SMS Fuzzing - SIM Toolkit Attack

No ratings

Presented at DeepSec 2011 by

In this talk I will show how to make a phone send an SMS message without the users consent and how to make the phone not to receive any message. The method used works on any phone, no matter if its a smartphone or not and also on any GSM/UMTS network. I will present how you can take advantage of sending a special crafted SIM Toolkit command message in order to achieve all that. Finally, I will present the results and their impact on the user and mobile networks security.