DEF CON 19 - hackers get hacked
seclists.org
seclists.org
Also, I only realized AFTER a few minutes of (failed) use that my Verizon 4G card was being MiTM'd as I had full strength but no connectivity.
What I don't understand is how this vector occurred (on the Android phone) given it is no different to connecting over public (open) wifi - anyone can read packets and so the connections between Google Apps (for example) are supposed to be encrypted.
My only guess is that my phone auto-downloaded a patch that was poisoned and the security failure here is that the phone assumes any patch fed to it over the mobile network must be trustworthy. :/
It's entirely possible there are other exploits but a modified update.zip is not a likely vector.
See the talk from BlackHat titled "Femtocells: a poisonous needle in the operator's haystack"
http://femto.sec.t-labs.tu-berlin.de/bh2011.pdf
Basically, they set up a rogue femtocell, you connected to it as you walked by and voila. It would also explain why you sometimes couldn't make calls (you need to be within 15 feet of most femtos to make a call, but you still have signal strength up to 40 feet).
Also, from what I can tell this wasn't a femto-cell but a significant antenna, perhaps even telco industry-grade.
He wasn't willing to say much else, only that the attack was very sophisticated and likely to be the work of top-notch professionals.
Also plenty of people on Sprint's network had full bars but could make absolutely no calls and data was extremely slow, but about half a block from the Rio everything worked perfectly again, now it could well be that they were handed off to a different tower, but people on AT&T and T-Mobile weren't having the same issues.
DefCon this year was awesome. Plenty of fun to be had, and as more and more people start carrying around cell phones that are more powerful these attacks will continue to be developed and continue to be exploited.
I was definitely having the same issues on AT&T. Falling back to SMS instead of voice or Twitter for communication worked a lot better for coordinating things, although the lag was an issue.
I'd venture to guess they hacked some of the femtocell gear, or maybe used for the evil the gear from openbts project.
It's sad, really. These people are not too stupid at least in the technology area. It would be so great to have their skills directed at making the world good. Like, providing the connectivity somewhere in the villages in lalaland far away. Alas.
Some of my friends bring burner/throwaway/blank phones to Defcon, and this is why.
But I question the overall value of this activity for the society, compared to other things.
Commenting is indeed a time sink.
I'll try to do it less. Thanks.
Or you insert the SIM card into the notebook itself ? If yes, would be curious to know which OS is it - I remember seeing that Windows grouped the 3G and WiFi connection settings into the same dialog, but since I do not use windows at all nor have a laptop h/w which would grok a SIM card, can't check.
And the theory you describe with the same SSID - indeed that would be very much possible to pull off. Assuming there is a nation-wide standardized SSID, it could easily trick people into connecting to it.
Additionally, there are times my 3g connection does not show up correctly and I have to initiate it by dialing out (#777 I believe) as if it's a modem - but if the SSID of a wifi connection were there I could see someone who was not fully paying attention to click on that by accident when the default one does not show up right away.
Any chances you might find some time to make some screenshots and blogpost them ?
The Mobile Broadband Connection doesn't always show up leaving the Wireless Network Connection list at the top. In this case you now see two entries for "Verizon Wireless" - the top being my broadband connection, the second one being my wireless routers SSID. Without paying attention and just working off of muscle memory it is feasible to go to an open network acting maliciously without realizing it.
Mind if I steal this pic for a blog post ? (Or if you planned a write-up, I'd be interested in a URL. It's worth making a bit of noise around it so the MS guys think of it as a problem worth solving.)
No argument here, I'm not an expert... but isn't this exactly what the microcell devices that AT&T (etc) are giving to customers do? You set it up on your home broadband and nearby users invisibly use that "tower" and it goes over your home network.
(This probably goes without saying, but I'll say it anyway; if you do this in the wild and you don't take precautions for handling emergency calls, you're probably a bad person.)
GSM implementation insecurity hasn't affected iphone or blackberry enterprise deployment, not sure why it would affect android.
This is so far into the "state sponsored only" realm that if you'd actually pulled it off and were bragging about it you'd provide some kind of proof instead of generic symptoms designed to make people paranoid.
I'm pretty surprised at all the media outlets that are carrying this and people taking it at face value. Anyone can write up something and send it to a mailing list - remember that full disclosure is pretty much ground zero for security trolling.
[1] http://www.slideshare.net/zahidtg/femtocells-a-poisonous-nee...
A very interesting attack, but not interesting in the sense that cdma/wimax (perhaps LTE too?) is unsafe but in the sense that there are serious vulnerabilities in the network stack for android.
However I'd probably take a cheap old laptop off ebay, bought for the event and then discarded afterward. I'd feel I was missing out if I wasn't able to at least dip a packet sniffer into the famously hellish torrent of exploits I've heard so much about. I'd never take any of my personal machines though.
However I would mind being rootkited, as it could serve as an entry point to infect other systems.
One link I readily found was http://www.youtube.com/watch?v=8bkg3AjY6fs but maybe there was more than one preso, I don't remember.
If I were to go to this gathering, I'd go with a pen, paper, and a video camera.
So the advice was: disposable pay-as-you-go phone and craigslist it afterwards. Same for laptop. Don't bring them home.