A network-related or instance-specific error occurred while establishing a connection to SQL Server. The server was not found or was not accessible. Verify that the instance name is correct and that SQL Server is configured to allow remote connections. (provider: Named Pipes Provider, error: 40 - Could not open a connection to SQL Server) HERE IS A LIST OF THINGS U NEED 2 TEACH UR CHILDREN AT EARLY AGE:, Global : Today Indya

Latest News

Your Data, Location Might be Tracked with This SIM Card Flaw, Without Your Knowledge
Tuesday, September 17, 2019 IST
Your Data, Location Might be Tracked with This SIM Card Flaw, Without Your Knowledge

The SimJacker vulnerability, uncovered by AdaptiveMobile Security, exploits a common SIM card flaw to affect nearly a billion Android, iOS, eSIM and IoT devices.

 
 

SimJacker, a new vulnerability discovered by researchers, has been linked to a widely used software that affects SIM cards used commonly across 30 countries. In what appears to be a critical threat, the flaw is reportedly exploited by simply sending a text message to target devices, which in turn activates specific SIM card instructions that can be used to spy on active location of individuals, send fake messages on behalf of the device owner, make fraudulent calls, force-install malware, steal critical information and more such serious acts.
 
The flaw has been discovered by AdaptiveMobile Security, a frontline provider of real-time cyber-telecom security technologies. While reports indicate that the proof of concept of the attack is yet to be submitted, AdaptiveMobile CEO Cathal McDaid says, "We are quite confident that this exploit has been developed by a specific private company that works with governments to monitor individuals. As well as producing this spyware, this same company also have extensive access to the SS7 and Diameter core network (both critical network backbone infrastructure), as we have seen some of the same Simjacker victims being targeted using attacks over the SS7 network as well, with SS7 attack methods being used as a fall-back method when Simjacker attacks do not succeed."
 
 
To execute such attacks, the infiltrator is only required to send a message that resembles a system code message that is actually a malware code that directly communicates with the SIMalliance Toolbox Browser (or S@T Browser). This is a piece of software that is present in a wide volume of SIM cards across many nations in the world. In a blog post detailing the vulnerability, AdaptiveMobile states that S@T Browser is a legacy protocol, whose technology specifications have not been upgraded in over a decade now. However, by virtue of it being present in SIM cards, attackers are making use of its ability to take actions such as send system messages, set up an operator call, launch specific browser links and send requisite data to a target address.
 
As a result, sensitive data such as live location, device IMEI number and more are being collected in what appears to be a silent espionage project. McDald says, "By using these commands in our own tests, we were able to make targeted handsets open up web browsers, ring other phones, send text messages and so on. These attacks could be used to fulfil such purposes as mis-information by sending SMS/MMS messages with attacker controlled content, fraud by dialling premium rate numbers, espionage as a location retrieving attack, espionage as a listening device by ringing a number, malware spreading by forcing a browser to open a web page with malware located on it, denial of service by disabling the SIM card, information retrieval such as language, radio type, battery level etc. — it even may be possible to go even further, depending on handset type."
 
What is particularly more alarming is that unlike Check Point's recently uncovered vulnerability that arose due to a flaw in the over-the-air update system message being sent on Samsung, Huawei, LG and some other Android devices, the SimJacker vulnerability does not require any action to be taken by a mobile phone user. Instead, it works completely in the background, thereby working as a deadly surveillance tool for any agency with such intentions. The SimJacker vulnerability is also device agnostic, and works with the same intensity across devices made by OEMs such as Apple, Samsung, Google and Huawei — all leaders in the smartphone space. The threat is also imminent on IoT devices, which employ certain builds of eSIM, hence further expanding its potential to what AdaptiveMobile refers as "over a billion individuals across the world".
 
McDald states that AdaptiveMobile has already been in touch with telecom operators in the affected nations, and are working with them to issue a fix. This fix in question would come from an operator's end, which can block fraudulent system messages that carry such malware and spyware-ridden code. The company has also communicated the same to GSM Association and SIMalliance, and will be revealing more details about the SimJacker flaw at the Virus Bulletin Conference in London, on October 3.

 
 

 
 
 
 
 

Related Topics

 
 
 

Trending News & Articles

 Article
'Worse than prison': A rare look inside China's detention camps to 'brainwash' Muslims

ALMATY: Hour upon hour, day upon day, Omir Bekali and other detainees in far western China's new indoctrination camps had to disavow the...

Recently posted . 211K views . 1 min read
 

 Article
What The Shape Of Your Belly Button Says About Your Health

If you have payed attention to the belly buttons of people on the beach or the members of your family, you have probably noticed that they have different shapes and...

Recently posted . 10K views . 2 min read
 

 Article
New ‘Langya’ virus hits China as 35 people found infected: How deadly is it?

The Langya henipavirus has a place with a similar group of infections, including Nipah, which is known to kill up to 3/4 of people in extreme cases.

Recently posted . 5K views . 1 min read
 

 Article
Queen Elizabeth Dies At 96: The New Royal Line Of Succession

Queen's death: The eldest of her four children, Charles, Prince of Wales, who at 73 was the oldest heir apparent in British history, became king immediately...

Recently posted . 5K views . 1 min read
 

 
 

More in Electronics & Gadgets

 Article
Happy April Fools' Day 2018! What is the origin behind it, top facts, best pranks and why we celebrate the tradition

The reasons why we mark April Fools' Day on April 1st every year and the best jokes ever

Recently posted. 816 views . 0 min read
 

 Article
Mark Zuckerberg emerges unscathed by congressional grilling as Facebook hearing ends

Facebook founder Mark Zuckerberg emerged largely unscathed Wednesday from two days of high-stakes hearings that saw US lawmakers grill the billionaire over how the ...

Recently posted. 721 views . 1 min read
 

 Article
Cancer will kill 5.5 million women per year by 2030: Report

Cancer will kill 5.5 million ladies - about the number of inhabitants in Denmark - every year by 2030, an almost 60% expansion in under two decades, a report said T...

Recently posted. 699 views . 10 min read
 

 Photo
The Best Hobbies For Men



Recently posted . 2K views
 

 Reviews
The Best 5 Camping Tents in India 2018 – Reviews & Buying Guide



Recently posted . 3K views . 99 min read
 

 Reviews
Leaseweb hosting review



Recently posted . 3K views . 67 min read
 

 Article
10 Best Beaches in the World – Traveler’s choice

What is the perfect definition of best and beautiful beach? For few people, it may be the beauty of the shore with the whiteness of the sand. For few others, it m...

Recently posted. 1K views . 3 min read
 

 Article
QUARTER OF THE WORLD'S POPULATION IS UNDER EXTREME WATER STRESS, SAYS WRI REPORT

Consequences like food insecurity and conflict will also be felt in India, which is among the 17 worst-affected countries.  

Recently posted. 871 views . 1 min read
 

 
 
 

   Prashnavali

  Thought of the Day

"It's always best to have a positive outlook on life, it's easy to see all the bad around you, but there's always good in the world, be thankful you are alive to breathe, to love, to laugh, and to enjoy all the wonders life has to offer."
Anonymous

Be the first one to comment on this story

Close
Post Comment
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST
Shibu Chandran
2 hours ago

Serving political interests in another person's illness is the lowest form of human value. A 70+ y old lady has cancer.

November 28, 2016 05:00 IST


ads
Back To Top