topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Thursday March 28, 2024, 6:07 am
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: Fake GSM base station tricks target iPhones  (Read 2933 times)

Josh

  • Charter Honorary Member
  • Joined in 2005
  • ***
  • Points: 45
  • Posts: 3,411
    • View Profile
    • Donate to Member
Fake GSM base station tricks target iPhones
« on: January 20, 2011, 03:39 PM »
icon_iphone.gif

While his Black Hat DC Conference demonstration was not flawless, a University of Luxembourg student on Wednesday did show that it's possible to trick iPhone users into joining a fake GSM network.

Ralf-Philipp Weinmann showed how to cobble together a laptop using open-source software OpenBTS and other low-cost gear to create a fake GSM transmitter base station to locate iPhones in order to send their owners a message. A number of iPhone users in the room expressed surprise that they had gotten a message asking them to join the network.

Weinmann, who is researching vulnerabilities in cellular networks, said that with the right equipment, the range for the rogue GSM station he built can be 35 kilometers.

More at source...

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: Fake GSM base station tricks target iPhones
« Reply #1 on: January 20, 2011, 03:55 PM »
(see attachment in previous post)
While his Black Hat DC Conference demonstration was not flawless, a University of Luxembourg student on Wednesday did show that it's possible to trick iPhone users into joining a fake GSM network.

Ralf-Philipp Weinmann showed how to cobble together a laptop using open-source software OpenBTS and other low-cost gear to create a fake GSM transmitter base station to locate iPhones in order to send their owners a message. A number of iPhone users in the room expressed surprise that they had gotten a message asking them to join the network.

Weinmann, who is researching vulnerabilities in cellular networks, said that with the right equipment, the range for the rogue GSM station he built can be 35 kilometers.

More at source...

There were people at a hacking conference stupid enough to be carrying an iPhone?!? I thought they banned those things a long time ago because of their pathetic security...

mwb1100

  • Supporting Member
  • Joined in 2006
  • **
  • Posts: 1,645
    • View Profile
    • Donate to Member
Re: Fake GSM base station tricks target iPhones
« Reply #2 on: January 20, 2011, 05:20 PM »
There were people at a hacking conference stupid enough to be carrying an iPhone?!? I thought they banned those things a long time ago because of their pathetic security...

I wonder if the attack was really targeting something iPhone-specific. iPhones use an Infineon GSM chipset - I'd guess it (or a closely-related attack) would be effective against many Infineon-based phones.  Then again, I'm assuming that Infineon isn't exclusive to iPhone.

Stoic Joker

  • Honorary Member
  • Joined in 2008
  • **
  • Posts: 6,646
    • View Profile
    • Donate to Member
Re: Fake GSM base station tricks target iPhones
« Reply #3 on: January 20, 2011, 06:19 PM »
There were people at a hacking conference stupid enough to be carrying an iPhone?!? I thought they banned those things a long time ago because of their pathetic security...

I wonder if the attack was really targeting something iPhone-specific. iPhones use an Infineon GSM chipset - I'd guess it (or a closely-related attack) would be effective against many Infineon-based phones.  Then again, I'm assuming that Infineon isn't exclusive to iPhone.
Ya know, I found that detail rather troubling also. But the article was very specific in singling out the iPhone.

Sure, I'm wearing my schadenfreude hat, but (to be honest) this very well could be an iceberg tip.