Remote USSD Attack - Samsung Android phones

Status
Not open for further replies.
Custom Title Activated
Loyal Member
Joined
Apr 26, 2005
Messages
3,137
Reaction score
496






This basicly allows you to completely wipe most Samsung android phones (including the S3) remotely by luring the user to your website (where the code to reset the device is executed upon loading the website). For the S3 it only works if the user is still on the default android version and hasn't upgraded to Jelly Bean. The default browser must be used too.

So if you recently got an S3, upgrade it to Jelly bean!
 
Joined
Mar 7, 2003
Messages
5,747
Reaction score
899
Having skype means it constantly asks me what I want to use, that or the default browser.

So I guess that would mean if this happened, it would stop it and ask me what to do?

But yeah having a USSD to reset the phone is silly. Though maybe it has some reason to have it, like it's a part of Samsung Dive or something?
 
Joined
Apr 28, 2005
Messages
6,953
Reaction score
2,420
You're correct. As long as the "use this by default" box isn't checked it'll always ask you which one before opening.

I don't know many people who use the stock android browser anyway. Most people either use dolphin or chrome. If this only works on the initial version that shipped with the gs3 and the stock browser then I don't see this as a problem.
 
Custom Title Activated
Loyal Member
Joined
Apr 26, 2005
Messages
3,137
Reaction score
496

Correct.


The thing is that it's not just the GS3, the GS3 and other Samsung phones are vulnerable as well.
 
Status
Not open for further replies.