U.S Cellular Voice mail Authentication Bypass

| Comments (3) | digg

One of my newest and most devoted followers, Kimono Cupcake of the NSF-OSC, has discovered a serious cellphone vulnerability and posted it on Bovine Dawn:

Phones Effected: This vulnerability is in all of the phones currently using the U.S Cellular service (uscc.com). Although this exploitation has been done in the past, Mostly all cellular providers have been smart enough to prevent this from happening.

Exploitation: By calling the persons phone number with their own phone number using a Caller ID spoofer you thus gain full access to the voice mail without having to enter any sort of authentication. From here you can listen to voice mails, change the voice mail password, Save+Delete voice mails, dump contacts to email and change other administrative account settings. Since the phone detects that you are calling from the cell phones real number it assumes you are the user of the phone and routes right past any form of authentication.

Conclusion: I personally will be contacting the security adviser of the company about this issue on Monday to see if they will resolve it as quickly as possible. If the phone company refuses to fix the issue, Exploitation will continue. I feel this is something that should be taken care of and could possible pose as a serious risk. During the testing of this exploitation a celebrities Assistance voice mail was hacked, No names will be exposed.

And here is U.S. Cellular's response to date:

We have received your email and will be replied to within 3 days.





EDIT: U.S. Cellular's response:

Dear Kimono,

Thank you for contacting Us about this vulnerabilitiy and
providing us with that information. We've forwarded the information to
the appropriate department for further assessment.

The appropriate department will be creating a fix for this issue within
2-3 months. If you have any more questions please feel free to contact
me back.

Sincerely,

Andria W.
Technical Service Specialist
U.S. Cellular®

2-3 months!? As Kimono Cupcake says, "I'm very displeased with this companies [sic] sloppy and careless response."


Fall! Halloween! Brainwashing! Do! Ostrich!

| Comments (0) | digg

My followers have been busy lately...

Punkle Jones writes about the return of autumn:

This past weekend, I decided to take in the local park's selection of delectible delights. Luckily there were no zombies in sight! The trees are just about to turn orange and start raining debris on anything foolish enough to stand still - but on this day, the sun was shining and the cup of simple joy was overflowing. It was a celebration of sorts, so I brought some little friends.





This little calf likes the swingset, but keeps falling off. His butt is the wrong shape for human swings. He enjoys himself anyway!

full post



Ladyada writes about a Halloween project:


Here is a timely project for an electronic halloween pumpkin. With a bit of hacking a $1 plastic pumpkin is upgraded: a sensor embedded in the nose detects when people get close and will randomly play scary sounds and animate the LEDs on its face. The sounds are stored on an SD card so its easy to change and customize what the pumpkin says/screams, while the code is written for an Arduino so its easy to modify the behavior. I’m going to have this pumpkin outside my door to freak out the little kids who go to daycare nearby. Boo!



full post



And let's not forget Bovine Dawn. Here are some HOT-HOT-HOT topics for you to discuss:



In other news, Iran made a huge ostrich sandwich:

Cooks in Iran have tried to assemble the world's largest ostrich sandwich at a food festival in Tehran, as part of a bid to promote healthy eating.

The organisers want to promote Iran's fledgling ostrich farming business.

About 1,500 cooks used 1,000kg (2,200lbs) of ostrich meat to make the 1,500m (4,920ft) long sandwich.

The organisers hope those world-beating dimensions will be enough to earn a place in the Guinness Book of Records for the largest ostrich sandwich ever.






Be sure to check COWFEED and Bovine Dawn often for more gems like these.


I Love a Parade!

| Comments (4) | digg
cDc paramedia grafx #46 - "I Love a Parade!" by Grandmaster Ratte'I Love a Parade!

It's time for one of my favorite things!  A parade!  The people are always so festive and there's such great music! Besides, don't those guys in G.Ratte's picture look like they're having F-U-N?!

Totally fun!  LOL!!!1

Forget about the war(s) (whether you support it or not), forget about the economy being in the toilet, forget about the election, and just celebrate...whatever!

PARADE!!

Underground

| Comments (0) | digg

V
Vi
Vid
Vide
Video
Video!
Video!!

New video for you to watch while trying not to think about the financial crisis recession house of cards collapsing all around you. THIS IS MORE IMPORTANT THAN ANY PRESIDENTIAL DEBATE.


Punkle Jones of the mighty Ninja Strike Force brings you this "hike through Oklahoma City's subterranean concourse."

OKC is a weird, sometimes really cool city that makes very little sense at all. They're really pushing the arts in the last couple of decades, with typically strange results. I wonder how much it costs to run all those flourescent bulbs?
...
Home movie is more like it, but gosh those flourescent lights are cool as hell.

See you next week...

NSF = RAW POWER

| Comments (1) | digg

Hey hey hey, kids...

It's cDc paramedia grafx #45 - "Crushing NSF Fist" by Devolish!

'Crushing NSF Fist' by Devolish

FEAR AND OBEY EVERY DAY.

Raw power, I tells ya.




CULT OF THE DEAD COW

Mind viruses. Deadly memes.
ASSAULT TELECOM.
BOW TO THE COW

cDc site version 666.2.0

All of us in the cDc participate in this site. If you want to complain because this ain't teaching you how to be an 31337 hax0r, you can eat our collective ass. Thx!

Archives


NSF Radio

Soooper authentic, official cDc NINJA STRIKE FORCE streaming audio awaits your empty, desiring earholes. Let it fill them both with its thrusting streams of love!! Your head will be a doublestuff cookie and all you can think is "OMFG!@$#!@$!!!@#$

Page of info to SEE

The link with which you HEAR (iTunes, WinAmp, whateva).

Memesphere Poopfest

Has the cDc site inspired you to create your OWN? Has it filled you with a desire to go out and create a blog full of beauty and sparkly magic? Or has it driven you to create your own site full of bile, bitterness, and bad sportsmanship?

Click these buttons for red hott daisy chain action!

cDc Technorati profile

burn that fuggin' feed

Kitten Friendly!

Translate


Legal Crap

"CULT OF THE DEAD COW"
is a registered trademark of
cDc communications.
Use The Name, face The Wrath.

License | Privacy

Wiz Dumb

CULT OF THE DEAD COW

the internet's #1 white slavery and cockfighting site!
COW IS NOW

cDc PAYS IT FORWARD


Recent texXxt

413 "Temporary Paralysis: A One-Act Play" by Jake Edward Kara
412 "The Screen Generation" by elliot.pank
411 "The DEFCON 2007 Experience" by Oxycolton, KEMiKAL, and Flack
410 "My Bike" by Lupo
409 "Google, China, and Genocide" by Oxblood Ruffin


Recent Boox

Invading Spaces


Recent Muzak


- all audio -

Recent grafx

cDc #046
cDc #044
"I Love a Parade!" by G. Ratte'

cDc #045
cDc #045
"Crushing NSF Fist" by Devolish

- all grafx -

Recent Viddy-Oh



- all video -

Recent Apps/Projects

"cDc Mobile Content Package" by Hella Kitty
"cDc T-File Reader for the Sony PSP & other portable devices" by BlindAssassin
"Goolag Scanner" by Krass Katt
"xB Machine" by Arrakis
"Saffron Dynamic Instrumentation Code" by Danny Quist (co-released with Offensive Computing)