Mobile woes: Modems expose control panels

In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said

02/19/2014


In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said.

Devices managed via their built-in web servers are vulnerable to cross-site request forgery (CSRF) attacks, said researcher Andreas Lindh. This means a malicious website visited by a victim can end up gaining access to the USB modem’s control-panel web page and tamper with the device.

Thus, a vulnerable device can end up sending SMS messages over the mobile network to a premium-rate number. Similarly, a malicious web page could masquerade as a legit login page and covertly text the victim’s username and password.

Lindh said he was able to contain a counterfeit Facebook login page in a data URI hidden behind a TinyURL link, which could end up sent to a victim by email or a social network: Opening the data URI renders the bogus Facebook page in the browser, and when the user submits his or her username and password, some JavaScript texts the credentials via the connected vulnerable USB modem.

The web interface for each affected device usually ends up reached from a 192.168.x.x or 10.x.x.x network address: It can configure roaming or set a SIM PIN. But one of the less publicized features is the ability to silently send and receive text messages, once the user has successfully connected the device to the phone network.

"I fairly quickly found a CSRF vulnerability that would allow me to make the modem send a text message to any number of my choosing, simply by having the user go to a website under my control," Lindh said. "Unlike Wi-Fi routers, there is no login functionality for USB modems so I didn’t have to worry about bypassing authentication."

Martijn Grooten, Virus Bulletin’s anti-spam test director, said the vulnerability Lindh found is perfect for spear-phishing attacks.

The problems all stem from a lack of consideration for security in the design of cheap consumer communications kit and, more particularly, a lack of testing, said David Rogers, who teaches mobile systems security at the University of Oxford. The 3G/4G modem issue is due to a lack of authentication, and a firmware update combined with a fresh set of instructions to consumers could resolve the issue, he said.

- Greg Hale, ISSSource.com



No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
The System Integrator Giants program lists the top 100 system integrators among companies listed in CFE Media's Global System Integrator Database.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
This eGuide illustrates solutions, applications and benefits of machine vision systems.
Learn how to increase device reliability in harsh environments and decrease unplanned system downtime.
This eGuide contains a series of articles and videos that considers theoretical and practical; immediate needs and a look into the future.
System integration: Best practices and technologies to help; Virtualization virtues; Cyber security advice; Motor system efficiency, savings; Product exclusives; Road to Hannover
Collaborative robotics: How to improve safety, return on investment; Industrial Internet of Things, Industrie 4.0: World views; High-performance HMI, Information Integration: OPC and OMG
9 tips: How to integrate a servo system; Process control mathematical models; Serial network grounding; Engineers' Choice Awards; Learn from cyber security mistakes
This article collection contains several articles on the Industrial Internet of Things (IIoT) and how it is transforming manufacturing.
PLCs, robots, and the quest for a single controller; how OEE is key to automation solutions.
Learn how Industry 4.0 adds supply chain efficiency, optimizes pricing, improves quality, and more.

Find and connect with the most suitable service provider for your unique application. Start searching the Global System Integrator Database Now!

Getting to the bottom of subsea repairs: Older pipelines need more attention, and operators need a repair strategy; OTC preview; Offshore production difficult - and crucial
Digital oilfields: Integrated HMI/SCADA systems enable smarter data acquisition; Real-world impact of simulation; Electric actuator technology prospers in production fields
Special report: U.S. natural gas; LNG transport technologies evolve to meet market demand; Understanding new methane regulations; Predictive maintenance for gas pipeline compressors
click me