GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > News Section > Service Products News & Updates


Service Products News & Updates Service Products and Tools New and Updates

Reply
 
LinkBack Thread Tools Display Modes
Old 12-07-2008, 17:33   #1 (permalink)
No Life Poster
 
Join Date: Nov 2002
Location: Russia
Age: 42
Posts: 1,317
Member: 17711
Status: Offline
Thanks Meter: 1,858
Exclamation --==> How they kill smart-cards <==--


Before reading this article, it is better to read a story on forums about what happened to those running latest (1.08 and 1.09) BB5 King software for PKeys.

The mechanism of killing a smart-card
Before an applet is written to a card, a secured session is established. This is done using two APDU commands - INITIALIZE UPDATE and EXTERNAL AUTH. During data exchange each side (card and server or an application) proove that they know card access keys. Session keys are also generated.

But if INITIALIZE UPDATE is not followed by a correct EXTERNAL AUTH, a card increases it's security counter. When security counter reaches some value, card stops accepting INITIALIZE UPDATE command at all. Card is alive, but noone can now update or delete any applet from it. Even the one knowing card access keys (the author).

Security counter exists outside of time. It does not clear itself in a minute, two, month, year. Is is cleared only upon successful secured session has been established (e.g. card update was successfully initiated).

The process of "murder"
JAF cards were not destroyed at every user, that executed some application. This allows to suggest the following. Destructive software lists connected card readers in system and kills the first card it finds. Nothing is done further.

Now about the most important. If the first card happened to be PKey card, you can see the result immediately. I will stop updating. But if that was a, say, SETool card, there will be no result at all because no SETool update server exist.

Diagnostics
Is it easy to recognize a "killed" card even if you don't know it's access keys. Just issue INITIALIZE UPDATE command and see the answer. If the card answer would be an error - it is damaged. Damaged card works ok, but it will be impossible to update it. It is easy also to write diagnostics software to detect damaged cards. But just keep in mind, that each such check increases security counter.

Financial considerations
You need to think about the fact, that killing cards is profitable for dishonest people. If card stopped updating, user is ought to keep using outdated software or buy a new card.

It is obvious, that now we will see lots of "free" software with card destructor integrated.

DO NOT DOWNLOAD AND EXECUTE UNKNOWN SOFWARE!!!

Last edited by FractalizeR; 12-07-2008 at 17:39.
  Reply With Quote
The Following 345 Users Say Thank You to FractalizeR For This Useful Post:
Show/Hide list of the thanked
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: https://forum.gsmhosting.com/vbb/f475/how-they-kill-smart-cards-645081/
Posted By For Type Date
Untitled document This thread Refback 07-01-2013 16:03
Untitled document This thread Refback 05-15-2013 05:49
--==> How they kill smart-cards <==-- - GSM-Forum This thread Refback 06-20-2012 03:05
forum.z3x-team: FAIL: It is not a Z3x box-team card''!! This thread Refback 03-09-2012 06:02
forum.z3x-team: This thread Refback 03-04-2012 20:19
forum.z3x-team: !!!!! This thread Refback 01-04-2012 12:47
forum.z3x-team: This thread Refback 11-12-2011 11:20
forum.z3x-team: FAIL: It is not a Z3x box-team card''!! This thread Refback 11-08-2011 18:54
Unlock Free 1202 với box JAF - Page 2 - VIETFONES FORUM This thread Refback 09-02-2011 05:52
SETool3 SmartCard emulator v 0.915034 proget - Forum-IndoFlasher Post #0 Refback 06-06-2011 23:16
Untitled document This thread Refback 09-19-2010 19:15
GSM-Hosting This thread Refback 09-10-2010 22:14
Card keys is damaged, Your account is suspended etc. - VIP GSM Support System This thread Refback 06-28-2010 13:35
Card keys is damaged, Your account is suspended etc. - Forum SCPGSM | Spare Part HP | Flasher Box HP This thread Refback 06-01-2010 15:59
Unlock Free 1202 v This thread Refback 04-30-2010 15:18
Information How they kill smart-cards by FractalizeR - The All-Pinoy GSM Forum & National Districts This thread Refback 04-27-2010 21:47
Untitled document This thread Refback 04-22-2010 18:43
Aktualizacja/Update Pkeya i temat BB5King - PRZECZYTAJ !!! This thread Refback 04-07-2010 19:23
Untitled document This thread Refback 03-31-2010 12:41
Untitled document This thread Refback 03-25-2010 13:29

Similar Threads
Thread Thread Starter Forum Replies Last Post
How to Release smart card with new 2.32? KUBAT1 Infinity-Box 6 03-12-2008 13:11
How to deselect Smart Card option Only. talkways Universalbox 4 07-05-2007 14:58

 



All times are GMT +1. The time now is 11:55.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.19153 seconds with 10 queries

SEO by vBSEO