{"id":31886,"date":"2021-03-15T16:24:11","date_gmt":"2021-03-15T20:24:11","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=31886"},"modified":"2021-07-03T14:20:40","modified_gmt":"2021-07-03T18:20:40","slug":"sms-rerouting-vulnerability","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/03\/15\/sms-rerouting-vulnerability\/","title":{"rendered":"SMS Rerouting Vulnerability"},"content":{"rendered":"<p><a href=\"https:\/\/www.vice.com\/en\/article\/y3g8wb\/hacker-got-my-texts-16-dollars-sakari-netnumber\">Joseph Cox<\/a> (<a href=\"https:\/\/twitter.com\/josephfcox\/status\/1371509983842598918\">tweet<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.vice.com\/en\/article\/y3g8wb\/hacker-got-my-texts-16-dollars-sakari-netnumber\"><p>I hadn&rsquo;t been SIM swapped, where hackers trick or bribe telecom employees to port a target&rsquo;s phone number to their own SIM card. Instead, the hacker used a service by a company called Sakari, which helps businesses do SMS marketing and mass messaging, to reroute my messages to him. This overlooked attack vector shows not only how unregulated commercial SMS tools are but also how there are gaping holes in our telecommunications infrastructure, with a hacker sometimes just having to pinky swear they have the consent of the target.<\/p><p>[&#8230;]<\/p><p>While adding a number, Sakari provides the Letter of Authorization for the user to sign. Sakari&rsquo;s LOA says that the user should not conduct any unlawful, harassing, or inappropriate behaviour with the text messaging service and phone number.<\/p><p>But as Lucky225 showed, a user can just sign up with someone else&rsquo;s number and receive their text messages instead.<\/p><p>[&#8230;]<\/p><p>As for how Sakari has this capability to transfer phone numbers, Nohl from Security Research Labs said &ldquo;there is no standardized global protocol for forwarding text messages to third parties, so these attacks would rely on individual agreements with telcos or SMS hubs.&rdquo;<\/p><p>[&#8230;]<\/p><p>Horsman added that, effective immediately, Sakari has added a security feature where a number will receive an automated call that requires the user to send a security code back to the company, to confirm they do have consent to transfer that number.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2019\/02\/14\/stealing-high-value-instagram-accounts\/\">Stealing High-Value Instagram Accounts<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2017\/07\/21\/i-got-hacked-and-all-i-got-was-this-new-sim-card\/\">I Got Hacked and All I Got Was This New SIM Card<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2016\/06\/12\/twitter-account-hacked-via-sim-reset\/\">Twitter Account Hacked via SIM Reset<\/a><\/li>\n<\/ul>\n\n<p id=\"sms-rerouting-vulnerability-update-2021-03-19\">Update (2021-03-19): <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2021\/03\/easy-sms-hijacking.html\">Bruce Schneier<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.schneier.com\/blog\/archives\/2021\/03\/easy-sms-hijacking.html\">\n<p>Don&rsquo;t focus too much on the particular company in this article.<\/p>\n<\/blockquote>\n\n<p id=\"sms-rerouting-vulnerability-update-2021-05-24\">Update (2021-05-24): <a href=\"https:\/\/www.macrumors.com\/2021\/03\/25\/sms-routing-vulnerability-fix\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/03\/25\/sms-routing-vulnerability-fix\/\">\n<p>Major carriers in the U.S. like Verizon, T-Mobile, and AT&amp;T have made a change to how SMS messages are routed to put a stop to a security vulnerability that allowed hackers to reroute texts, reports <em><a href=\"https:\/\/www.vice.com\/en\/article\/5dp7ad\/tmobile-verizon-att-sms-hijack-change\">Motherboard<\/a><\/em>.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Joseph Cox (tweet): I hadn&rsquo;t been SIM swapped, where hackers trick or bribe telecom employees to port a target&rsquo;s phone number to their own SIM card. Instead, the hacker used a service by a company called Sakari, which helps businesses do SMS marketing and mass messaging, to reroute my messages to him. This overlooked attack [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-03-15T20:24:14Z","apple_news_api_id":"b5e852cc-0a54-4e1b-9cee-b644b48a77f6","apple_news_api_modified_at":"2021-07-03T18:20:44Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAg==","apple_news_api_share_url":"https:\/\/apple.news\/AtehSzApUThuc7rZEtIp39g","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[722,48,1393,2090],"class_list":["post-31886","post","type-post","status-publish","format-standard","hentry","category-technology","tag-federal-communications-commission-fcc","tag-security","tag-short-message-service-sms","tag-two-factor-authentication-2fa"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31886","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=31886"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31886\/revisions"}],"predecessor-version":[{"id":32598,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/31886\/revisions\/32598"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=31886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=31886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=31886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}