Galaxy S III and Other Sammy Devices Vulnerable to Remote Wipe Hack

dgstorm

Editor in Chief
Staff member
Premium Member
Joined
Dec 30, 2010
Messages
10,991
Reaction score
3,961
Location
Austin, TX
[video=youtube;Q2-0B04HPhs]http://www.youtube.com/watch?feature=player_detailpage&v=Q2-0B04HPhs[/video]​

Some security researchers have found a pretty severe security vulnerability in the Samsung Galaxy S III that also appears on several other Samsung devices including the Galaxy Beam, S Advance, Galaxy Ace, and Galaxy S II. According to their demonstration given at the Ekoparty security conference, a simple USSD can trigger an event that will cause the phone to do a factory reset and wipe all your personal data. Additionally, they also shared that the data-wipe hack can hit the devices in multiple ways. It could be be sent from a website, pushed via NFC or triggered by a QR code.

Interestingly, the Samsung Galaxy Nexus is unaffected because it is a pure Android device, which shows this was Sammy's coding mistake. Supposedly, an update has already been sent out to some SGS3 phones, but that has not been confirmed. Here's a quote with some additional info,

“The USSD code issue in the SGS3 is patched, and has been for some time” TeamAndIRC claims. “Current i747 [AT&T Galaxy S III] and i9300 [European Galaxy S III] firmware are not vulnerable.” An update pushed out to the AT&T Galaxy S III last week apparently patched the loophole, with the i9300 being updated beforehand. We’re still yet to hear from Samsung with an official comment.

Samsung has yet to comment on the find. Above is a video demo of the vulnerability in action.

Thanks to all my tipsters who sent this one in!

Source: SlashGear
 

pc747

Regular Member
Rescue Squad
Joined
Dec 23, 2009
Messages
25,489
Reaction score
6,865
[video=youtube;Q2-0B04HPhs]http://www.youtube.com/watch?feature=player_detailpage&v=Q2-0B04HPhs[/video]​


Some security researchers have found a pretty severe security vulnerability in the Samsung Galaxy S III that also appears on several other Samsung devices including the Galaxy Beam, S Advance, Galaxy Ace, and Galaxy S II. According to their demonstration given at the Ekoparty security conference, a simple USSD can trigger an event that will cause the phone to do a factory reset and wipe all your personal data. Additionally, they also shared that the data-wipe hack can hit the devices in multiple ways. It could be be sent from a website, pushed via NFC or triggered by a QR code.

Interestingly, the Samsung Galaxy Nexus is unaffected because it is a pure Android device, which shows this was Sammy's coding mistake. Supposedly, an update has already been sent out to some SGS3 phones, but that has not been confirmed. Here's a quote with some additional info,



Samsung has yet to comment on the find. Above is a video demo of the vulnerability in action.

Thanks to all my tipsters who sent this one in!

Source: SlashGear

Now if we can get that htc 5 inch nexus this year that would be awesome. We will see if the rumor is just that.
 

syndicate0017

Silver Member
Joined
Feb 2, 2011
Messages
2,007
Reaction score
48
Now if we can get that htc 5 inch nexus this year that would be awesome. We will see if the rumor is just that.

I heard about that. It would be very un-Google-like to make the Nexus line a phablet. Rumored specs look incredible and that's also a warning flag for me. Google doesn't generally put top of the line hardware into a Nexus device.
 

pc747

Regular Member
Rescue Squad
Joined
Dec 23, 2009
Messages
25,489
Reaction score
6,865
I heard about that. It would be very un-Google-like to make the Nexus line a phablet. Rumored specs look incredible and that's also a warning flag for me. Google doesn't generally put top of the line hardware into a Nexus device.

Good point

Sent from my Galaxy Nexus using Tapatalk 2
 
Top