5Ghoul: Unleashing Chaos on 5G Edge Devices
asset-group.github.io
asset-group.github.io
Glad they were able to figure out the branding though.
That's pretty obviously something someone threw together in a few minutes after grabbing a few [0] random images from the internet. This isn't one of those exploit sites with more effort poured into marketing than the exploits themselves.
Heartbleed I remember, along with Spectre/Meltdown, but I couldn't name the weak exploits that turn out to be nothing burgers. Log4j could have used a brand though, imo.
I still remember some of the big ones like MS03-026/031, MS08-067, CVE-2005-1042.
Not directly, but downgrading to LTE would almost certainly force a UE to expose its IMSI at least.
It should be no surprise the code is crap quality, like the fw in those Polish trains, although those had malware to boot.
And then, the protocols themselves are encumbered. GSM is a disaster in general.
The land line network used to work like the cell network does today. Early home computer networks, and then later, home internet were enabled by the court ruling that said the phone company couldn't block you from plugging modems in (or charge more for the same copper wire if you did plug a modem in).
California network neutrality laws supposedly ban discrimination against devices as well as against web sites, but it's either unenforced, or there is a loophole.
Can't you already do that today? Just swap your sim card.
just moving sim card to another phone will completely block you any access until you "reactivate" in the majority of telcos around the world.
Mind listing those countries? One source[1] for the US says that statement is only true for 1 of the 3 major telecoms. One of the other two requires an approved device to activate the sim, but otherwise doesn't care, and the other doesn't care as long as the device supports VoLTE.
[1] https://prepaid-data-sim-card.fandom.com/wiki/United_States#...
But also, with the history of actually open protocols such as SMTP, the opportunity for abuse is enormous. The mobile phone system is abused right now by manufacturers, vendors, and "the surveillance state", but being open may just end up with us in a state where all that is true and there's a limitless slurry of effluent from semi-anonymous bad faith actors.
With SS7, not only can you spoof any phone number, but you can cause the other end of the network connection to wire money without getting their prior authorization!
This is improved somewhat by STIR/SHAKEN, but, even with that, the state of the art is worse than SMTP.
Unfortunately, there is way too much old gear around, probably hundreds of billions of dollars worth, so instead of actually rebuilding communications systems we're forced to bolt on security (and features, like with IPv6) onto an extremely large pile of ossified bull dung.
Anyone abusing the mobile network runs the risk of their provider pulling the plug and disabling their access.
It feels like a damn miracle anything actually works.