GoIP-1 GSM gateway could be harnessed for phone fraud by hackers
shufflingbytes.com
shufflingbytes.com
Btw the old dbladm backdoor still worked IIRC at the end of 2020 but needed some re (I suspect it still does) - you can dump the code from firmware updates.
They mark new challenge types with a letter in front of the numbers when you try to log in. I got the original (no prefix) and S, H, N type challenges working.
Also possible to extract and reassemble custom firmware updates (if you want to run custom code) after you get admin rights - the package is only protected by an md5 in the header. Be sure to have a jtag ready, you'll need it the first few tries.
Here's some old notes on the PKG format: https://gist.github.com/tostercx/3f2f2776736fbdaf9b8fa77c203...
The FS is either cramfs or squashfs.
Apart from all the funky web-interfaces (with their security defects), isn't that basically what this GoIP-1 device is? Like, you can use it to send SMS; but it's not free, it's charged to the SIM account, right?
So if you're stupid enough to put the web interface for this thing on the big, bad internet, then strangers can use your SIM card to send "free" text messages. But much the same would happen if you left your phone on a park bench.