GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Other Gsm/Mobile Related Forums > GSM Programming & Reverse Engineering

GSM Programming & Reverse Engineering Here you can post all Kind of GSM Programming and Reverse Engineering tools and Secrets.

Reply
 
LinkBack Thread Tools Display Modes
Old 08-04-2019, 09:00   #61 (permalink)
Moderator
 
Join Date: May 1999
Location: Blagoevgrad, Bulgaria
Age: 47
Posts: 1,045
Member: 73
Status: Offline
Sonork: 100.86913
Thanks Meter: 528
Donate money to this user

Dreams... Is cheap and no restrictions.
__________________
You'll die as you lived in a flash of the blade,
in a corner forgotten by no one
You lived for the touch for the feel of the steel
One man, and his honor.
  Reply With Quote
Old 08-04-2019, 15:29   #62 (permalink)
No Life Poster
 
.:D:.'s Avatar
 
Join Date: Apr 2016
Posts: 1,645
Member: 2561651
Status: Offline
Sonork: 100.*******
Thanks Meter: 246
Ok i have device with knox 0x0 its also exyons and then i want to repair the imei, os that not possible?
I see in fb there's local person he can repair M20 imei without server, he clearly show in video the device have imei from 35 and emergency call and in 1mint device reboot and immediately pickup the sim and signals even sim detect and now the imei start from 86... maybe he repair black listed imei.
Now I'm 100% sure there's a way for samsung exyons without server. Even without patch... if not then how he can done it? Even he done m10 also

Quote:
Originally Posted by LEENO View Post
Patch possible only for few model and not latest versions. When patch is working, phone will not send calls anymore after update.

Possible to repair imei in all Samsung until S10 with samsung official method, possible if knox warranty void is zero. Phone will always work after update.
Possible remotely
Idk why but i read your all comments and your experience force me to though about you....
Are you in samsung?


Quote:
Originally Posted by Victor View Post
... Patch ok. But how Will fight with AVB 2.0 in high bit firmwares? Vbmeta.img contain hashes of partitions plus 2048/4096/8192 bits signed depended by vendor.
  Reply With Quote
Old 08-10-2019, 02:18   #63 (permalink)
Freak Poster
 
Join Date: Nov 2004
Age: 40
Posts: 195
Member: 93421
Status: Offline
Thanks Meter: 15
Leeno say this: Only Samsung way its best solution --> i have best solution--> same, i work inside Samsung...
  Reply With Quote
The Following User Says Thank You to desanclador For This Useful Post:
Old 08-10-2019, 06:34   #64 (permalink)
No Life Poster
 
.:D:.'s Avatar
 
Join Date: Apr 2016
Posts: 1,645
Member: 2561651
Status: Offline
Sonork: 100.*******
Thanks Meter: 246
check pm bro .........

Quote:
Originally Posted by desanclador View Post
Leeno say this: Only Samsung way its best solution --> i have best solution--> same, i work inside Samsung...
  Reply With Quote
The Following User Says Thank You to .:D:. For This Useful Post:
Old 08-12-2019, 15:28   #65 (permalink)
No Life Poster
 
Join Date: Mar 2007
Location: Portugal, beautifull Lisbon &#
Age: 40
Posts: 937
Member: 478535
Status: Online
Thanks Meter: 365
Quote:
Originally Posted by LEENO View Post
Only way to obtain keys is to stolen it or create a virus for use many pcs as a super pc for obtain it via brute-force method
Quote:
Originally Posted by Victor View Post
Dreams... Is cheap and no restrictions.
well... Someone definitely had try to:

bleepingcomputer news/security/samsung-service-centers-in-italy-targeted-in-malware-campaign

Perhaps this campaign had this objective? who knows...
  Reply With Quote
Old 08-12-2019, 17:53   #66 (permalink)
No Life Poster
 
.:D:.'s Avatar
 
Join Date: Apr 2016
Posts: 1,645
Member: 2561651
Status: Offline
Sonork: 100.*******
Thanks Meter: 246
Page not found .
  Reply With Quote
The Following User Says Thank You to .:D:. For This Useful Post:
Old 08-12-2019, 23:32   #67 (permalink)
No Life Poster
 
Join Date: Mar 2007
Location: Portugal, beautifull Lisbon &#
Age: 40
Posts: 937
Member: 478535
Status: Online
Thanks Meter: 365
Quote:
Originally Posted by .:D:. View Post
Page not found .
https://www.bleepingcomputer.com/new...ware-campaign/


Quote:
Security researchers have discovered ongoing malware campaigns targeting Samsung service centers in Italy, campaigns that appear to be the counterparts of attacks that have previously targeted similar electronics service centers in Russia this year.

These malware campaigns are nothing out of the extraordinary, and the only thing that remains a mystery is their purpose and end goal.
Mundane malware distribution effort

The attacks usually start with the delivery of spoofed spear-phishing emails to Samsung Italy service center workers.

These emails carry attached Excel documents that when opened leverage the CVE-2017-11882 Office Equation Editor vulnerability to infect users with malware.

The entire malware delivery system and exploit chain is described in a detailed report published by Italian cyber-security firm TG Soft and is near identical to the attacks targeting electronics service centers in Russia, as described in a previous Fortinet report.

Both attack waves, targeting Italy and Russia, started at the end of March, according to the two reports. But while Russian service centers were targeted with the Imminent Monitor RAT, the attacks on Samsung Italy service centers also leveraged other RATs, such Netwire and njRAT.

Both companies also noted that the spear-phishing emails are very well put together, and appear to have been written by a native in Italian and Russian, respectively.
Nobody knows the purpose of these attacks

But despite all the data gathered by TG Soft and Fortinet, the two companies have not been able to determine why the hackers are trying to infect electronics service centers, to begin with.

Such service centers hold very little customer data that a threat actor could steal, and an attacker having many other more attractive companies he could target and gain more useful data from.

One explanation may be that attackers are trying to taint the tools used in these service centers so that they could infect the repaired devices with malware. But this is only a theory, as no evidence has been unearthed to support this scenario, and this entire malware distribution campaign remains shrouded in a fog of mystery.
  Reply With Quote
Old 08-13-2019, 05:57   #68 (permalink)
No Life Poster
 
.:D:.'s Avatar
 
Join Date: Apr 2016
Posts: 1,645
Member: 2561651
Status: Offline
Sonork: 100.*******
Thanks Meter: 246
Ok but there's nothing for us in this case
  Reply With Quote
Old 08-13-2019, 07:49   #69 (permalink)
No Life Poster
 
Join Date: Mar 2007
Location: Portugal, beautifull Lisbon &#
Age: 40
Posts: 937
Member: 478535
Status: Online
Thanks Meter: 365
Quote:
Originally Posted by .:D:. View Post
Ok but there's nothing for us in this case
Never told that. Just pointed to some sort of try to infiltrate to samsc to gather info (internal logins, software or, as the report say, to infect customers devices).

This wile quoting LEENO about the
"Only way to obtain keys is to stolen it or create a virus for use many pcs as a super pc for obtain it via brute-force method"

and vitor for:
"Dreams... Is cheap and no restrictions."

The are more than 10 ways to make a stew!

But the tl/dr is, there is no way to forge a cert without the proper credentials (priv key)
Bruteforce 1 cert, even if it is possible just 1 time, would take an immense amount of energy (thus money) that would not even worth your entire business. Then, you would need to create another cert for the next customer!
  Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 



All times are GMT +1. The time now is 07:54.



Powered by Searchlight © 2019 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2019 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2017 -
Page generated in 0.28865 seconds with 7 queries

SEO by vBSEO