https://youtu.be/ITbqTl8pTMs?t=200 Err... were these commands meant to be obfuscated the whole time?
I'm not really sure why it was blurred when it is easily searchable on the database they publish
ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
41–50 of 79 posts
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#42Earlier quoted context omitted.
Dialup was still a thing in this century, even if it feels like a long, long time ago. You could still reset people's connections by having them echo ATH0 back to you, if they were on a bad setup.
Only if you could get the other party to type +++ first to enter command mode, though. I'm not aware of any modem that would accept commands, including ATH0, outside of command mode. Then again, there were a lot of bad modems in the world…
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#43Any info about Apple phones? Do they use AT commands?
They do internally, but as far as I know there's no way to send them from outside - you have to be root, and if you're root you don't really need AT commands to exfiltrate data.
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#44Umm, Hayes commands are still used? That's a blast from the past. I thought those went out in the 80s or 90s?
Yes, I was wondering if I read that right, but it seems that AT commands are still in use. Us BBS nerds used to know AT commands by heart. We would send instructions to our 2400 baud Hayes modems using QModem: ATZ = reset ATDT1234 = dial 1234 on a touch tone phone (DP for pulse dial) Those of us who later moved to US Robotics modems started learning proprietary USR ampersand codes. ATH0.
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#45Umm, Hayes commands are still used? That's a blast from the past. I thought those went out in the 80s or 90s?
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#46Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#47Edit: Just realized that the commands bypassed the prompts. That is a different beast. But the question still remains.
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#48Really curious, why treat these automation capabilities as a vulnerability? Several security popups appeared, a cable was attached, an application executed on the computer... as a user I'd much rather have the possibility in the future of automating my phone's UI than to have vendors treat this as a vulnerability and patch. Edit: Just realized that the commands bypassed the prompts. That is a different beast. But the…
Re: ATtention Spanned: Comprehensive Android Vulnerability Analysis of AT Commands
#49Umm, Hayes commands are still used? That's a blast from the past. I thought those went out in the 80s or 90s?