Mobile networks - Do they have a text message spam filter?
Someone is using my phone number when making online enquires. They've been doing it for about 2 months now. So I'm getting unsolicited texts and calls.
I've decided to attempt to contact the person to persuade them to stop. In my country, I predict I'll need to send 100 text messages to find them...if they respond to the text. It feels like they're changing a digit of their own phone number.
The content of the text will be exactly the same, it'll be using a newly registered sim, and I'll be using a GSM module connected to my computer.
If this were emails, I imagine Google and Microsoft would probably mark the emails as spam. And so I'm curious if mobile networks would treat text messages in the same manner?
I ask in this sub because I imagine someone in this community has played with mass text messages and I can't think of a better sub.
๐ฃreddit_user33
Mobile networks do have some spam protections, depending on the service provider. The problem is that many of these networks allow phone number spoofing, meaning you can call from a number you donโt own. This bypasses a lot of the anti-spam protections in place. Itโs a huge problem world wide and thereโs not much anyone can do about it because networks donโt want to spend the money to fix it, and government agencies wonโt force them to fix it. (Often because these government agencies get lobbied by the networks)
Thereโs really just not much you can do. Even if you call the original number, thereโs probably not a person on the other side, just a computer.
๐คNullOfUndefined
๐@malwr
Someone is using my phone number when making online enquires. They've been doing it for about 2 months now. So I'm getting unsolicited texts and calls.
I've decided to attempt to contact the person to persuade them to stop. In my country, I predict I'll need to send 100 text messages to find them...if they respond to the text. It feels like they're changing a digit of their own phone number.
The content of the text will be exactly the same, it'll be using a newly registered sim, and I'll be using a GSM module connected to my computer.
If this were emails, I imagine Google and Microsoft would probably mark the emails as spam. And so I'm curious if mobile networks would treat text messages in the same manner?
I ask in this sub because I imagine someone in this community has played with mass text messages and I can't think of a better sub.
๐ฃreddit_user33
Mobile networks do have some spam protections, depending on the service provider. The problem is that many of these networks allow phone number spoofing, meaning you can call from a number you donโt own. This bypasses a lot of the anti-spam protections in place. Itโs a huge problem world wide and thereโs not much anyone can do about it because networks donโt want to spend the money to fix it, and government agencies wonโt force them to fix it. (Often because these government agencies get lobbied by the networks)
Thereโs really just not much you can do. Even if you call the original number, thereโs probably not a person on the other side, just a computer.
๐คNullOfUndefined
๐@malwr
Reddit
Mobile networks - Do they have a text message spam filter? : r/hacking
2.7M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploitsโฆ
MASSIVE Slickwraps Data breach!
https://preview.redd.it/glle8vcgpbi41.png?width=1892&format=png&auto=webp&s=f51a26272b2fb64b01fe2b25b22bef1b1a95ae4e
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
https://www.droid-life.com/2020/02/21/slickwraps-appears-to-have-suffered-a-massive-data-breach/
https://www.androidcentral.com/slickwraps-website-full-vulnerabilities-and-they-dont-seem-care
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
๐ฃprojeto56
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb(Includes PDF of the pentest report)
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
๐คprojeto56
๐@malwr
https://preview.redd.it/glle8vcgpbi41.png?width=1892&format=png&auto=webp&s=f51a26272b2fb64b01fe2b25b22bef1b1a95ae4e
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
https://www.droid-life.com/2020/02/21/slickwraps-appears-to-have-suffered-a-massive-data-breach/
https://www.androidcentral.com/slickwraps-website-full-vulnerabilities-and-they-dont-seem-care
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
๐ฃprojeto56
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb(Includes PDF of the pentest report)
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
๐คprojeto56
๐@malwr
A new malware sample format called UMSE (Universal Malware Sample Encryption) which improves user confidentiality and reverse engineering process is now available here: https://github.com/dalvarezperez/umse/
โน๏ธ Sent from one of our subscribers
๐@malwr
โน๏ธ Sent from one of our subscribers
๐@malwr
GitHub
dalvarezperez/umse
Universal Malware Sample Encryption. Contribute to dalvarezperez/umse development by creating an account on GitHub.
