Live data from Hacker News

USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

exquisitetweets.com

131–140 of 186 posts

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#131

Here's a safe version of the exploit that displays your IMEI: http://kristofferR.com/samsung.html Check the html in your desktop browser first, for all you know I might as well be a malicious douchebag. The exploit seems to require a stock Samsung Galaxy dialer, works fine on my cheap Samsung Galaxy Y but not on my friend's modded S3 with a vanilla Android dialer.

Doesn't work on my Galaxy Nexus, stock 4.1...

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#132
post #44

I deployed this code on this page : http://flasharabia.com however the code doesn't seem to work ..

Seriously? You're posting the DESTRUCTIVE version of the exploit instead of a safe test version? Shame on you.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#133

Here's a safe version of the exploit that displays your IMEI: http://kristofferR.com/samsung.html Check the html in your desktop browser first, for all you know I might as well be a malicious douchebag. The exploit seems to require a stock Samsung Galaxy dialer, works fine on my cheap Samsung Galaxy Y but not on my friend's modded S3 with a vanilla Android dialer.

Or you could have a script that, when notices the user agent to not be mobile, shows the IMEI version, but otherwise shows the reset version :P

Except there is no javascript on that page. They could do the same thing server side though

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#134

Earlier quoted context omitted.

I just tested it on a Samsung Galaxy S3, in several forms (as src in link, script, img, video and object elements, as well as the href in an a element). Nothing happened here.

Android Central reported that the (verizon) S3 was not vulnerable to this attack. http://www.androidcentral.com/major-security-vulnerability-s... Edit: Found some postings on xda-dev that the GS3 is vulnerable. Could depend on firmware version, I know a system update came out recently on Sprint.

[deleted]

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#135
post #16

Earlier quoted context omitted.

It wouldn't affect anyone because no one has ever scanned a QR code in an ad

http://picturesofpeoplescanningqrcodes.tumblr.com/

This needs a QR code sticker. http://qr.kaywa.com/?s=8&d=http%3A%2F%2Fpicturesofpeople...

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#136
post #65

Earlier quoted context omitted.

My local bus company has failed to grasp QR codes in a mind-bogglingly thorough way. Every stop has a poster with a QR code on it, advertising that you can now look up when the next bus will be here by scanning the QR code. The first thing you might notice is that the poster is actually a photo of a QR code on a poster, and is taken at an angle sufficient to render scanning the QR code impossible. The second thing yo…

Maybe they got the idea from Google Code, which helpfully shows me a QR code for the tarball I'm about to download, for all those times I'm using the browser on my desktop and the IDE on my phone.

I had assumed that they were mostly doing that for .apks but had just turned it on for everything.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#137

Here's a safe version of the exploit that displays your IMEI: http://kristofferR.com/samsung.html Check the html in your desktop browser first, for all you know I might as well be a malicious douchebag. The exploit seems to require a stock Samsung Galaxy dialer, works fine on my cheap Samsung Galaxy Y but not on my friend's modded S3 with a vanilla Android dialer.

Works on Nexus One 2.3.6 as well.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#140
post #72

Works with my HTC Desire if I use the info code, the dialog for showing battery status etc pops up. Raises interesting consumer protection questions, this is a 2010 phone with no updates recently. The law says the dealer has to fix or make up for manufacturing defects that show up years later.

Are software defects considered manufacturing defects? BTW, read elsewhere that if you are using the Chrome browser instead of the Samsung browser this doesn't affect you. Haven't had the guts to test it myself.

Where did you see that? Someone else said the same thing.
Post reply on HN