Re: Questions on GSM Penetration test

From: John Adams (jadams@inktomi.com)
Date: 01/28/02


Date: Mon, 28 Jan 2002 11:11:30 +0900 (GMT)
From: "John Adams" <jadams@inktomi.com>
To: M Lister <mlist@m-net.arbornet.org>

On Sat, 26 Jan 2002, M Lister wrote:

> > 2. You can copy a sim card.
>
> Please forgive me if this sounds naive, but I was under a *STRONG*
> impression that it is practically impossible to copy a smart card. [Isnt
> that what is used as a SIM card]. From the little that I know of smart

You really might want to look around at all of the resources people have
devoted to cracking, breaking, and emulating smart cards for Direct TV,
Dish network, and DSS. If it's any indication of what we're to expect when
we use smart cards as the sole authentication factor in a security (or
currently for that matter) then we still have a long way to go before
smart cards can be widely used as a secure means of authentication.

GSM security has been cracked as well, nearly days after it released in
europe.

-john

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Risks Digest 25.08
    ... Wind Power Risks ... FBI Found to Misuse Security Letters ... RFID hack could crack open 2 billion smart cards ...
    (comp.risks)
  • [NT] Console Java Applications can Leak Passphrases on Windows
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... or by further smart cards known as Operator Card ... Each card can be further protected by a passphrase, ... brand names include Java support. ...
    (Securiteam)
  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)