<?xml version="1.0"?>
<!-- name="generator" content="blosxom/2.0" -->
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN" "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">
  <channel>
    <title>Collin R. Mulliner   </title>
    <link>http://www.mulliner.org/blog/blosxom.cgi</link>
    <description>...stuff I do and things I like... </description>
    <language>en</language>

  <item>
 <title>Countering SMS/mTAN Trojans</title>
 <pubDate>Wed, 08 May 2013 20:58:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/05/08#smsotppaper</link>
 <description>
Together with my former colleagues Ravi, Patrick, Jean-Pierre from
TU Berlin / &lt;a href=&quot;http://sec.t-labs.tu-berlin.de&quot;&gt;SecT&lt;/a&gt; I have
been working on an enhancement for mobile phones in order
to protect SMS messages especially &lt;a href=&quot;http://en.wikipedia.org/wiki/Transaction_authentication_number#Mobile_TAN_.28mTAN.29&quot;&gt;mTANs&lt;/a&gt; against trojans.
&lt;br&gt;&lt;br&gt;
We investigated several ways to improve mTAN security and finally
came to the conclusion that we just need to change the SMS routing
on the mobile phone itself.&lt;br&gt;&lt;br&gt; &lt;b&gt;Basically we remove SMS messages
that contain mTANs from the normal delivery queue and only deliver them
to a special application. This way no other program (including trojans) 
can access the SMS message.&lt;/b&gt;
&lt;br&gt;&lt;br&gt;
We implemented and tested our idea on Android. The paper &lt;a href=&quot;https://www.mulliner.org/collin/academic/publications/mulliner_dimva2013.pdf&quot;&gt;SMS-based One-Time Passwords: Attacks and Defense&lt;/a&gt; will be presented at &lt;a href=&quot;http://dimva.sec.t-labs.tu-berlin.de/&quot;&gt;DIMVA 2013&lt;/a&gt; in July in Berlin, Germany.
&lt;br&gt;&lt;br&gt;
A demo video of the prototype is shown below:&lt;br&gt;
&lt;iframe width=&quot;560&quot; height=&quot;315&quot; src=&quot;http://www.youtube.com/embed/SF2HoK0D3_4&quot; frameborder=&quot;0&quot; allowfullscreen&gt;&lt;/iframe&gt;</description>
 </item>
  <item>
 <title>Mobile Security News Update May 2013</title>
 <pubDate>Tue, 07 May 2013 19:11:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/05/07#mobile_security_update_may2013</link>
 <description>
Conferences
&lt;ul&gt;
&lt;a href=&quot;http://www.nosuchcon.org/&quot;&gt;NoSuchCon&lt;/a&gt; finally released their agenda.They have an interesting lineup but no mobile talk.&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.sourceconference.com/dublin/speakers_2013.html&quot;&gt;SourceDublin&lt;/a&gt; Android application reverse engineering &amp; defensesi by Patrick Schulz &amp; Felix Matenaar.&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.summercon.org/schedule.html&quot;&gt;SummerCon&lt;/a&gt; has posted it's schedule. I'll present some work I've done on Dynamic Dalvik Instrumentation.&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.recon.cx/&quot;&gt;REcon&lt;/a&gt; has stared to post talks. Reversing HLR, HSS and SPR: rooting the heart of the Network and Mobile cores from Huawei to Ericsson by Philippe Langlois.  Reversing and Auditing Android's Proprietary Bits by Joshua J. Drake. 
