<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Investigators replicate Nokia 1100 online banking hack - Comments</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack</link>
 <description>Comments for &quot;Investigators replicate Nokia 1100 online banking hack&quot;</description>
 <language>en</language>
<item>
 <title>I also have a nokia 1100,</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12162</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;I also have a nokia 1100, anyone want to purchase it? contact me at&lt;br /&gt;
wbsh at realss dot com&lt;/p&gt;
</description>
 <pubDate>Tue, 26 May 2009 12:08:19 -0400</pubDate>
 <dc:creator>shang</dc:creator>
 <guid isPermaLink="false">comment 12162 at http://www.thestandard.com</guid>
</item>
<item>
 <title>If you hava a iphone ,we Can</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12160</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;If you hava a iphone ,we Can be traded.&lt;br /&gt;
haha~~&lt;/p&gt;
</description>
 <pubDate>Tue, 26 May 2009 11:05:45 -0400</pubDate>
 <dc:creator>Bob</dc:creator>
 <guid isPermaLink="false">comment 12160 at http://www.thestandard.com</guid>
</item>
<item>
 <title>Hi friend , i am bob have</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12159</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;Hi friend , i am bob have that Nokia 1100 made in China Beijing and now i am using it .... if you are also interested  in it ,please free free to contact with me .&lt;br /&gt;
&lt;a href=&quot;mailto:napoleon_ii@163.com&quot; rel=&quot;nofollow&quot;&gt;napoleon_ii@163.com&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;My MSN:napoleon_ii@hotmail.com,pls let us speak by it.&lt;br /&gt;
Waiting for your reply.&lt;/p&gt;
</description>
 <pubDate>Tue, 26 May 2009 11:03:23 -0400</pubDate>
 <dc:creator>Bob</dc:creator>
 <guid isPermaLink="false">comment 12159 at http://www.thestandard.com</guid>
</item>
<item>
 <title>good！</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12157</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;good！&lt;/p&gt;
</description>
 <pubDate>Tue, 26 May 2009 09:36:39 -0400</pubDate>
 <dc:creator>waterg</dc:creator>
 <guid isPermaLink="false">comment 12157 at http://www.thestandard.com</guid>
</item>
<item>
 <title>i am having 1 piece of nokia</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12147</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;i am having 1 piece of nokia 1100 made in germany plz provide me the best price&lt;br /&gt;
of what you can give the i can give the photo also to the serious&lt;br /&gt;
buyers my email id is sufiyanrajwani @ gmail . com, +919998152560&lt;/p&gt;
</description>
 <pubDate>Mon, 25 May 2009 01:50:15 -0400</pubDate>
 <dc:creator>sufiyanrajwani</dc:creator>
 <guid isPermaLink="false">comment 12147 at http://www.thestandard.com</guid>
</item>
<item>
 <title>It is delirium..</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12138</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;It is delirium..&lt;/p&gt;
</description>
 <pubDate>Fri, 22 May 2009 18:04:29 -0400</pubDate>
 <dc:creator>Guest..</dc:creator>
 <guid isPermaLink="false">comment 12138 at http://www.thestandard.com</guid>
</item>
<item>
 <title>huynya naverno</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12137</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;huynya naverno&lt;/p&gt;
</description>
 <pubDate>Fri, 22 May 2009 12:56:55 -0400</pubDate>
 <dc:creator>1</dc:creator>
 <guid isPermaLink="false">comment 12137 at http://www.thestandard.com</guid>
</item>
<item>
 <title>Cloning a SIM Trivial? Try</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12133</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;Cloning a SIM Trivial? Try looking into it. It hasn&#039;t been trivial for a number of years. I doubt that many carriers still use older SIMs - which were trivial to clone.&lt;/p&gt;
</description>
 <pubDate>Fri, 22 May 2009 08:39:10 -0400</pubDate>
 <dc:creator>SIMWiz</dc:creator>
 <guid isPermaLink="false">comment 12133 at http://www.thestandard.com</guid>
</item>
<item>
 <title>For the final step...clone a</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack#comment-12131</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;For the final step...clone a SIM...trivial? Of course, if one could clone a SIM and set the IMEI number, it is possible to fool the network. It is just that little detail of cloning the SIM that may be a problem.&lt;/p&gt;
&lt;p&gt;These ultraScan dudes are funny people.&lt;/p&gt;
</description>
 <pubDate>Fri, 22 May 2009 04:29:49 -0400</pubDate>
 <dc:creator>forensic-bob</dc:creator>
 <guid isPermaLink="false">comment 12131 at http://www.thestandard.com</guid>
</item>
<item>
 <title>Investigators replicate Nokia 1100 online banking hack</title>
 <link>http://www.thestandard.com/news/2009/05/21/investigators-replicate-nokia-1100-online-banking-hack</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;/p&gt;
