Dailydave mailing list archives
Re: Seeking more info on: Devastating mobile attack under spotlight
From: liquidfish <liquidfish () gmail com>
Date: Mon, 27 Nov 2006 12:32:37 -0800
It is possible for carriers to send and install a new firmware image to a mobile phone using SMS messages. The system is called Firmware Over The Air (FOTA) technology. Mobile carriers use this tech to send updates to customers without requiring customer intervention. So whether or not it is possible to update a mobile station's entire firmware image is not in question. It IS possible because the carriers have designed systems to make it possible. The question that needs to be answered is whether or not (and possibly how) those systems validate the legitimacy of the FOTA messages they recieve. Something like the 3GPP EAP-SIM standard would be a very applicable (although a pain in the butt i imagine given the dependency on SMS messages for FOTA) method for validation that could possibly resolve the alleged vulnerability (if it exists) -p
_______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com http://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- Seeking more info on: Devastating mobile attack under spotlight Dude VanWinkle (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Paul Wouters (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Robert Clark (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight liquidfish (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Dave Korn (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Robert Clark (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Nicolas RUFF (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Roy M. Silvernail (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Gadi Evron (Nov 28)
- Re: Seeking more info on: Devastating mobile attack under spotlight Matt Richard (Nov 28)
- Re: Seeking more info on: Devastating mobile attack under spotlight Gadi Evron (Nov 28)
- Re: Seeking more info on: Devastating mobile attack under spotlight liquidfish (Nov 28)
- Re: Seeking more info on: Devastating mobile attack under spotlight Gadi Evron (Nov 29)
- Re: Seeking more info on: Devastating mobile attack under spotlight liquidfish (Nov 29)
- Re: Seeking more info on: Devastating mobile attack under spotlight Roy M. Silvernail (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Paul Wouters (Nov 27)
- Re: Seeking more info on: Devastating mobile attack under spotlight Nicolas RUFF (Nov 28)