Live data from Hacker News

USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

exquisitetweets.com

171–180 of 186 posts

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#171
post #61

Earlier quoted context omitted.

I've yet to scan one of these codes, or see anyone scanning one. It seems like something from the 90s just came back for one last dying breath.

I would guess the opposite. QR codes are too early. They need to be scannable by a device that doesn't require reaching into your pocket, fumbling with your phone and then trying to get the right angle. Combining a couple projections, I see them going from utterly useless to gimmicky cool for a particular crowd within 2 years.

Maybe using something like NFC? so you come near to a poster and it pushes a URL or something to you?

Or a 'smart billboard' perhaps: http://mashable.com/2011/04/16/smart-billboard/

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#172

Here's a safe version of the exploit that displays your IMEI: http://kristofferR.com/samsung.html Check the html in your desktop browser first, for all you know I might as well be a malicious douchebag. The exploit seems to require a stock Samsung Galaxy dialer, works fine on my cheap Samsung Galaxy Y but not on my friend's modded S3 with a vanilla Android dialer.

"Web page not available" using Browser on SK17i running CM9.1.0

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#173

I created an Android app to intercept these requests and prevent them. https://dl.dropbox.com/s/28lk6rn09x84qqg/AutoResetBlocker.ap... Please test it and make sure it works for you. 1. Open the above link on your phone 2. Install the application (it requires no special permissions) 3. Try this IMEI test: http://jsfiddle.net/kKFn8/ 4. Check the box to make "Auto-Reset Blocker" the default action 5. Auto-Reset Blocker…

Thanks, works as intended on my S3. Any chance of releasing the source code though?

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#174

Here's a safe version of the exploit that displays your IMEI: http://kristofferR.com/samsung.html Check the html in your desktop browser first, for all you know I might as well be a malicious douchebag. The exploit seems to require a stock Samsung Galaxy dialer, works fine on my cheap Samsung Galaxy Y but not on my friend's modded S3 with a vanilla Android dialer.

To people reporting that this works on other devices such as HTC phones, this doesn't mean your phone is vulnerable: First, the hash-star code to display the IMEI number is standard, while the reset code is device specific. Second, as I understand it the problem with the Galaxy S3 is that it doesn't ask for user confirmation after the reset code is entered.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#175

I created an Android app to intercept these requests and prevent them. https://dl.dropbox.com/s/28lk6rn09x84qqg/AutoResetBlocker.ap... Please test it and make sure it works for you. 1. Open the above link on your phone 2. Install the application (it requires no special permissions) 3. Try this IMEI test: http://jsfiddle.net/kKFn8/ 4. Check the box to make "Auto-Reset Blocker" the default action 5. Auto-Reset Blocker…

Works great. However, the immediate select app popup if it's "safe" means that the "This phone number appears safe" text is shadowed on my phone. Perhaps add a "dial" button? Still, please set up a Market account, this would be great!

I submitted a new version incorporating your suggestion. It should be on the market in a couple hours. :-)

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#176
post #173

I created an Android app to intercept these requests and prevent them. https://dl.dropbox.com/s/28lk6rn09x84qqg/AutoResetBlocker.ap... Please test it and make sure it works for you. 1. Open the above link on your phone 2. Install the application (it requires no special permissions) 3. Try this IMEI test: http://jsfiddle.net/kKFn8/ 4. Check the box to make "Auto-Reset Blocker" the default action 5. Auto-Reset Blocker…

Thanks, works as intended on my S3. Any chance of releasing the source code though?

Thanks for asking. That is the plan. I just need a bit more time to make it presentable.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#177

Page text was: the USSD code to factory data reset a Galaxy S3 is *2767*3855# can be triggered from browser like this:

does that mean premium rate numbers can also be triggered?

It's not the end of the world though. You're browsing on your android phone and suddenly it dials an unexpected number and you can see that it starts 900XXXXXXX or 976XXXXXXX. Most people are going to hang up pretty quickly. Sure, you might be out of pocket for up to $10 (I don't actually know how much mobile carrier charge for the connection charge), but it's not the same as losing all your data.

A more common attack vector to make money on compromised accounts would be setting up a call forward to an international number and then dialing the subscribers phone number. Illegal low cost calling cards often steal service by doing this. If there was a way to also retrieve the user's phone number, I can imagine a system where you dial the calling card company, input your code and the number you want to dial.... It tells you that it's trying to connect you and that it may take a couple of minutes... It snares the next person caught out on the website, sets their call forward to the number you want to dial, then dials that subscriber for you and connects. So then it's charging the wireless subscriber for your international call, and even if they then disable the call forward on their account, until you hang up, it's still charging them for the call forward.

Re: USSD code to factory data reset a Galaxy S3 can be trigged from a HTML page

#180
post #62
post #41

Earlier quoted context omitted.

A clearer video showing the lack of prompt: http://tweakers.net/video/6292/html-code-laat-galaxy-s-ii-re...

I have an S2, And I'm reading this from it. I was like "woow", then clicked the link that says "the code" instinctively and a sec later realized the stupid thing I just did (not smart reading that code from a vulnerable device). luckily, I pressed the back button before the page loaded. That was close

It's a .png file of the code...
Post reply on HN