Mobile woes: Modems expose control panels
In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said
In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said.
Devices managed via their built-in web servers are vulnerable to cross-site request forgery (CSRF) attacks, said researcher Andreas Lindh. This means a malicious website visited by a victim can end up gaining access to the USB modem’s control-panel web page and tamper with the device.
Thus, a vulnerable device can end up sending SMS messages over the mobile network to a premium-rate number. Similarly, a malicious web page could masquerade as a legit login page and covertly text the victim’s username and password.
The web interface for each affected device usually ends up reached from a 192.168.x.x or 10.x.x.x network address: It can configure roaming or set a SIM PIN. But one of the less publicized features is the ability to silently send and receive text messages, once the user has successfully connected the device to the phone network.
"I fairly quickly found a CSRF vulnerability that would allow me to make the modem send a text message to any number of my choosing, simply by having the user go to a website under my control," Lindh said. "Unlike Wi-Fi routers, there is no login functionality for USB modems so I didn’t have to worry about bypassing authentication."
Martijn Grooten, Virus Bulletin’s anti-spam test director, said the vulnerability Lindh found is perfect for spear-phishing attacks.
The problems all stem from a lack of consideration for security in the design of cheap consumer communications kit and, more particularly, a lack of testing, said David Rogers, who teaches mobile systems security at the University of Oxford. The 3G/4G modem issue is due to a lack of authentication, and a firmware update combined with a fresh set of instructions to consumers could resolve the issue, he said.
- Greg Hale, ISSSource.com
|Search the online Automation Integrator Guide|
Case Study Database
Get more exposure for your case study by uploading it to the Control Engineering case study database, where end-users can identify relevant solutions and explore what the experts are doing to effectively implement a variety of technology and productivity related projects.
These case studies provide examples of how knowledgeable solution providers have used technology, processes and people to create effective and successful implementations in real-world situations. Case studies can be completed by filling out a simple online form where you can outline the project title, abstract, and full story in 1500 words or less; upload photos, videos and a logo.
Click here to visit the Case Study Database and upload your case study.