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://shakacon.org/&quot;&gt;Shakacon&lt;/a&gt; Deviant Ollam - Android Phones Can Do That?!? Custom Tweaking for Power Security Users. Max Sobell - Android 4.0: Ice Cream &quot;Sudo Make Me a&quot; Sandwich. Andreas Kutz - Pentesting iOS Apps - Runtime Analysis &amp; Manipulation. 
&lt;/ul&gt;
&lt;br&gt;
Some interesting upcoming talks! I guess everybody else an their moms are waiting to hear back from the Black Hat USA CfP.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://syscan.org/index.php/sg/&quot;&gt;SyScan'13&lt;/a&gt; review
&lt;ul&gt;
SyScan was a totally awesome event. Really good talks and lots of them.
My favorite talk was: Bochspwn: Exploiting Kernel Race Conditions Found via Memory Access Patterns by Mateusz Jurczyk and Gynvael Coldwind. 
&lt;/ul&gt;
&lt;br&gt;
&lt;br&gt;
News
&lt;ul&gt;
&lt;a href=&quot;http://www.aclu.org/blog/technology-and-liberty/aclu-files-ftc-complaint-over-android-smartphone-security&quot;&gt;ACLU Files FTC Complaint Over Android Smartphone Security&lt;/a&gt; this story is a little older already but insecurity of old Android devices is a pressing issue.
&lt;/ul&gt;
&lt;br&gt;&lt;br&gt;
Links
&lt;ul&gt;
&lt;a href=&quot;http://vrt-blog.snort.org/2013/04/changing-imei-provider-model-and-phone.html&quot;&gt;Changing the IMEI, Provider, Model, and Phone Number in the Android emulator&lt;/a&gt;&lt;br&gt;&lt;br&gt;
&lt;A href=&quot;https://blog.fortinet.com/Finding-Similarities-and-Differences-at-DEX-Level/&quot;&gt;Finding Similarities and Differences at DEX Level&lt;/a&gt;
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://tinytocs.org/vol2/papers/tinytocs2-lange.pdf&quot;&gt;Securing Two-factor Authentication for Smartphones in a Usable Way by Adding a Connected Token&lt;/a&gt;
Two-factor authentication for smartphones is easy to break and can be secured by using a smart watch which acts as a connected token.
Matthias Lange (Technische Universität Berlin&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://tinytocs.org/vol2/papers/tinytocs2-tang.pdf&quot;&gt;Android Apps: What are they doing with your precious Internet?&lt;/a&gt;
The majority of Android apps are not malicious, but use internet access in ways that are not compatible with the user's interests.
Amy Tang (University of California Berkeley), Ashwin Rao (INRIA), Justine Sherry (University of California Berkeley), Dave Choffnes (University of Washington)
&lt;/ul&gt;
</description>
 </item>
  <item>
 <title>Mobile Security News Update April 2013</title>
 <pubDate>Thu, 11 Apr 2013 23:50:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/04/11#mobile_security_update_april2013</link>
 <description>
Conferences:
&lt;ul&gt;
&lt;a href=&quot;http://www.hackcon.org/&quot;&gt;HackCon&lt;/a&gt; No.8 10-11 April in Oslo Norway. First time I hear about this conference. Mobile talks: Leveraging Mobile Devices on Penetration Tests and Want to control smart phones?&lt;br&gt;&lt;br&gt;
&lt;/ul&gt;

