Scientists spot 4G bug that can help hackers impersonate you

Feb 23, 2020
Berlin: Researchers have found a serious vulnerability in LTE/4G mobile communication standard that can help hackers impersonate other phone users, take a streaming service subscription at your expense or publish secret company documents under someone else’s identity.

The vulnerability — which affects virtually all mobile phones, tablets and some connected household appliances — may also hamper investigations of law enforcement agencies because attackers can not only make purchases in the victim’s name but can also access websites using the victim’s identity.

For example, an attacker can upload secret company documents and to network operators or law enforcement authorities, it would look as if the victim is the perpetrator, said researchers from Ruhr-Universitat Bochum public university.

“An attacker can book services, for example stream shows, but the owner of the attacked phone would have to pay for them,” said Professor Thorsten Holz from Horst Gortz Institute for IT Security.

Only changing the hardware design would mitigate the threat.

The team is attempting to close the security gap in the latest mobile communication standard 5G, which is currently rolled out.

“Mobile network operators would have to accept higher costs, as the additional protection generates more data during the transmission. In addition, all mobile phones would have to be replaced and the base station expanded. That is something that will not happen in the near future,” said David Rupprecht.

The problem is the lack of integrity protection: data packets are transmitted encrypted between the mobile phone and the base station, which protects the data against eavesdropping.

However, it is possible to modify the exchanged data packets.

“We don’t know what is where in the data packet, but we can trigger errors by changing bits from 0 to 1 or from 1 to 0,” said Rupprecht.

By provoking such errors in the encrypted data packets, the researchers can make a mobile phone and the base station decrypt or encrypt messages.

They not only can convert the encrypted data traffic between the mobile phone and the base station into plain text, they can also send commands to the mobile phone, which are then encrypted and forwarded to the provider – such as a purchase command for a subscription.

The researchers from Bochum used so-called software-defined radios for the attacks.

These devices enable them to relay the communication between mobile phone and base station.

Thus, they trick the mobile phone to assume that the software-defined radio is the benign base station; to the real network, in turn, it looks as if the software-defined radio was the mobile phone.

For a successful attack, the attacker must be in the vicinity of the victim’s mobile phone, said the researchers. IANS

Kolkata Police forms nine-member SIT to probe IIM-Calcutta rape case

Kolkata: Police have formed a nine-member Special Investigation Team (SIT) to probe the alleged rape of an outsider woman by a second-year student of the Indian Institute of Management-Calcutta (IIM-C)...

Iranian Prez was injured in Israel’s Nasrallah-style assassination plot: Report

Tehran: Iranian President Masoud Pezeshkian sustained a minor leg injury during an Israeli airstrike that targeted a building in western Tehran on June 16, a semi-official news agency reported on...

Russian FM meets Kim Jong-un during visit to North Korea

Seoul: Russian Foreign Minister Sergei Lavrov met with North Korean leader Kim Jong-un on Saturday during his visit to North Korea, Moscow's foreign ministry said. In a Telegram post, the...

IIM-Calcutta rape case: Questions raised over campus security

Kolkata: Serious concerns have emerged over the security arrangements at the Indian Institute of Management-Calcutta (IIM-C), after a woman was allegedly raped inside the boys’ hostel on the campus's southern...

Namibian female Cheetah Nabha succumbs to injuries

Bhopal: In a poignant development from Kuno National Park, a Namibian female cheetah named ‘Nabha’ has died following injuries sustained during a hunting attempt within her 'Soft Release Boma'. Boma...

Shubhanshu Shukla in good health, likely to reach Earth on July 15: ISRO

New Delhi: Indian astronaut Shubhanshu Shukla, currently on board the International Space Station, is expected to begin his journey back to Earth on July 14, and reach on July 15,...

Pakistan: Nine people abducted, shot dead in Balochistan

Islamabad: At least nine passengers were abducted and killed by unidentified gunmen in Pakistan's Balochistan province, the spokesperson of the provincial government confirmed on Friday.   The incident occurred near...

Punjab Assembly unanimously adopts resolution against deployment of CISF at BBMB projects

Chandigarh: The Punjab Assembly on Friday unanimously adopted a resolution against the deployment of Central Industrial Security Force (CISF) personnel at hydropower projects of the Bhakra Beas Management Board (BBMB),...

No criminal offence in merely supporting Pakistan: Allahabad HC

New Delhi: The Allahabad High Court has ruled that merely showing support to Pakistan, without referring to any incident or mentioning the name of India, will not prima facie attract...

South Korea, US, Japan stage joint air drills involving B-52 bomber

Seoul: South Korea, the United States and Japan held combined air drills Friday as part of efforts to strengthen their joint response against North Korea's nuclear and missile threats, the...

Former Iranian official hints at possible assassination attempt on Trump

Tehran: Mohammad-Javad Larijani, a former senior advisor to Iran’s Supreme Leader Ayatollah Ali Khamenei, hinted at an assassination attempt on US President Donald Trump, implying that he could face a...

Shubhanshu Shukla to begin journey back to Earth on July 14: Axiom Space

New Delhi: Indian astronaut Shubhanshu Shukla, currently on board the International Space Station, is expected to begin his journey back to Earth on July 14, said Axiom Space on Friday....

Read Previous

Finishing touches being given at the Motera Stadium for the Feb 24 “Namaste Trump” event in Ahmedabad . (Photo IANS/PIB)

Read Next

Samsung Galaxy A51: All rounder mid-range smartphone

WP2Social Auto Publish Powered By : XYZScripts.com