Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Feds, Industry, Battle the Biggest Bug
Kevin Poulsen, SecurityFocus 2002-06-12

A security hole in implementations of Abstract Syntax Notation One may threaten some of America's most crucial networks. Relax, the President's been briefed.

Comments Mode:
Feds, Industry, Battle the Biggest Bug 2002-06-12
Anonymous (1 replies)
Feds, Industry, Battle the Biggest Bug 2002-06-19
Anonymous
Use an SS7 gateway such as the Nortel CSG. It runs on HP-UX, can be managed by SNMP (oh the irony!) and is very rarely secured in any way shape or form.

Incidentally, mobile billing information is stored in ASN.1 format, and usually transferred via FTP. It would be interesting to see if it's possible to crash Charging Gateways on GPRS by screwing around with ASN.1, although the ability to do so would vary from network to network.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/474/13096#13096
Feds, Industry, Battle the Biggest Bug 2002-06-19
MKobar (at) Lymeware (dot) com [email concealed]







 

Privacy Statement
Copyright 2009, SecurityFocus