OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Guy Hadsall (ghadsalACM.ORG)
Date: Sun Feb 18 2001 - 13:08:46 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Ronen,

    The SMS platform will dictate the type of attack. The Ericsson is on
    Solaris, others are on NT. Best way to tackle the test is to prepare for
    the enivonment and completely understand the interfaces between systems.
    The TOE (test environment) for an SMS system includes both circuit switched
    and packet interfaces. The operating system of the network elements are
    often NT for non-carrier solutions and the application software has more
    often then not never been assessed by a security practictioner. It'll be
    like "fishing in a barrel" IMHO.

    Good luck, and please do share!

    GuyH

    -----Original Message-----
    From: Penetration Testers [mailto:PEN-TESTSECURITYFOCUS.COM]On Behalf Of
    Ronen Segal
    Sent: Sunday, February 18, 2001 7:44 AM
    To: PEN-TESTSECURITYFOCUS.COM
    Subject: [PEN-TEST] SMS (Short Message Service) Security

    Hello all.
    I’m about to conduct a Security Risk Assessment about a- TDMA and GSM SMS
    Services.
    If you could please point me to an article that deals with this matter or
    some thing that could help me get started by understanding the Risks SMS
    poses to the Service provider and the Cellular Subscriber I would be very
    Thankful.
    Thank You.
    Ronen