VIDEO: Samsung Galaxy SII vulnerable to complete data loss by clicking one link

At a recent Security Conference in Buenos Aires, Telecommunications researcher Ravi Borgaonkar demonstrated a very simple yet unprecedented vulnerability in some Samsung mobile phones, which, when implemented would result in a complete factory reset of the phone – and loss of all data. EFTM has conducted our own tests and we have the video to prove it.

The vulnerability uses a Telco carrier connection code (USSD) to perform the factory reset, and while it’s something that almost any Android phone could be subject to, normally it would require the user to perform an action, such as clicking a button.

But because of the added layer of software Samsung has built into some of its phones, this USSD code can be “dialled” automatically by the phone, and in the process, the phone is reset.

Here’s how it works.

The attacker, places a very simple line of code into a web page. If you had the address of the page and visited it, your phone would reset. But why would you go to such a page?

Well, imagine you got a direct message on Twitter, or a Facebook message from a friend saying “Wow, this is such an awesome video, check it out http://etcetcetc.etc”. You think “Okay, right, that sounds good” and you click. Hey presto, you’ve visted the site and your phone is turning itself off and wiping all your data.

You didn’t realise your friend’s Twitter or Facebook account was compromised, and it wasn’t really your friend sending that message. We’ve all seen these types of attacks before.

This code could be built into an existing page, so you might be visiting a legitimate looking site only to have the same thing happen.

As Ravi explained in his presentation, this could also occur via tap and go transmission of a web address (NFC) or by QR code as I’ve demonstrated below.


Trevor Long

Trev is a Technology Commentator, Dad, Speaker and Rev Head. He produces and hosts two popular podcasts, EFTM and Two Blokes Talking Tech. He also appears on over 50 radio stations across Australia weekly, and is the resident Tech Expert on Channel 9’s Today Show each day and appears regularly on A Current Affair. Father of three, he is often found down in his Man Cave. Like this post? Buy Trev a drink!

Recent Posts

  • Tech

Review: OPPO Reno 11 F 5G, mid-range smartphone? Could have fooled me

The OPPO Reno 11 F is OPPO’s latest mid-range smartphone and once again it is…

1 day ago
  • Tech

Podcast: Optus and TPG get together for the bush, Qantas Woes & more tech news – Two Blokes Talking Tech #631

Optus and TPG/Vodafone get together after it didn't work out with Telstra and TPG -…

1 day ago
  • Motoring

EXCLUSIVE: Tesla Supercharger roll-out in Australia stopped as job losses at Tesla end new development

Massive news in the world of Electric Vehicles this week with Tesla laying off around…

1 day ago
  • Lifestyle

Podcast: TITANIC – The Best Movies You’ve Never Seen

Jack and Rose, a love story and a tragedy. The iconic Titanic disaster incorporated into…

1 day ago
  • Motoring

Toyota RAV4 Hybrid tops sales charts, but Ford Ranger streets ahead of Toyota HiLux year-to-date

The new-car sales race had quite a few upsets last month, according to official figures…

1 day ago
  • News

AirBNB announce fun new Icon experiences letting you rub shoulders with the stars and more

Finding a fun experience while on a holiday is even easier, with AirBNB announcing Icons,…

2 days ago