Call for Papers:
&lt;ul&gt;
&lt;A href=&quot;http://www.wisa.or.kr/&quot;&gt;The 14th International Workshop on Information Security Applications (WISA2013)&lt;/a&gt; an academic workshop but they seek more practical papers comparable with Usenix WOOT.&lt;br&gt;&lt;br&gt;
&lt;/ul&gt;

News:
&lt;ul&gt;
&lt;a href=&quot;http://blog.azimuthsecurity.com/2013/04/unlocking-motorola-bootloader.html&quot;&gt;Unlocking the Motorola Bootloader&lt;/a&gt; (Android phones) by Dan Rosenberg. A real nice read. Most interesting part is that
the unlock is via attacking a vulnerability in code running in TrustZone.
&lt;br&gt;&lt;br&gt;
&lt;/ul&gt;
&lt;br&gt;&lt;br&gt;

I have been super busy with work so I might missed a few things here and there. Right now I'm waiting
to here back from SummerCon and Black Hat USA about talks I submitted. I'm still thinking about submitting to ReCON ;)</description>
 </item>
  <item>
 <title>Mobile Security News Update March 2013 part 2</title>
 <pubDate>Thu, 14 Mar 2013 22:40:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/03/14#mobile_security_update_March_13_2</link>
 <description>
CanSecWest was pretty good this year. My favorite talks were (no order):
Desktop Insecurity - Ilja van Sprundel &amp; Shane &quot;K2&quot; Macaulay, Smart TV Security - SeungJin Lee, Godel's Gourd - Fuzzing for Logic Issues - Mike &quot;dd&quot; Eddington, and Reflecting on Reflection - Exploiting Reflection Vulnerabilities in
Managed Languages - James Forshaw. I can't wait to get the slides.
&lt;br&gt;&lt;br&gt;

Call for Papers:
&lt;ul&gt;
&lt;A href=&quot;https://www.usenix.org/conference/woot13/call-for-papers&quot;&gt;Workshop on Offensive Technologies (WOOT)&lt;/a&gt; August, Washington D.C., academic but targeting people who would normally speak at Black Hat/CanSecWest/etc.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.summercon.org/cfp.html&quot;&gt;SummerCon&lt;/a&gt; in June, New York City
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://masshackers.pbworks.com/w/page/61663884/BeaCon&quot;&gt;BeaCon&lt;/a&gt; local mini con in Boston
&lt;/ul&gt;
&lt;br&gt;

I totally missed Black Hat Europe, it had some interesting talks: The M2M Risk Assessment Guide, A Cyber Fast Track Project - Don A. Bailey, Practical Attacks Against MDM Solutions - Daniel Brodie + Michael Shaulov, Off Grid Communications With Android- Meshing The Mobile World - Josh Thomas + Jeff Robble, Next Generation Mobile Rootkits - Thomas Roth. &lt;br&gt;
&lt;br&gt;

An interesting looking paper from TROOPERS13 &lt;a href=&quot;https://media.blackhat.com/ad-12/Niemietz/bh-ad-12-androidmarcus_niemietz-WP.pdf&quot;&gt;UI Redressing Attacks on Android Devices&lt;/a&gt; (apparently it was released at Black Hat Abu Dhabi last year).
&lt;br&gt;&lt;br&gt;
News
&lt;ul&gt;
&lt;a href=&quot;http://www.theverge.com/2013/3/13/4099450/andy-rubin-steps-down-as-head-of-android&quot;&gt;Andy Rubin steps down as head of Android&lt;/a&gt; ...interesting.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://permalink.gmane.org/gmane.comp.security.full-disclosure/88743&quot;&gt;A few android security issues&lt;/a&gt; ... worth reading!
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;https://www.facebook.com/notes/facebook-engineering/under-the-hood-dalvik-patch-for-facebook-for-android/10151345597798920&quot;&gt;Under the Hood: Dalvik patch for Facebook for Android&lt;/a&gt;&lt;br&gt;&lt;br&gt;
&lt;/ul&gt;

Fun find by my former co-worker Matthias: &lt;a href=&quot;https://twitter.com/budvisor/status/310278100598534144&quot;&gt;Lost connection to Battery&lt;/a&gt; ... WTF!?!</description>
 </item>
  <item>
 <title>Mobile Security Update March 2013</title>
 <pubDate>Mon, 04 Mar 2013 17:14:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/03/04#mobile_security_update_March2013</link>
 <description>
Review RSA
&lt;ul&gt;
Last week I attend the RSA Conference for the first timer ever. I always
had the impression that it is not worth going but this year I went anyway.
The plan was to just hang around at the various side events that take place
during RSAC. Meeting with people etc. That part is totally worth it
if you can spent the day doing actual work. I ended up going to the conference
to speak on the &lt;a href=&quot;https://ae.rsaconference.com/US13/connect/sessionDetail.ww?SESSION_ID=1982&quot;&gt;Mobile Security Battle Royale&lt;/a&gt; panel (as a replacement for Jon Oberheide). So I got a conference pass and could checkout the actual
conference and expo. The expo was pretty standard if you are used to attend
events like CeBIT or maybe CES. Just smaller and security companies only. 
I didn't have the chance to attend other talks besides &lt;i&gt;Big Brother's Greek Tragedy State-Deployed Malware &amp; Trojans&lt;/i&gt; so I can't really make my mind up 
if it is worth the money or not.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.scmagazine.com/rsa-2013-ios-safer-than-android-due-to-open-app-model-patching-delays/article/282697/&quot;&gt;SC Magazine&lt;/a&gt; wrote an article
about the panel I spoke on. Here are some comments: &lt;i&gt;Android certainly does
support remote updates. But the problem really is that manufacturers and
mobile carriers stop supporting devices after 12-18 month.&lt;/i&gt;
&lt;/ul&gt;
&lt;br&gt;

