Mobile woes: Modems expose control panels

In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said


In another scenario where mobile devices have an inherent lack of security, vulnerabilities in 3G and 4G USB modems can end up exploited to steal login credentials or send premium rate text messages, a researcher said.

Devices managed via their built-in web servers are vulnerable to cross-site request forgery (CSRF) attacks, said researcher Andreas Lindh. This means a malicious website visited by a victim can end up gaining access to the USB modem’s control-panel web page and tamper with the device.

Thus, a vulnerable device can end up sending SMS messages over the mobile network to a premium-rate number. Similarly, a malicious web page could masquerade as a legit login page and covertly text the victim’s username and password.

Lindh said he was able to contain a counterfeit Facebook login page in a data URI hidden behind a TinyURL link, which could end up sent to a victim by email or a social network: Opening the data URI renders the bogus Facebook page in the browser, and when the user submits his or her username and password, some JavaScript texts the credentials via the connected vulnerable USB modem.

The web interface for each affected device usually ends up reached from a 192.168.x.x or 10.x.x.x network address: It can configure roaming or set a SIM PIN. But one of the less publicized features is the ability to silently send and receive text messages, once the user has successfully connected the device to the phone network.

"I fairly quickly found a CSRF vulnerability that would allow me to make the modem send a text message to any number of my choosing, simply by having the user go to a website under my control," Lindh said. "Unlike Wi-Fi routers, there is no login functionality for USB modems so I didn’t have to worry about bypassing authentication."

Martijn Grooten, Virus Bulletin’s anti-spam test director, said the vulnerability Lindh found is perfect for spear-phishing attacks.

The problems all stem from a lack of consideration for security in the design of cheap consumer communications kit and, more particularly, a lack of testing, said David Rogers, who teaches mobile systems security at the University of Oxford. The 3G/4G modem issue is due to a lack of authentication, and a firmware update combined with a fresh set of instructions to consumers could resolve the issue, he said.

- Greg Hale,

No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
The System Integrator Giants program lists the top 100 system integrators among companies listed in CFE Media's Global System Integrator Database.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
This eGuide illustrates solutions, applications and benefits of machine vision systems.
Learn how to increase device reliability in harsh environments and decrease unplanned system downtime.
This eGuide contains a series of articles and videos that considers theoretical and practical; immediate needs and a look into the future.
Choosing controllers: PLCs, PACs, IPCs, DCS? What's best for your application?; Wireless trends; Design, integration; Manufacturing Day; Product Exclusive
Variable speed drives: Smooth, efficient, electrically quite motion control; Process control upgrades; Mobile intelligence; Product finalists: Vote now; Product Exclusives
Machine design tips: Pneumatic or electric; Software upgrades; Ethernet advantages; Additive manufacturing; Engineering Leaders; Product exclusives: PLC, HMI, IO
This article collection contains the 5 most referenced articles on improving the use of PID.
Learn how Industry 4.0 adds supply chain efficiency, optimizes pricing, improves quality, and more.

Find and connect with the most suitable service provider for your unique application. Start searching the Global System Integrator Database Now!

Cyber security cost-efficient for industrial control systems; Extracting full value from operational data; Managing cyber security risks
Drilling for Big Data: Managing the flow of information; Big data drilldown series: Challenge and opportunity; OT to IT: Creating a circle of improvement; Industry loses best workers, again
Pipeline vulnerabilities? Securing hydrocarbon transit; Predictive analytics hit the mainstream; Dirty pipelines decrease flow, production—pig your line; Ensuring pipeline physical and cyber security