Chinese Bitcoin investor loses $45 million to a SIM-Swapping attack.
๐ฃnilehighclub
SIM Swapping is stupid easy too, thatโs why this is a rampant issue - all it takes is someone inside the carrier (and not even a high ranking person)
๐คmc2memes
These sort of attacks are just stunning.
I still have not really worked out how they manage to steal a persons phone number.
I guess they gain a lot of information about a person so they can answer any question an ISP may ask. Or is it simply the fact that ISP's have basically no security built into their processes?
๐คVestigialHead
You keep 45 million on something protected by an sms on a phone.... youโre an idiot
๐คEAP007
๐@malwr
๐ฃnilehighclub
SIM Swapping is stupid easy too, thatโs why this is a rampant issue - all it takes is someone inside the carrier (and not even a high ranking person)
๐คmc2memes
These sort of attacks are just stunning.
I still have not really worked out how they manage to steal a persons phone number.
I guess they gain a lot of information about a person so they can answer any question an ISP may ask. Or is it simply the fact that ISP's have basically no security built into their processes?
๐คVestigialHead
You keep 45 million on something protected by an sms on a phone.... youโre an idiot
๐คEAP007
๐@malwr
X (formerly Twitter)
X
Cacti v1.2.8 authenticated Remote Code Execution (CVE-2020-8813) - Shells.Systems
๐ฃcyberg0100
๐@malwr
๐ฃcyberg0100
๐@malwr
Shells.Systems
Cacti v1.2.8 authenticated Remote Code Execution (CVE-2020-8813) - Shells.Systems
Estimated Reading Time: 8 minutesSummary about Cacti Cacti is a complete network graphing solution designed to harness the power of RRDToolโs data storage and graphing functionality, Cacti provides a fast poller, advanced graph templating, multiple dataโฆ
Binwalk
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography).
But what is exactly Binwalk? How does it show me more files inside a file?
How does it work?
๐ฃblue8ird
It looks for file format signatures and for file headers/footers of different formats.
Btw a more common use case than steganography is extracting files from a firmware image.
๐คTompazi
๐@malwr
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography).
But what is exactly Binwalk? How does it show me more files inside a file?
How does it work?
๐ฃblue8ird
It looks for file format signatures and for file headers/footers of different formats.
Btw a more common use case than steganography is extracting files from a firmware image.
๐คTompazi
๐@malwr
reddit
Binwalk
I've figured out how and when exactly to use Binwalk on files (JPG files for example, steganography). But what is exactly Binwalk? How does it...
Writing a #GHIDRA Loader: STM32 Edition
https://wrongbaud.github.io/writing-a-ghidra-loader/
๐@malwr
https://wrongbaud.github.io/writing-a-ghidra-loader/
๐@malwr
Announcing GA of O365 ATP Campaign Views and Compromised User Detection and Response
๐ฃTeamsMe
๐@malwr
๐ฃTeamsMe
๐@malwr
TECHCOMMUNITY.MICROSOFT.COM
Announcing GA of O365 ATP Campaign Views and Compromised User Detection and Response
Office 365 Advanced Threat Protection just got even better. Together, the two features we're announcing the GA of today: Campaign Views and Advanced..
I just open-sourced sweetie data, a repo of multiple honeypot logs.
๐ฃ0xsha
Nice thanks for sharing. I've shut down the majority of my honeypots and just use threat feeds and other intelligence streams.
๐คintoxicatednoob
๐@malwr
๐ฃ0xsha
Nice thanks for sharing. I've shut down the majority of my honeypots and just use threat feeds and other intelligence streams.
๐คintoxicatednoob
๐@malwr
GitHub
GitHub - 0xsha/sweetie-data: This repo contains logstash of various honeypots
This repo contains logstash of various honeypots. Contribute to 0xsha/sweetie-data development by creating an account on GitHub.
[PDF] OSS Supply Chain Security by the Linux Foundation
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr