Cатсн²² (in)sесuяitу / ChrisJohnRiley

Because we're damned if we do, and we're damned if we don't!

Tag Archives: Shmoocon

Shmoocon 2011: Defeating mTANs for profit

Defeating mTANs for profit Axelle Apvrille and Kyle Yang   Zeus In The MObile –> ZITMO Malware for Symbian OS > 9.0 Intercepts mTANs (one-time passwords sent over SMS) Targeting Spanish online banks Propagated on PC by Zeus botnet First case seen of organized criminals exploiting mobile TANs   Zeus (AKA Zbot) It’s a crimeware kit [...]

Shmoocon 2011: Attacking 3G and 4G mobile telecommunications networks

Attacking 3G and 4G mobile telecommunications networks Enno Rey, Rene Graf & Daniel Mende   No demos today due to shipping materials and the like. TSA don’t like big electronic devices being shipped after all. Still, that doesn’t mean there was no practical research. Fundamentals Standards In mobile telco world everything is standardized by 3GPP [...]

Shmoocon 2011: Printers gone wild!

Printers Gone Wild! Ben Smith Printers are everywhere… they are ubiquitous! Everybody seems to ignore them. They get plugged in, and just work! HP Basics Listens on tcp/9100 Admin page on 80/443 Many have hard disks! HP printers have 3 passwords Web admin Telnet (same as the wedadmin) PJLPassword PJLPassword can be used to lockout [...]

Shmoocon 2011: TEAM JOCH vs. Android: The Ultimate Showdown

TEAM JOCH vs. Android: The Ultimate Showdown Jon Oberheide and Zach Lanier Android Security Overview Base platform : ARM Core Linux Kernel 2.6.3x Native Libraries Dalvik VM …. TrustZone Security Foundation by ARM ARM11 TrustZone –> Unused! ARM11 Jazelle JVM –> Unused! ARMv6 eXecute-Never (XN)? –> Unused! Mobile ASLR sucks! Exploiting like it’s 1990 Executable [...]

Follow

Get every new post delivered to your Inbox.

Join 36 other followers