4 ms·
I wonder why we haven't seen more exploits targeting SMS PDU mode. Is it the barrier for script kiddies just too high? You would probably need a network tester
by donttrack 8y ago
I wonder why we haven't seen more exploits targeting SMS PDU mode. Is it the barrier for script kiddies just too high? You would probably need a network tester of some kind to properly try to find exploits.
I used to work for a big mobile phone manufacturer and once in a while we would get "secret" fixes to merge into the source. The commit message would be something unrelated and the builds would be pushed silently without much fanfare.
I was in charge for the merging, which is how I know this. Some of those fixes were for SMS PDU mode or related to stuff happening when PDUs were received. Not sure how phones handle these messages today, but I assume they follow spec, which means there are certain SMS PDUs which will be reacted on silently in the background (stuff in the PDU body is parsed and applications launched if necessary).
I should try to get an old R&S tester from eBay maybe. Could be fun to try to explore this area. Could be a nice security business niche to get into.
- IronBacon 8y agoI think I've seen a presentation from CCC years ago where they demonstrated an "SMS of death" (similar to the "ping of death") where they rebooted various brands of phones. I don't have a link at hand, I recall they used a SMS modem and they didn't reveal a lot of details (I'm not even sure if they rebooted or bricked the receiving phones) for abuse concerns, but it should probably easy to find. edit: it was easier than I thought, first hit on Google: https://media.ccc.de/v/27c3-4060-en-attacking_mobile_phones https://media.ccc.de/v/27c3-4060-en-attacking_mobile_phones