Conferences
&lt;ul&gt;
&lt;a href=&quot;http://www.immunityinc.com/infiltrate/speakers.html&quot;&gt;Infiltrate&lt;/a&gt; posted a few more talks. The one I'm really interested in is: Josh &quot;m0nk&quot; Thomas - 
NAND-Xplore -&gt; Bad Blocks = Well Hidden.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;https://www.troopers.de/agenda13/index.html&quot;&gt;Troopers&lt;/a&gt; in Heidelberg Germany (March). They have a few interesting talks: UI Redressing Attacks on Android Devices by Marcus Niemietz, Malicious Pixels: QR-Codes as attack vectors by Peter Kieseberg, Corporate Espionage via Mobile Compromise: A Technical Deep Dive by David Weinstein and a few other non mobile talks that look really interesting.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://conference.hitb.org/hitbsecconf2013ams/&quot;&gt;Hack in the Box Amsterdam&lt;/a&gt; LTE Pwnage: Hacking HLR/HSS and MME Core Network Elements, SMS To Meterpreter: Fuzzing USB Internet Modems. I really need to go to HITB some day.
&lt;/ul&gt;
&lt;br&gt;

New Conferences
&lt;ul&gt;
&lt;a href=&quot;http://www.nosuchcon.org/&quot;&gt;NSC - NoSuchCon&lt;/a&gt; is a new conference
held in May in Paris, France. The organizers seek strong (only) technical 
content.
&lt;/ul&gt;
&lt;br&gt;

