Scaling up baseband attacks:
More (unexpected) attack surface
Ralf-Philipp Weinmann SnT, University of Luxembourg <ralf-philipp.weinmann@uni.lu> Black Hat USA 2012 2012-07-25 36.117038, -115.174562
Scaling up baseband attacks: More (unexpected) attack surface - - PowerPoint PPT Presentation
Scaling up baseband attacks: More (unexpected) attack surface Black Hat USA 2012 2012-07-25 36.117038, -115.174562 Ralf-Philipp Weinmann SnT, University of Luxembourg <ralf-philipp.weinmann@uni.lu> Security issues with SUPL
Ralf-Philipp Weinmann SnT, University of Luxembourg <ralf-philipp.weinmann@uni.lu> Black Hat USA 2012 2012-07-25 36.117038, -115.174562
Ralf-Philipp Weinmann SnT, University of Luxembourg <ralf-philipp.weinmann@uni.lu> Black Hat USA 2012 2012-07-25 36.117038, -115.174562
SUPLSTART (setID is MSISDN / IMSI!) SUPLRESPONSE (chooses pos. method) SUPLPOSINIT (cell info. and pos. estimate) SUPLPOS (RRLP embedded!) SUPLEND
SUPLSTART (setID is MSISDN / IMSI!) SUPLRESPONSE (chooses pos. method) SUPLPOSINIT (cell info. and pos. estimate) SUPLPOS (RRLP embedded!) SUPLEND
h-slp.mncxxx.mccyyy.pub.3gppnetwork.org
h-slp.mnc410.mcc310.pub.3gppnetwork.org
supl.google.com
from http://forums.crackberry.com/blackberry-bold-9000-f83/annoying-certificate-expired- popup-270587/
Application Processor Digital Baseband Processor RAM Application Processor Digital Baseband Processor RAM RAM Serial communication
Shared memory architecture Baseband as modem
RAM Application Processor Digital Baseband Processor RAM RAM Serial communication
Shared memory architecture Baseband as modem
Application processor core Digital baseband processor core
RAM Application Processor Digital Baseband Processor RAM RAM Serial communication
Shared memory architecture Baseband as modem
Application processor core Digital baseband processor core GPS/GNSS GPS/GNSS
Baseband App processor gpsOne SUPL server
Parses SUPL messages Builds connections to SUPL server
Frank Van Diggelen: A-GPS: Assisted GPS, GNSS, and SBAS, Artech House Publishers, ISBN 1596933747, 2009 Charlie Miller, Dion Blazakis, Dino Dai Zovi, Stefan Esser, Vincenzo Iozzo, Ralf-Philipp Weinmann: iOS Hacker’s Handbook, Wiley Publishing, ISBN 1118204123, 2012