[HGI-News-de] Vortrag: "All Your Baseband Are Belong To Us" - Ralf-Philipp Weinmann, University of Luxembourg - Donnerstag, 9. Dezember 2010
Newsletter des Horst Görtz Instituts
hgi-news-deutschland at lists.ruhr-uni-bochum.de
Di Dez 7 23:58:04 CET 2010
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Sehr geehrte Damen und Herren,
im Rahmen des HGI-Kolloquiums, organisiert vom Lehrstuhl für Netz-
und Datensicherheit (NDS), wird Ralf-Philipp Weinmann, University of
Luxembourg, am kommenden Donnerstag den 9. Dezember 2010 über
"All Your Baseband Are Belong To Us" referieren.
Der Vortrag beginnt um 11:15 Uhr im ID 03/445.
Abstract:
The primary attack vectors against smartphones have
concentrated on getting code running on the application
processor. The operating systems running on these processors are
getting hardened; in some cases exploitation of mobile devices
can be more difficult than of widespread desktop operating
systems. In contrast, the security of the GSM/3GPP stack running
on the baseband processor has been severely neglected. The
advent of open-source solutions for running GSM base stations
enables another, undervalued attack vector: Malicious base
stations are not considered in the attack model assumed by the
GSMA and the ETSI; similarly vendors of baseband stacks seem to not
have taken malicious input from the network side into account. We
investigate this attack surface and demonstrate the
viability of memory corruptions against two widespread stacks
used by baseband processors of popular smartphones supporting GSM.
Beste Grüße
Dominik Birk
- --
| Dominik Birk Wissenschaftlicher Mitarbeiter |
| Ruhr-Universität Bochum Horst Görtz Institut für IT-Sicherheit |
| Tel.: 0234-32-26740 Gebäude IC 4/052 |
| Mail: dominik.birk at rub.de 44780 Bochum |
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
iEYEARECAAYFAkz+u/wACgkQSMABFNCY+g7MxgCfczJfj8toJyJx5wUUmWlvylBG
FKkAnjOTZg78vivaMiKN03hvm1RnZUEc
=/ovu
-----END PGP SIGNATURE-----
Mehr Informationen über die Mailingliste Hgi-News-Deutschland