VIDEO: Samsung Galaxy SII vulnerable to complete data loss by clicking one link

At a recent Security Conference in Buenos Aires, Telecommunications researcher Ravi Borgaonkar demonstrated a very simple yet unprecedented vulnerability in some Samsung mobile phones, which, when implemented would result in a complete factory reset of the phone – and loss of all data. EFTM has conducted our own tests and we have the video to prove it.

The vulnerability uses a Telco carrier connection code (USSD) to perform the factory reset, and while it’s something that almost any Android phone could be subject to, normally it would require the user to perform an action, such as clicking a button.

But because of the added layer of software Samsung has built into some of its phones, this USSD code can be “dialled” automatically by the phone, and in the process, the phone is reset.

Here’s how it works.

The attacker, places a very simple line of code into a web page. If you had the address of the page and visited it, your phone would reset. But why would you go to such a page?

Well, imagine you got a direct message on Twitter, or a Facebook message from a friend saying “Wow, this is such an awesome video, check it out http://etcetcetc.etc”. You think “Okay, right, that sounds good” and you click. Hey presto, you’ve visted the site and your phone is turning itself off and wiping all your data.

You didn’t realise your friend’s Twitter or Facebook account was compromised, and it wasn’t really your friend sending that message. We’ve all seen these types of attacks before.

This code could be built into an existing page, so you might be visiting a legitimate looking site only to have the same thing happen.

As Ravi explained in his presentation, this could also occur via tap and go transmission of a web address (NFC) or by QR code as I’ve demonstrated below.


Recent Posts

  • Podcasts

The Best Movies You’ve Never seen podcast: This week – Anaconda

A giant Anaconda stalking the Amazon, while a film crew set out to make an…

1 day ago
  • Tech

Razer announces its newest ultra-low latency earbuds, the Hammerhead V3 HyperSpeed

Razer has announced its new gaming earbuds, the Hammerhead V3 HyperSpeed, designed for high-end audio…

2 days ago
  • Motoring

Nearly half of all KIAs sold last weekend were electric – EV Sales boom!

We all know that the month of March was a record for Electric Vehicle sales…

3 days ago
  • Lifestyle

Dyson’s HushJet™ Mini Cool fan is a bit late for the Aussie summer – but it’s cool

Dyson has announced yet another product you probably never expected from them - the HushJet™…

3 days ago
  • Tech

The Two Blokes Talking Tech podcast – Episode #727 – Apple’s iPhone Fold – finally?

Apple's iPhone fold - Trev's now confident it's coming, Stephen has news on When -…

3 days ago
  • Lifestyle

Shaken, not stirred – PlayStation’s iconic new controller coming soon

With the imminent release of 007 First Light for PS5, a high-action game where players…

4 days ago