- 09-27-2012, 04:45 PM
Thread Author #1
- 09-27-2012, 06:59 PM #2
- 09-27-2012, 07:37 PM #3
- 09-27-2012, 09:24 PM #4
Re: USSD vulnerability
Nico, no, its a real threat... There is a submission on the cm ics gerrit. not sure if/when it will be accepted
Guess whos coming back! - 09-27-2012, 11:03 PM #5
Re: USSD vulnerability
Who says our phones are affected? Any phone will pull up the MEID with that code. HOWEVER...just because you have a dialer code that pulls up your MEID does not mean we have one that initiates any sort of factory reset. There is no proof that our phones are vulnerable to this kind of attack.
--Chris [cole2kb]

"Any story about malware on any platform...without numbers is not giving you the full picture, and just might be more worried about getting your clicks than any real discussion."
Words to live by: there are always two sides to every story. - 09-27-2012, 11:11 PM #6
Re: USSD vulnerability
Very true, but I think the real question is, how likely is it that someone would initiate this attack against you? I guess what I mean to say is, what's the motivation for doing this to someone? Is there anything to be gained through such an attack?
Sent from my LG-VM670 using Tapatalk 2This space intentionally left blank. - 09-27-2012, 11:19 PM #7
Re: USSD vulnerability
If you can click on one of these links, it could dial a premium number and initiate a charge on your bill, but that's one of the beauties of being pre-paid, we can't even use these services.
The worst case scenario is a factory reset, a la the Samsung phones affected. But, I have yet to find a dialer code to do that on our devices.--Chris [cole2kb]

"Any story about malware on any platform...without numbers is not giving you the full picture, and just might be more worried about getting your clicks than any real discussion."
Words to live by: there are always two sides to every story.Thanked by 2: - 09-28-2012, 08:42 AM #8
- 09-28-2012, 02:04 PM #9
Re: USSD vulnerability
I don't see any point for anyone to use this "vulnerability" in the wild for, well, anything. Its pointless. Worst case scenario is you have to restore one of your full backups (you do make these, right?)
But tomorrow I will be patching my roms against this and releasing in the usual places.my roms & kernels (based on iho)
If you'd like to donate to me, i accept litecoin, bitcoin, and hardware
LTC - LTVALL5gsjPvgeiBWD7c6DHNWidbpzVu3w
BTC - 1TVALLetFibDe8Zap5qPsqa4BAJWQYQ59Thanked by 2: - 09-28-2012, 02:54 PM #10Guess whos coming back!
- 09-28-2012, 04:54 PM
Thread Author #11
Re: USSD vulnerability
What ever the attack could or couldn't do I think I can spare the 250kb of internal space with a second dialer app that for surely can't even execute any of the ussd's. But then again this is America were so many of us walk around unarmed like bad people don't exist. There will be Guinea pigs and some bad things might happen to good people but at least I'll be a spectator and not a participant.

Sent from my LG-VM670 using Android Central Forumsbeamed from the mothership...but its only a proxy for mylubuntu 12.04 - 09-28-2012, 05:01 PM #12my roms & kernels (based on iho)
If you'd like to donate to me, i accept litecoin, bitcoin, and hardware
LTC - LTVALL5gsjPvgeiBWD7c6DHNWidbpzVu3w
BTC - 1TVALLetFibDe8Zap5qPsqa4BAJWQYQ59 - 09-28-2012, 05:34 PM #13Guess whos coming back!
- 09-29-2012, 01:34 PM #14
- 09-30-2012, 03:12 PM #15
- 09-30-2012, 07:41 PM #16
- 10-01-2012, 08:51 PM #17
Re: USSD vulnerability
That's my theory, not every single phone is the same, so it is VERY hard to hit every single combo. As far as I know, the Samsung phones all have very similar codes and such, making them the biggest target in the Android world. If they could crack the iPhone, it would be even easier.
Similar Threads
-
Vulnerability: Remote USSD Attack
By darkavenger in forum LG Optimus S Rooting, ROMs, and HacksReplies: 19Last Post: 10-06-2012, 11:23 PM -
Skype for Android Vulnerability!!! READ!
By deeznuts2 in forum Verizon HTC ThunderboltReplies: 17Last Post: 04-16-2011, 08:38 AM -
QCodes - ussd requests application
By Solvek in forum Android ApplicationsReplies: 0Last Post: 12-07-2010, 04:53 AM -
vulnerable after rooting?
By droidandme in forum AT&T Captivate Rooting, ROMs, and HacksReplies: 1Last Post: 08-03-2010, 05:16 PM -
EVO Vulnerabilities
By barko12 in forum HTC EVO 4GReplies: 20Last Post: 06-04-2010, 06:22 AM



Reply




































