Live data from Hacker News

SIM Vulnerability leads to information disclosure via malicious SMS

simjacker.com

21–30 of 60 posts

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#21
post #11

Title is misleading. No "hijacking" is taking place, they are obtaining the Cell ID (approximate location) and IMEI info from the phone, by sending it a malicious SMS containing SIM card instructions. Details; https://www.adaptivemobile.com/blog/simjacker-next-generatio... A better title IMHO; SIM Vulnerability leads to information disclosure via malicious SMS.

Seems like a highjack may be possible actually... Here is a list of other things they listed they can do with the simjacker exploit that goes beyond simple data exfiltration: > PLAY TONE > SEND SHORT MESSAGE > SET UP CALL > SEND USSD > SEND SS > PROVIDE LOCAL INFORMATION > Location Information, IMEI, Battery, Network, Language, etc > POWER OFF CARD > RUN AT COMMAND > SEND DTMF COMMAND > LAUNCH BROWSER > OPEN CHANNEL…

[deleted]

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#22
post #11

Title is misleading. No "hijacking" is taking place, they are obtaining the Cell ID (approximate location) and IMEI info from the phone, by sending it a malicious SMS containing SIM card instructions. Details; https://www.adaptivemobile.com/blog/simjacker-next-generatio... A better title IMHO; SIM Vulnerability leads to information disclosure via malicious SMS.

Ok, we'll go with that title above.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#24
I obtained a low-tech phone for SMS and phone calls. I then turned my Samsung Android back into a PDA by removing the SIM chip.

I explain to my clients when they express astonishment at my low-tech phone that I am protecting their security, as I have the PDA sync with my Exchange Server, where I keep sensitive info to provide them support and I do not allow the low-tech phone to access my Exchange Server.

I also tell them that I had based my decision on the track records of Google, Apple, Verizon, etc. in regards to security.

Nothing is perfect, but at least my attack surface is lessened.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#26
post #11

Title is misleading. No "hijacking" is taking place, they are obtaining the Cell ID (approximate location) and IMEI info from the phone, by sending it a malicious SMS containing SIM card instructions. Details; https://www.adaptivemobile.com/blog/simjacker-next-generatio... A better title IMHO; SIM Vulnerability leads to information disclosure via malicious SMS.

Seems like a highjack may be possible actually... Here is a list of other things they listed they can do with the simjacker exploit that goes beyond simple data exfiltration: > PLAY TONE > SEND SHORT MESSAGE > SET UP CALL > SEND USSD > SEND SS > PROVIDE LOCAL INFORMATION > Location Information, IMEI, Battery, Network, Language, etc > POWER OFF CARD > RUN AT COMMAND > SEND DTMF COMMAND > LAUNCH BROWSER > OPEN CHANNEL…

running arbitrary AT commands gives lots of potential... i wish they would provide (a lot) more details about their claims :(

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#27
post #11

Title is misleading. No "hijacking" is taking place, they are obtaining the Cell ID (approximate location) and IMEI info from the phone, by sending it a malicious SMS containing SIM card instructions. Details; https://www.adaptivemobile.com/blog/simjacker-next-generatio... A better title IMHO; SIM Vulnerability leads to information disclosure via malicious SMS.

Why in the world is this API surface even available, and why aren't Google / Apple / handset manufacturers scrambling to patch this?

Google and Apple can't do anything to mitigate this.

Edit: The following is incorrect. SIM cards are self-contained computers. Among other things, they're responsible for encrypting and decrypting communications between your phone and your carrier. This means that a SIM card will see the contents of a message before your OS or other hardware in your phone does. These exploits should work just as well against "dumb" phones as smartphones because they're not attacking the actual phones.

This API exists because SIM cards are self-contained computers; they need a way to communicate with everything else.

Re: SIM Vulnerability leads to information disclosure via malicious SMS

#30
There doesn't seem to be a lot of specifics here. Does this mean I can send anyone a text that has some magical character in it to trigger this S@T Browser to execute arbitrary AT commands? Or is this some kind of special SMS like a type-0 SMS or something?
Post reply on HN