channels to reach the destination but the destination couldn’t grok that?
- app4soft 8y ago> I don’t believe it was discovered by anyone before. It was so funny when I discover this Easter egg and then use it for trolling own friends... Awesome time where I was like "phone hacker" :-D Thanks Siemens developers that gave us time for thinking... ╔═══════════════════╗ ║ ║ ║ ║ ║ Please, wait... ║ ║ ● ● ● ◐ ○ ║ ║ ║ ║ ║ ╚═══════════════════╝
- jiveturkey 8y agoi used to use this (in my company) to provision OTP secrets. this was before iphone. after provisioning, OTP requests could be offline. thus no worries about sending an otp over sms. of course the secret was itself encrypted via pre-provisioned Key Encrypting Key. or users could manually enter the wrapped otp secret on the off chance the sms didn’t work. it worked for nokia and blackberry so that covered nearly 100%. the article talks about abuse but in my case quite a useful “backdoor”.
- pavel_lishin 8y agoUnrelated to the article, but when I zoomed in to 150%+ in Chrome, this image [1] turned into this image [2]: https://www.contextis.com/media/images/made/media/images/content/RF_box.width-800_800_533_75.jpg https://www.contextis.com/media/images/made/media/images/con... https://www.contextis.com/media/images/made/media/images/content/RF_box.width-800_800_533_1.jpg https://www.contextis.com/media/images/made/media/images/con...