Your Web News in One Place

Help Webnuz

Referal links:

Sign up for GreenGeeks web hosting
September 25, 2012 12:17 pm EDT

'Dirty USSD' code could automatically wipe your Samsung TouchWiz device

'Dirty USSD' code embed can reset your Samsung Galaxy S III  and other TouchWiz devices

The Factory Reset. One of those last ditch efforts that many of us have a fair bit of experience with. However, a malicious embed code could potentially do the exact same thing to your Galaxy S III. The Unstructured Supplementary Service Data (USSD) code (which we won't reproduce here) apparently only works on Samsung phones running Touchwiz, and only if you are directed to the dodgy destination while inside the stock browser (rather than Chrome, for example). This means the Galaxy Nexus is unaffected, but it can work the same dark magic on the likes of the Galaxy S II.

We've been trying to murder a GS III here at Engadget, but with no luck as yet -- we can cause the malicious digits to appear in the dialer, but we can't force the stock browser to visit them as a URL, even when trying a bit of URL forwarding and QR code trickery. However, this particular GS III has been rooted in the past, even though it's now running an official TouchWiz ROM, and that may be interfering with the process.

Aside from our own experiences, the evidence for the vulnerability is certainly strong. It was demonstrated at the Ekoparty security conference last weekend, during which time presenter Ravi Borgaonkar also showed how a different code could even wipe your SIM card. See the video after the break for the evidence.

Continue reading 'Dirty USSD' code could automatically wipe your Samsung TouchWiz device

Filed under: , , ,

'Dirty USSD' code could automatically wipe your Samsung TouchWiz device originally appeared on Engadget on Tue, 25 Sep 2012 08:17:00 EDT. Please see our terms for use of feeds.

PermalinkTom Scott (Twitter) | sourceAlejandrospamloco (YouTube), Ekoparty security conference ||Comments

Original Link: http://www.engadget.com/2012/09/25/dirty-ussd-code-samsung-hack-wipe/

Share this article:    Share on Facebook
View Full Article

Engadget

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics. Engadget was launched in March of 2004 in partnership with the Weblogs, Inc. Network (WI

More About this Source Visit Engadget