News
&lt;ul&gt;
&lt;a href=&quot;http://www.nytimes.com/2013/02/23/business/htc-settles-ftc-charges-over-security-flaws-in-devices.html&quot;&gt;HTC Settles Privacy Case Over Flaws in Phones&lt;/a&gt; Interesting read, quote: &lt;i&gt;The Federal Trade Commission charged HTC with customizing the software on its Android- and Windows-based phones in ways that let third-party applications install software that could steal personal information, surreptitiously send text messages or enable the device's microphone to record the user's phone calls.&lt;/i&gt;
&lt;/ul&gt;
&lt;br&gt;
Personal note:
&lt;ul&gt;
Wiley announced our book &lt;a href=&quot;http://www.wiley.com/WileyCDA/WileyTitle/productCd-111860864X.html&quot;&gt;Android Hacker's Handbook&lt;/a&gt;
&lt;/ul&gt;</description>
 </item>
  <item>
 <title>Mobile Security News Update February 2013</title>
 <pubDate>Thu, 31 Jan 2013 17:46:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/01/31#mobile_security_update_Feb2013</link>
 <description>
Conferences:
&lt;ul&gt;
&lt;a href=&quot;http://cansecwest.com/&quot;&gt;CanSecWest&lt;/a&gt; coming up in March has started posting talks: Doug DePerry @dugdep &amp; Tom Ritter @TomRittervg - CDMA Femptocell Traffic Interception and Remote Mobile Phone Cloning, Rahul Sasi @fb1h2s - SMS to Meterpreter, Fuzzing USB Modems, Stephan Esser @i0n1c will be talking about iOS, Joshua J. Drake @jduck1337i - Tackling the Android Challenge. In addition to mobile security there is another super interesting talk about embedded system security: @beist will be talking about Samsung SmartTVs.&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://syscan.org/index.php/sg/speakerlist&quot;&gt;SyScan&lt;/a&gt; Singapore is coming up in April and also posted talks. There are not too many mobile talks but all talks sound pretty good. Stefan Esser ( @i0n1c ) - Mountain Lion / iOS Vulnerability Garage Sale. I will also show some stuff I've been working on in the past month during a lightning talk, all brand new!
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.sourceconference.com/boston/speakers_2013.html&quot;&gt;SourceBoston&lt;/a&gt; also in April: Protecting sensitive information on iOS devices David Schuetz, Attacking NFC Mobile Wallets: Where Trust Breaks Down Max Sobell. 
&lt;br&gt;&lt;bR&gt;
&lt;a href=&quot;http://infiltratecon.com/speakers.html&quot;&gt;Infiltrate&lt;/a&gt; Matias Soler - 
The Chameleon: A cellphone-based USB impersonator, Stephen Lawler &amp; Stephen Ridley - Advanced Exploitation of Mobile/Embedded Devices: The ARM Microprocessor.
&lt;/ul&gt;
&lt;br&gt;
News:
&lt;ul&gt;
&lt;a href=&quot;http://www.osnews.com/story/26734/The_end_of_the_line_for_Symbian&quot;&gt;The end of the line for Symbian&lt;/a&gt; is kinda sad. Although I wasn't a big Symbian fan, Symbian was still pretty cool as a mobile OS. I had fun hacking it.
&lt;br&gt;&lt;br&gt;
&lt;a href=&quot;http://www.infoworld.com/d/security/android-botnet-abuses-peoples-phones-sms-spam-209415&quot;&gt;Android botnet abuses people's phones for SMS spam&lt;/a&gt; this is just too funny. I kinda hat that on my slides for a couple of years already.
&lt;/ul&gt;
&lt;br&gt;&lt;br&gt;
Personal notes: I'm going to be in San Francisco during RSA, ping me if you want to chat. I'm also going to be at CanSecWest, just attending this year. Further I'm going to SyScan. I also plan to be around SourceBoston but unfortunately not attending (ticket prices vs. university etc, I'm not complaining). 
</description>
 </item>
  <item>
 <title>Mobile Security News Update January 2013</title>
 <pubDate>Fri, 04 Jan 2013 15:45:00 GMT</pubDate>
 <link>http://www.mulliner.org/blog/blosxom.cgi/2013/01/04#mobile_security_update_Jan_2013</link>
 <description>
Conferences:
&lt;ul&gt;
&lt;a href=&quot;http://www.shmoocon.org/schedule&quot;&gt;Shmoocon 2013&lt;/a&gt; has posted their schedule. Mobile talks are: Armor for your Android Apps by Roman Faynberg, Protecting Sensitive Information on iOS Devices by David Schuetz, Apple iOS Certificate Tomfoolery by Tim Medin.
&lt;/ul&gt;

All other upcoming conferences (SyScan, CanSecWest, SourceBoston, Infiltrate) haven't posted any talks yet.
&lt;br&gt;&lt;br&gt;

My 29c3 conference review. The new location CCH in Hamburg is really nice. There is a lot of space and the space was used very well. Due to the space the conference was much more relaxed. This also counted for the talks. Most of the time everybody had a place to sit. One small downside of this years conference the schedule, sometimes three tech talks were running in parallel in different rooms. But all together I don't think anybody could complain about 29c3. For me personally one of the best congresses I ever attended. The recordings of the talks can be downloaded from &lt;a href=&quot;http://events.ccc.de/congress/2012/wiki/Documentation#Official_mirrors&quot;&gt;here&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;
Happy New Year.</description>
 </item>
  </channel>
</rss>