Home

Samsung Phone Flaw Lets Attackers Remotely Reset Device

Comments | Larry Seltzer, BYTE | September 25, 2012 10:12 AM

Category: Tablets, Smartphones

A researcher at a security conference in Berlin has shown how Unstructured Supplementary Service Data (USSD) codes could be used in cyber attacks against mobile phones. The Samsung Galaxy S3, for instance, can be reset to factory default merely by browsing a malicious website.

Ravi Borgaonkar, a researcher at the Technical University of Berlin, gave a presentation entitled, Dirty use of USSD Codes in Cellular Network. Below is a video of part of the presentation:

The codes are commands to the phone to perform diagnostic and management features as listed on the xda-developers wiki:

  • testing mode
  • view IMEI number
  • service mode signal status
  • display phone's current firmware
  • battery and other general settings like GSM/CDMA
  • change the "Power" button action in your phone
  • Factory data soft reset
  • Gtalk service monitor
  • Opens a File copy screen where you can back up your media files
  • GPS test
  • service mode main menu
  • Factory Hard Reset to ROM firmware default settings
  • leave Factory

These codes can be invoked, without any user intervention, through a variety of mechanisms. Borgaonkar demonstrated the attack using an SMS message sent to the phone, holding the phone in proximity to an NFC tag, and discussed others such as a QR code.

All these vectors result in pushing the code to the phone, possibly by instructing it to visit a website that contains a "tel:" URL with the code. For example, a Samsung phone, when visiting a Web page containing <frame src="tel:*2767*3855#" />" would reset the phone to factory default. Other codes can wipe the SD and SIM cards.

Borgaonkar says that the attacks only work so far on Samsung devices. Many of the attack vectors can be disabled by the user. It's not clear that these vectors are present with all carriers.

Hat tip to Softpedia.

Follow Larry Seltzer and BYTE on Twitter, Facebook, LinkedIn, and Google+:



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events