Firmware tweak can block subscriber calls, says Berlin group

Aug 28, 2013 by Nancy Owano weblog

A telecommunications security research group at the Technical University of Berlin earlier this month told an audience at the 22nd USENIX Security Symposium that they were able to hack phones by modifying embedded software. They could block calls and texts intended for nearby people connected to the same cellular network. They pulled this off by modifying embedded software on the mobile phone's baseband processor, controlling communications with a network's transmission towers. Just one phone could have the impact of blocking service to people served by base stations within a certain coverage area. The hack involves modifying the baseband processor on some phones and tricking older 2G GSM networks into not delivering calls and messages intended for subscribers nearby.

The hacked – OsmocomBB – can block calls and messages because it can quickly respond to them before the phones that are intended to get the communications can do so.

But wait, did they say GSM (Global System for Mobile communications)? Isn't that the older type of network, so who cares? The fact that the group's method worked on the second-generation (2G) GSM networks is important. These are the most common type of worldwide; about 4 billion people use GSM networks for calls even though carriers promote 3G and 4G. The group's work with 2G was explained further at USENIX by Kévin Redon, a Berlin-based researcher. Radon said that GSM is still relevant, can be found everywhere; in fact, in some countries there is only GSM, he stated.

Redon and researchers Nico Golde and Jean-Pierre Siefert provided the presentation, "Let Me Answer That For You: Exploiting Broadcast Information in Cellular Networks."

They implemented their approach and they tested it out to find that they were able to carry out their attacks on a number of German cell phone operators, vulnerable to the trio's attack.

According to their work, "We demonstrate that for at least GSM, it is feasible to hijack the transmission of mobile terminated services such as calls, perform targeted denial of service attacks against single subscribers and as well against large geographical regions within a metropolitan area."

This video is not supported by your browser at this time.
Credit: Kévin Redon / USENIX

They also noted that the attack can be accomplished just by using inexpensive consumer devices that are available on the market. According to MIT Technology Review, the group used open-source baseband code to write replacements.

This video is not supported by your browser at this time.
block phone calls or SMS via GSM paging procedure race condition


Explore further: DOCOMO and Huawei confirm LTE network over unlicensed spectrum

More information: www.usenix.org/conference/usen… on-cellular-networks
www.technologyreview.com/news/… other-peoples-calls/
threatpost.com/phone-hack-coul… some-mobile-networks

Related Stories

GSM phones -- call them unsafe, says security expert

Dec 27, 2011

(PhysOrg.com) -- A German security expert has issued a warning that billions of mobile phone users who depend on GSM networks are vulnerable to having their personal mail hacked. He blames the problem on network ...

Researchers show how to use mobiles to spy on people

Apr 22, 2010

(PhysOrg.com) -- Researchers have demonstrated how it is possible to use GSM (Global System for Mobile communications) data along with a few tools to track down a person’s mobile phone number and their location, ...

Scientists break satellite telephony security standards

Feb 08, 2012

Satellite telephony was thought to be secure against eavesdropping. German researchers at the Horst Gortz Institute for IT-Security (HGI) at the Ruhr University Bochum (RUB) have cracked the encryption algorithms of the European ...

GSM system about to be compromised

Dec 08, 2009

(PhysOrg.com) -- Research scientists in California and elsewhere are deliberately setting out to compromise the mobile phone system used by around three billion people. The system uses Global System for Mobile ...

Recommended for you

Bringing emergency communications together

Aug 21, 2014

A new University of Adelaide research project aims to improve emergency operations through integrated communications systems for police and the emergency services.

For top broadband policy, look no further than Canada

Aug 20, 2014

You might have seen communications minister Malcolm Turnbull raising the issue about Australian press not discussing policy problems and solutions from overseas, in a speech delivered at the Lowy Institute Media Awards last week: ...

Cities, states face off on municipal broadband

Aug 19, 2014

Wilson, N.C., determined nearly a decade ago that high-speed Internet access would be essential to the community's social and economic health in the 21st century, just as electricity, water and sewers were in the previous ...

New loss mechanism for global 4G roaming

Aug 19, 2014

A loss mechanism that has not been an issue in previous mobile handset antennas will become important for global 4G roaming, according to results of experiments carried out in Aalborg, Denmark.

User comments : 0