SIM Card Vulnerability Fix Utilized the Exploit to Fix Itself

  • 3 August 2013
  • 0 replies
  • 503 views

Userlevel 7
  • Retired Webrooter
  • 1581 replies
Karsten Nohl of Security Research Labs was scheduled to demonstrate an interesting hack involving SIM cards at Black Hat a few days ago, but his demonstration was called off due to the carriers fixing the issue in the nick of time.  Nohl declined to name who the carriers were.
 
He discovered that a vulnerability existed where a Java flaw could be exploited by sending a specially-crafted over-the-air (OTA) cryptographically secured text message. SIM cards can contain phone numbers, contact information, and other personally identifiable information to the phone owner.
 


image: cnet asia


As it turns out, the unnamed carriers utlized the vulnerability themselves to hack into the SIM cards and patch them, thus leaving them unhackable again by the same exploit.  So in this case, white-hat hacking saved the day.
 
Full story from ZDNet.

0 replies

Be the first to reply!

Reply