Home / Series / DEF CON / Aired Order / Season 32 / Episode 48

Smishing Smackdown: Unraveling the Threads of USPS Smishing and Fighting Back

It's the holiday season and all through the air, Messages arrive, not with joy, but despair. A sinister plot unfolds, a digital dance, Smishing scammers striking, a threat to enhance. This past holiday season saw a dramatic rise in SMS phishing (smishing) messages, specifically targeting people pretending to be the USPS. Almost everyone in the United States received one of these messages using a kit sold by the ‘Smishing Triad’. While many of us knew these were scams many more did not, including someone close to me. I knew I had to do something about it once I started receiving these texts myself. With my focus in web application testing, I immediately took interest in these smishing kits and how I could exploit them. After a thorough review, some collaboration with other researchers, and a little reverse engineering I was able to find two vulnerabilities in the scammer’s kits allowing me to login to the admin panels.

English
  • Originally Aired August 10, 2024
  • Runtime 45 minutes
  • Created August 25, 2024 by
    Subscriber-2473783
  • Modified August 25, 2024 by
    Subscriber-2473783