The Register® — Biting the hand that feeds IT

Feeds

A single web link will WIPE Samsung Android smartphones

Magic number in URL triggers factory reset

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

An enterprising hacker has demonstrated how a simple web page can reset various Samsung phones back to the state they left the factory - enabling a click, bump or text to take out a victim's mobe entirely.

The devastating flaw lies in Samsung's dialling software, triggered by the tel protocol in a URL. It isn't applicable to all the company's Android handsets, but those that are vulnerable can have their PIN changed or be wiped completely just by visiting a web page or snapping a bad QR code, or even bonking up against the wrong wireless NFC tag.

The tel protocol is generally used with phone numbers to provide clickable "call me" links on websites: tapping on the hyperlink in the handset's web browser opens up the dialling software and calls the number contained in the link. Such calls aren't made until the fandroid presses a "dial" button, so security is maintained - but some numbers don't require "dial" to be pressed, and it's those which are exploited in this attack.

The best example of an executing number - aka an unstructured supplementary service data message - is *#06#: enter that into just about any GSM phone and it will display the IMEI, the device's serial number. But, importantly, it will do that without one pressing the "dial" button.

That's benign, but try entering *2767*3855# on a Samsung Galaxy S3 and you'll be rewarded with an impossible-to-cancel factory reset before you can say shudda-bought-an-iPhone.

Once one has established that any automatically loaded URL can trigger the behaviour, the attack becomes easy to expand: automatically opening iframes, pushed WAP/USSD messages and NFC tags are capable conduits as elegantly demonstrated over the weekend at Ekoparty 2012:

Not all Samsung handsets are affected; they need to interpret numbers submitted from the browser as though they were typed on the pad, and it seems that some operators have tweaked their handsets to prevent that - although probably not deliberately, it's just a side effect of other changes. Using another web browser should not be effective; there are some claims that Google Chrome is immune, but there are an equal number claiming otherwise.

Samsung hasn't confirmed the attack at the time of writing, but it's safe to assume that a fix will be forthcoming pretty quickly - there's no big technical barrier and Samsung will want to be seen responding rapidly.

The XDA Developers forum has some non-destructive examples should one want to try the hack, but the overall risk should be quite small as the attacker gains nothing from destroying all the data on a phone.

Despite that it might be worth steering clear of unknown URLs, NFC, QR Codes for a while, particularly if they come from smug friends touting new iPhones who might see more humour than most in trashing a Samsung handset or two. ®

Agentless Backup is Not a Myth

Catch me if you can

IPhone users have to resort to remotely aggravating Samsung Android users. They sure as hell can't find out where we live any more.

31
2

Re: Magic

It MUST work on iPhones- Samsungs are a direct copy, aren't they?

22
1

Re: "fandroid"

...unless the journalist uses perjoratives to describe everyone

21
1

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence