Ethical Hackers Demonstrates Exploitable Security Holes of GSM Networks in India

Follow Us

GSM networks has a critical security breach, as White hats demonstrated the the vulnerability of the widely accepted mobile technology at Nullcon, the International Security Conference 2012, held at Goa.

Ethical Hackers Demonstrates Exploitable Security Holes of GSM Networks in India




The white hats or the ethical hacker group Matrix Shell explained and showed the security holes of GSM technology deployed in India they also demonstrated a real hacking scenario using GSM network in real time.

The security experts of the team includes Akib Sayyed, Dipesh Goyel, Bipul Sahu and Nitin Agarwal. They said that anyone can impersonate another GSM mobile number by:

1. using IMSI and making calls

2. Possible threats include

3. identity theft

4. Huge mobile bills or no balance of the victims

5. An attacker can create a grid of such hardware and can empty the phone balance of each
subscriber in just less than 3 hrs.

6.The attacker can give misleading information by using some government employee's identity or even use some law enforcement personsonal's identity.

Chances of catching the attacker

There are very less chances to catch the attackers as he/she can change the imei,imeisv. The attacker can also spoof location by saying that his location is at 70 km away from the GSM base station even though he/she is sitting very near to the same GSM base station.

No encryption on Air Interface
Standard encryption on GSM should be a5/1 but in India the providers mostly use a5/0 I.e. no encryption. In this scenario the attacker can use some open source software to sniff the communication from air and can listen to the calls easily.

The reasons as we suspect why these GSM configuration issues exist in the telecom networks

It takes less time to setup session between mobile phone and BTS if no encryption is used also less load on the systems.

It might be that the operators are forced to do this due to huge air traffic on GSM networks and implementing such techniques will cost them in terms of hardware upgrade to bear the load or some addon hardware in same area to serve the same no. of subscribers.

There are certain security norms decided by governing body of GSM to stop these kind of attacks but many operators ignore them for whatever reasons.

Recent Comments

TheAndroidFreak :

Off Topic : Vivo X200 Pro Battery life.

OnePlus 13 and Xiaomi 15 to Feature Qualcomm Snapdragon 8…

abhijith :

No bsnl now gaining it’s momentum.. according to social media i saw people ported into bsnl feels they are struggling..…

Has BSNL Lost a Golden Opportunity

TheAndroidFreak :

Lava Blaze Duo 5G launched in India 6.67" FHD+ 3D Curved AMOLED 1.58"Secondary AMOLED display Dimensity 7025 64MP + 2MP…

OnePlus 13 and Xiaomi 15 to Feature Qualcomm Snapdragon 8…

Faraz :

They better cover atleast all these cities of those 17 circles, then only announce 5G. Else it will just piss…

BSNL Has Installed 62,201 4G Towers in India: Scindia

Shivraj Roy :

they are launching 5G as if its 2012 or something the way how airtel was lauching 4G in 2012 good…

Vodafone Idea 5G: Where It is Available, Areas Listed

Load More
Subscribe
Notify of
13 Comments
newest
oldest most voted
Inline Feedbacks
View all comments