• Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • Home
  • About Darknet
  • Hacking Tools
  • Popular Posts
  • Darknet Archives
  • Contact Darknet
    • Advertise
    • Submit a Tool
Darknet – Hacking Tools, Hacker News & Cyber Security

Darknet - Hacking Tools, Hacker News & Cyber Security

Darknet is your best source for the latest hacking tools, hacker news, cyber security best practices, ethical hacking & pen-testing.

Android Phones (Possibly) Hacked At Defcon On CDMA & 4G (HSPA)

August 12, 2011

Views: 15,166

It seems like some major ownage was layed down at Defcon, I was very interested by the thread coderman posted in Full Disclosure earlier:

DEF CON 19 – hackers get hacked!

Especially when some people did chime in with supporting opinions and agreeing that it does seem like they got hacked. Basically someone setup some bogus CDMA/4G cell towers (probably with OpenBTS) and hacked a bunch of Android phones (that’s what is being claimed anyway).

And just to clarify – there’s no REAL 4G or LTE hacking involved – in the US they call HSPA 4G.

Claims that both CDMA and 4G networks were compromised at the recent Defcon security event in Las Vegas have raised little surprise, but the vulnerability of handsets is hotly debated.

The claim was made by coderman, a stalwart of security conferences, who reports that he witnessed an advanced man-in-the-middle attack operating on both CDMA and UMTS networks and masterminded by an amalgam of Anon and Lulz. This attack was apparently able to identify connected devices and run through known exploits before falling back to ask the user’s permission to install.

The symptoms of infection include “3G/4G* signal anomalies”, “Android [device] at full charged plugged in, but dropping to <50% charge once unplugged", "Android services that immediately respawn when killed" and "a hard freeze, and then take[ing] a long time to reboot". Android users might recognise that as SNAFU, but according to coderman it indicates the user has fallen prey to hackers from the usually-desperate groups Anon and Lulz. Other attendees are less certain, with many asking for more evidence (we did too, with equal lack of success). While it's hard to see if the attack happened as described much of it is plausible and follows a steady erosion of the security around cellular networks, which have stood the test of time well but are now recognised as weakening. Critically the 2G networks do not authenticate both ways – the handset authenticates to the network, but not the other way round – so it's relatively easy for an attacker to set up a femtocell and intercept communications. Handsets will also drop the encryption level on request by the network, which is required for use in countries where strong encryption is still verboten but provides an opportunity for the attacker to simply switch off the encryption.

Now there’s a lot of claims flying around here including the hacks, how advanced they are and who they were perpetrated by (Anonymous and LulzSec?).

Yes, cell network hacking has moved forward a lot in the last couple of years and the processing power of the average laptop is more than enough to own most cellular networks – but did this really happen? Right now no-one know, and really who is going to come forwards with evidence?

“Hi, I’m a l33t hacker and my phone got raped at Defcon 19” – yah sorry but that’s not going to happen.

Handsets are supposed to display such a change of status to the user, but they don’t.

Faking a call is still very hard, the secret shared between the SIM and the network authentication centre remains secure and hard to crack as ever, but once the encryption is off then data can be intercepted and false updates can be pushed out to smartphones.

In most cases such updates will require user permission to install, and will need to be signed or present additional dialogs, but users will generally agree to anything they’re presented with. The Defcon attendees might be more cautious, but the technique should be expected elsewhere.

Certainly there are numerous reports of strange cell sites popping up during the conference.

Our man on the ground, Dan Goodin, didn’t see any himself, but as handsets automatically connect to the nearest base station with the right operator code there’s no obvious notification and little to stop calls and data being intercepted.

3G networks, including HSPA, are a lot more secure and authenticate in both directions. That makes interception harder, but not impossible. Interception is then dependent on the encryption being used; A5/3 is mandated in Europe and really hard to break, but not widely used. The USA still seems to be using A5/2, at best, for some reason.

So interception of cellular data is eminently plausible, and faking updates is also plausible, but when it comes to inserting malicious code into handsets one is just as dependent on the mobile OS as if one were connecting over a Wi-Fi connection.

The whole thing is plausible? Yah definitely, but Defcon attendees are not your average drones (I hope) – and have at least some security smarts.

The delivery mechanism for this attack is the same old story, pushing out malicious updates and hoping the user installs them. For an average joe – yes this will work, for anyone who works in infosec? I find that unlikely.

I really hope more research is done on these attacks and we get to see some evidence of what really went down.

Source: The Register

Related Posts:

  • US Voting Machines Hacked At DEF CON - Every One
  • An Introduction To Web Application Security Systems
  • Why Are Hackers Winning The Security Game?
  • Should US Border Cops Need a Warrant To Search Devices?
  • TeamViewer Hacked? It Certainly Looks Like It
  • Shadow Brokers NSA Hack Leaks 0-day Vulnerabilities
Share
Tweet24
Share5
Buffer
WhatsApp
Email
29 Shares

Filed Under: Exploits/Vulnerabilities, Privacy Tagged With: android, android security, anonymous, defcon, hacking android, lulzsec



Reader Interactions

Comments

  1. 802.16 says

    August 15, 2011 at 3:06 am

    The 4G WiMAX networks were in fact being MitM’d, I’ve confirmed with several security contacts close to Clear.

    • Darknet says

      August 15, 2011 at 11:25 am

      Thanks for the confirmation.