&lt;p&gt;An old candy-bar style Nokia 1100 mobile phone has been used to break into someone&#039;s online bank account, affirming why criminals are willing to paying thousands of euros for the device.&lt;/p&gt;
&lt;p&gt;Using special software written by hackers, certain models of the 1100 can be reprogrammed to use someone else&#039;s phone number and receive their SMS (Short Message Service) messages, said Max Becker, CTO of &lt;a href=&quot;http://www.ultrascan-kpo.com/&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;Ultrascan Knowledge Process Outsourcing&lt;/a&gt;, a subsidiary of fraud investigation firm Ultrascan.&lt;/p&gt;
&lt;p&gt;The Nokia 1100 hack is powerful since it undermines a key technology relied on by banks to secure transactions done over the Internet.&lt;/p&gt;
&lt;p&gt;Banks in countries such as Germany and Holland send a one-time password called an mTAN (mobile Transaction Authentication Number) to a person&#039;s phone in order to allow, for example, the transfer of money to another account. &lt;/p&gt;
&lt;p&gt;Since the Nokia 1100 can be reprogrammed to respond to someone else&#039;s number, it means cybercriminals can also obtain the mTAN by SMS. Cybercriminals must already have a person&#039;s login and password for a banking site, but that&#039;s easy since millions of computers worldwide contain malicious software that can record keystrokes.&lt;/p&gt;
&lt;p&gt;Ultrascan obtained Nokia 1100 phones made in Bochum, Germany. Phones made around 2003 in that now-closed factory have the firmware version that can be hacked, Becker said. Nokia has sold more than 200 million of the 1100 and its successors, although it&#039;s unknown how many devices have the particular sought-after firmware.&lt;/p&gt;
&lt;p&gt;Ultrascan was able to successfully reprogram an 1100 and intercept an mTAN, but just one time. Becker said they are undertaking further tests to see if the attack can be executed repeatedly.&lt;/p&gt;
&lt;p&gt;&amp;quot;We&#039;ve done it once,&amp;quot; Becker said. &amp;quot;It looks like we know how to do it.&amp;quot;&lt;/p&gt;
&lt;p&gt;Ultrascan experts obtained the hacker software to reprogram the phone through its network of informants, said Frank Engelsman, a fraud and security specialist with the company. &lt;/p&gt;
&lt;p&gt;That application allows a hacker to decrypt the Nokia 1100&#039;s firmware, Becker said. Then, the firmware can be modified and information such as the IMEI (International Mobile Equipment Identity) number can be changed as well as the IMSI (International Mobile Subscriber Identity) number, which allows a phone to register itself with an operator. &lt;/p&gt;
&lt;p&gt;The modified firmware is then uploaded to the Nokia 1100. Certain models of the 1100 used erasable ROM, which allows data to be read and written to the chip, Becker said. For the final step, the hacker must also clone a SIM (Subscriber Identity Module) card, which Becker said is technically trivial.&lt;/p&gt;
&lt;p&gt;Nokia, which was closed on Thursday due to a holiday, could not be contacted. However, the company has said it does not believe there is a vulnerability in the 1100&#039;s software.&lt;/p&gt;
&lt;p&gt;Becker said that may be semantically true, however, it&#039;s possible that the encryption keys used to encrypt the firmware have somehow slipped into the public domain. &amp;quot;We would really like to speak with Nokia,&amp;quot; Becker said.&lt;/p&gt;
&lt;p&gt;Ultrascan was also able to confirm that criminals are willing to pay a lot of money for the right Nokia 1100. An Ultrascan informant sold one of the devices recently in Tangiers, Morocco, for €5,500 (US$7,567), Engelsman said. Ultrascan previously confirmed data earlier this year that one Nokia 1100 sold for €25,000.&lt;/p&gt;
&lt;p&gt;Ultrascan, which specializes in tracking criminals involved in Internet and electronic fraud, is trying to trace criminals who are using Nokia 1100s in online banking frauds.&lt;/p&gt;
&lt;p&gt;&amp;quot;We keep trying to infiltrate these groups,&amp;quot; Engelsman said.&lt;/p&gt;
</description>
 <category domain="http://www.thestandard.com/taxonomy/term/2105">Data protection</category>
 <category domain="http://www.thestandard.com/taxonomy/term/13269">Exploits</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2372">Fraud</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1402">IDGNS</category>
 <category domain="http://www.thestandard.com/taxonomy/term/13782">Mobile security</category>
 <category domain="http://www.thestandard.com/taxonomy/term/1428">Security</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/13270">vulnerabilities</category>
 <category domain="http://www.thestandard.com/taxonomy/term/98">Breaking News</category>
 <pubDate>Thu, 21 May 2009 11:53:43 -0400</pubDate>
 <dc:creator>IDG News Service</dc:creator>
 <guid isPermaLink="false">134608 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
