DEF CON 31 - Using SIM Tunneling to Travel at Light Speed - Adrian Dabrowski, Gabriel Gegenhuber

  Рет қаралды 21,724

DEFCONConference

DEFCONConference

Күн бұрын

Cellular networks form large complex compounds for roaming purposes. Thus, geographically-spread testbeds for masurements and rapid exploit verification are needed to do justice to the technology's unique structure and global scope. Additionally, such measurements suffer from a combinatorial explosion of operators, mobile plans, and services. To cope with these challenges, we are releasing an open-source framework that geographically decouples the SIM (subscription) from the cellular modem by selectively connecting both remotely. This allows testing any subscriber with any operator at any modem location within seconds without moving parts. The resulting measurement and testbed platform "MobileAtlas" offers a scalable, controlled experimentation environment. It is fully open-sourced and allows other researchers to contribute locations, SIM cards, and measurement scripts.
Using the above framework, our international experiments in commercial networks revealed exploitable inconsistencies in traffic metering, leading to multiple data "phreaking" opportunities ("free-ride"). We also expose problematic IPv6 firewall configurations, hidden SIM card communication to the home network, and fingerprint dial progress tones to track victims across different roaming networks and countries with voice calls.

Пікірлер: 18
@jeffcard3623
@jeffcard3623 8 ай бұрын
The comedy was over the head of this audience.
@Hukkinen
@Hukkinen 8 ай бұрын
38:05 Privacy: Location Tracking with Ringback Tone Fingerpringing - This is quite something. The current country of a person can be determined.
@DonaldDucksRevenge
@DonaldDucksRevenge 6 ай бұрын
This the wholesomest hackery since Crunch whistled into a payphone
@sabofx
@sabofx 8 ай бұрын
Great presentation! Thank you for sorting this out! Mobile providers have profited more than enough from us, bandwidth hungry tourists. It's payback time! 🤭 PS: What's up with the audience at defcon31? They seem barely responsive. (Not just at this talk) Either someone should check them for a pulse 😵, or you need to point at least one 🎤 towards the public.
@zxcvb_bvcxz
@zxcvb_bvcxz 8 ай бұрын
From the audio of most of the talks, they had enough trouble getting a clear recording of the speaker. The audience is audible in some talks but it appears to either be gated or attenuated.
@zxcvb_bvcxz
@zxcvb_bvcxz 8 ай бұрын
@@dabrams84 a) lol b) the audience noise is gated, you can clearly hear it kicking in in other videos.
@CJ1337HF
@CJ1337HF 7 ай бұрын
Yeah I was there and there was plenty of laughs. It's just filtered out
@IgnatRemizov
@IgnatRemizov 8 ай бұрын
I wonder what the cost spread is like. What is the actual $ per GB roaming cost between all the different operators? Which one is the best, based on various factors? I would love to know
@dtriplett03
@dtriplett03 6 ай бұрын
Idk yet, but , 🇺🇸 increased 🇬🇧 decreased 😢😮
@vildis.
@vildis. 6 ай бұрын
What happened to Spoofify? Mentions about it are gone from the slides and i can't find the project anywhere
@BASSNETIC-MUSIC
@BASSNETIC-MUSIC 7 ай бұрын
The jokes were much to smart for this audience 😂 That fingerprinting is wild. Indonesia blocks your foreign device based on IMEI after a while and you need to pay tax to unlock it. Even if you try to circumvent this by putting the SIM in another device and connect through that using a hotspot! Would be nice to not have to deal with such nonsense.
@haczyk84
@haczyk84 5 ай бұрын
Polak? Przypominają mi się stare dobre czasy budek telefonicznych.
@razorednight
@razorednight 6 ай бұрын
Defcon!! In future plz mic the audience. This "silent audience" set up is not great.
@M3talr3x
@M3talr3x 7 ай бұрын
Is this only applicable for europoors?
Getting Started in Automotive Hacking, Installation & Tools
5:39
Block Harbor
Рет қаралды 4,3 М.
СҰЛТАН СҮЛЕЙМАНДАР | bayGUYS
24:46
bayGUYS
Рет қаралды 645 М.
Don't eat centipede 🪱😂
00:19
Nadir Sailov
Рет қаралды 23 МЛН
Can You Draw The PERFECT Circle?
00:57
Stokes Twins
Рет қаралды 89 МЛН
How To Hack APIs with Python
22:55
John Hammond
Рет қаралды 81 М.
Kiosk mode Bruteforce Evasion with Flipper Zero
0:40
Но Комп
Рет қаралды 1,2 МЛН
How Secure Shell Works (SSH) - Computerphile
9:20
Computerphile
Рет қаралды 809 М.
DEF CON 31 - Physical Attacks Against Smartphones - Christopher Wade
37:01
How to make, dimple lock picks at home.
7:43
Rook Knight
Рет қаралды 8 М.
DEF CON 31 War Stories - Living Next Door to Russia - Mikko Hypponen
47:46
VLAN Explained
4:38
PowerCert Animated Videos
Рет қаралды 1,6 МЛН
XL-Power Best For Audio Call 📞 Mobile 📱
0:42
Tech Official
Рет қаралды 772 М.
Wow AirPods
0:17
ARGEN
Рет қаралды 1,2 МЛН
A Comprehensive Guide to Using Zoyya Tools for Photo Editing
0:50