Primary Sidebar

Search Darknet

  • Email
  • Facebook
  • LinkedIn
  • RSS
  • Twitter

Advertise on Darknet

Latest Posts

Defending Against Malicious Botnets in 2025 Automated Traffic Threats and Mitigation

Defending Against Malicious Botnets in 2025 Automated Traffic Threats and Mitigation

Views: 175

Automated internet traffic will now overtake human activity, presenting sophisticated cyber threats … ...More about Defending Against Malicious Botnets in 2025 Automated Traffic Threats and Mitigation

TREVORspray - Credential Spray Toolkit for Azure, Okta, OWA & More

TREVORspray – Credential Spray Toolkit for Azure, Okta, OWA & More

Views: 342

TREVORspray is a purpose-built password spraying utility designed for red teams and offensive … ...More about TREVORspray – Credential Spray Toolkit for Azure, Okta, OWA & More

Force Push Scanner - Hunt GitHub Dangling Commits for Leaked Secrets

Force Push Scanner – Hunt GitHub Dangling Commits for Leaked Secrets

Views: 349

Force Push Scanner is an offensive security tool that identifies secrets inadvertently left in … ...More about Force Push Scanner – Hunt GitHub Dangling Commits for Leaked Secrets

Emerging Darknet Marketplaces of 2025 Anatomy Tactics & Trends

Emerging Darknet Marketplaces of 2025 Anatomy Tactics & Trends

Views: 5,486

Darknet marketplaces remain central to illicit trade in 2025, with evolving business models, payment … ...More about Emerging Darknet Marketplaces of 2025 Anatomy Tactics & Trends

Caracal - Rust eBPF Rootkit for Stealthy Post-Exploitation

Caracal – Rust eBPF Rootkit for Stealthy Post-Exploitation

Views: 519

Caracal is a new Rust-based eBPF (extended Berkeley Packet Filter) rootkit that provides a stealth … ...More about Caracal – Rust eBPF Rootkit for Stealthy Post-Exploitation

Windows_EndPoint_Audit - Endpoint Security Auditing Toolkit

Windows_EndPoint_Audit – Endpoint Security Auditing Toolkit

Views: 575

Windows_EndPoint_Audit from ITAuditMaverick introduces a powerful method for offensive security … ...More about Windows_EndPoint_Audit – Endpoint Security Auditing Toolkit

Topics

  • Advertorial (28)
  • Apple (46)
  • Cloud Security (2)
  • Countermeasures (231)
  • Cryptography (84)
  • Dark Web (1)
  • Database Hacking (89)
  • Events/Cons (7)
  • Exploits/Vulnerabilities (432)
  • Forensics (65)
  • GenAI (4)
  • Hacker Culture (9)
  • Hacking News (231)
  • Hacking Tools (688)
  • Hardware Hacking (82)
  • Legal Issues (179)
  • Linux Hacking (74)
  • Malware (240)
  • Networking Hacking Tools (353)
  • Password Cracking Tools (105)
  • Phishing (41)
  • Privacy (219)
  • Secure Coding (119)
  • Security Software (236)
  • Site News (51)
    • Authors (6)
  • Social Engineering (37)
  • Spammers & Scammers (76)
  • Stupid E-mails (6)
  • Telecomms Hacking (6)
  • UNIX Hacking (6)
  • Virology (6)
  • Web Hacking (384)
  • Windows Hacking (170)
  • Wireless Hacking (45)

Security Blogs

  • Dancho Danchev
  • F-Secure Weblog
  • Google Online Security
  • Graham Cluley
  • Internet Storm Center
  • Krebs on Security
  • Schneier on Security
  • TaoSecurity
  • Troy Hunt

Security Links

  • Exploits Database
  • Linux Security
  • Register – Security
  • SANS
  • Sec Lists
  • US CERT

Footer

Most Viewed Posts

  • Brutus Password Cracker Hacker – Download brutus-aet2.zip AET2 (2,333,820)
  • Darknet – Hacking Tools, Hacker News & Cyber Security (2,173,359)
  • Top 15 Security Utilities & Download Hacking Tools (2,096,839)
  • 10 Best Security Live CD Distros (Pen-Test, Forensics & Recovery) (1,199,813)
  • Password List Download Best Word List – Most Common Passwords (933,804)
  • wwwhack 1.9 – wwwhack19.zip Web Hacking Software Free Download (776,476)
  • Hack Tools/Exploits (673,480)
  • Wep0ff – Wireless WEP Key Cracker Tool (530,461)

Search

Recent Posts

  • Defending Against Malicious Botnets in 2025 Automated Traffic Threats and Mitigation July 16, 2025
  • TREVORspray – Credential Spray Toolkit for Azure, Okta, OWA & More July 14, 2025
  • Force Push Scanner – Hunt GitHub Dangling Commits for Leaked Secrets July 11, 2025
  • Emerging Darknet Marketplaces of 2025 Anatomy Tactics & Trends July 9, 2025
  • Caracal – Rust eBPF Rootkit for Stealthy Post-Exploitation July 7, 2025
  • Windows_EndPoint_Audit – Endpoint Security Auditing Toolkit July 4, 2025

Tags

apple botnets computer-security darknet Database Hacking ddos dos exploits fuzzing google hacking-networks hacking-websites hacking-windows hacking tool Information-Security information gathering Legal Issues malware microsoft network-security Network Hacking Password Cracking pen-testing penetration-testing Phishing Privacy Python scammers Security Security Software spam spammers sql-injection trojan trojans virus viruses vulnerabilities web-application-security web-security windows windows-security Windows Hacking worms XSS

Copyright © 1999–2025 Darknet All Rights Reserved · Privacy Policy