{"id":781,"date":"2015-11-09T12:38:37","date_gmt":"2015-11-09T12:38:37","guid":{"rendered":"http:\/\/nethemba.com\/cs\/?page_id=781"},"modified":"2019-08-19T09:41:08","modified_gmt":"2019-08-19T08:41:08","slug":"vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek","status":"publish","type":"page","link":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/","title":{"rendered":"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek"},"content":{"rendered":"<p lang=\"cs-CZ\" style=\"text-align: left;\" align=\"center\">SMS j\u00edzdenky jsou s oblibou pou\u017e\u00edvan\u00e9 ve velk\u00fdch m\u011bstech St\u0159edn\u00ed Evropy (Praha, Bratislava, Ko\u0161ice, V\u00edde\u0148, Var\u0161ava, ..)<\/p>\n<p lang=\"cs-CZ\" align=\"left\">C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f, kter\u00e9 nejsou dostate\u010dn\u011b dob\u0159e prov\u00e1zan\u00e9 na samotn\u00e9ho cestuj\u00edc\u00edho. Na demonstraci potenci\u00e1ln\u00edho zneu\u017eit\u00ed jsme navrhli speci\u00e1ln\u00ed s\u00ed\u0165ovou architekturu, kter\u00e1 umo\u017e\u0148uje skrz \u0161ifrovan\u00fd kan\u00e1l masivn\u011b distribuovat a sd\u00edlet SMS j\u00edzdenky mezi pasa\u017e\u00e9ry (SMS ticket hacker server + SMS ticket hack clients).<\/p>\n<p lang=\"cs-CZ\" align=\"left\">Kriti\u010dnost uveden\u00e9 zranitelnosti navy\u0161uje fakt, \u017ee v sou\u010dasn\u00e9 dob\u011b neexistuje jednoduch\u00fd a levn\u00fd zp\u016fsob jak uveden\u00fd \u00fatok odhalit.<\/p>\n<p lang=\"cs-CZ\" align=\"left\">Navrhli jsme tak\u00e9 v\u00edcero \u010d\u00e1ste\u010dn\u00fdch, ale nedostate\u010dn\u00fdch \u0159e\u0161en\u00ed, kter\u00e9 m\u016f\u017ee DP realizovat v snaze odhalit uveden\u00fd \u00fatok.<\/p>\n<p lang=\"cs-CZ\" align=\"left\">Tak\u00e9 jsme navrhli bezpe\u010dn\u00e9 a spolehliv\u00e9 \u0159e\u0161en\u00ed spo\u010d\u00edvaj\u00edc\u00ed ve sv\u00e1z\u00e1n\u00ed identity pasa\u017e\u00e9ra se SMS j\u00edzdenkou, bezpe\u010dn\u00fd zp\u016fsob generov\u00e1n\u00ed SMS j\u00edzdenek a tak\u00e9 zp\u016fsob jejich rychl\u00e9 kontroly se strany revizor\u016f.<\/p>\n<p lang=\"cs-CZ\" align=\"left\">P\u0159esto\u017ee jsme, v souladu s etikou tzv. responsible disclosure, dopravn\u00ed spole\u010dnosti s velk\u00fdm p\u0159edstihem p\u0159ed zve\u0159ejn\u011bn\u00edm o uveden\u00e9 zranitelnosti informovali, st\u00e1le je tato zranitelnost ignorovan\u00e1 a zraniteln\u00e9 syst\u00e9my jsou i nad\u00e1le pou\u017e\u00edvan\u00e9<\/p>\n<p align=\"left\"><span lang=\"cs-CZ\"><b>Prezentace: <\/b><\/span><a href=\"https:\/\/nethemba.com\/resources\/SMS-ticket-hack4.pdf\"><span lang=\"cs-CZ\">Zranitelnosti v SMS\u00a0j\u00edzdenk\u00e1ch (prezentace v angli\u010dtin\u011b)<\/span><\/a><\/p>\n<div id=\"__ss_4738280\"><iframe src=\"https:\/\/www.slideshare.net\/slideshow\/embed_code\/4738280\" width=\"425\" height=\"355\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/div>\n<p align=\"left\"><span lang=\"cs-CZ\"><b>Publikov\u00e1no na konferenc\u00edch:<\/b><\/span><\/p>\n<p align=\"left\"><a href=\"https:\/\/har2009.org\/program\/events\/89.en.html\"><span lang=\"cs-CZ\">Hacking at Random 2009 v Holandsku<\/span><\/a><\/p>\n<p align=\"left\"><a href=\"http:\/\/2009.confidence.org.pl\/prelegenci\/pavol-luptak\"><span lang=\"cs-CZ\">Confidence v Krakove \/\u00a0Polsku<\/span><\/a><\/p>\n<p align=\"left\"><a href=\"http:\/\/metalab.at\/wiki\/SMS-Ticket-Vortrag\"><span lang=\"cs-CZ\">Metalab ve V\u00eddni \/\u00a0Rakousko<\/span><\/a><\/p>\n<p align=\"left\"><strong><span lang=\"cs-CZ\">Rozhovor pro den\u00edk\u00a0SME:\u00a0<\/span><\/strong><a href=\"http:\/\/bratislava.sme.sk\/c\/4915803\/sms-listky-sa-zneuzit-daju-tvrdi-expert.html\"><span lang=\"cs-CZ\">SMS l\u00edstky sa zneu\u017ei\u0165 daj\u00fa, tvrd\u00ed expert<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SMS j\u00edzdenky jsou s oblibou pou\u017e\u00edvan\u00e9 ve velk\u00fdch m\u011bstech St\u0159edn\u00ed Evropy (Praha, Bratislava, Ko\u0161ice, V\u00edde\u0148, Var\u0161ava, ..) C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f, kter\u00e9 nejsou dostate\u010dn\u011b dob\u0159e prov\u00e1zan\u00e9 na samotn\u00e9ho cestuj\u00edc\u00edho. Na demonstraci potenci\u00e1ln\u00edho zneu\u017eit\u00ed jsme navrhli speci\u00e1ln\u00ed s\u00ed\u0165ovou architekturu, kter\u00e1 umo\u017e\u0148uje skrz \u0161ifrovan\u00fd kan\u00e1l masivn\u011b distribuovat a sd\u00edlet SMS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":524,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"class_list":["post-781","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba<\/title>\n<meta name=\"description\" content=\"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/\" \/>\n<meta property=\"og:locale\" content=\"cs_CZ\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba\" \/>\n<meta property=\"og:description\" content=\"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/\" \/>\n<meta property=\"og:site_name\" content=\"Nethemba\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/nethemba\" \/>\n<meta property=\"article:modified_time\" content=\"2019-08-19T08:41:08+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@nethemba\" \/>\n<meta name=\"twitter:label1\" content=\"Odhadovan\u00e1 doba \u010dten\u00ed\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minuta\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\\\/\",\"url\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\\\/\",\"name\":\"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\"},\"datePublished\":\"2015-11-09T12:38:37+00:00\",\"dateModified\":\"2019-08-19T08:41:08+00:00\",\"description\":\"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\\\/#breadcrumb\"},\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/home-new-2025\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"O n\u00e1s\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/?page_id=319\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"V\u00fdzkum\",\"item\":\"https:\\\/\\\/nethemba.com\\\/cs\\\/o-nas-old\\\/vyzkum\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nethemba.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/nethemba.com\\\/de\\\/\",\"name\":\"Nethemba\",\"description\":\"We care about your security\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nethemba.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"cs\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba","description":"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/","og_locale":"cs_CZ","og_type":"article","og_title":"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba","og_description":"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)","og_url":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/","og_site_name":"Nethemba","article_publisher":"https:\/\/www.facebook.com\/nethemba","article_modified_time":"2019-08-19T08:41:08+00:00","twitter_card":"summary_large_image","twitter_site":"@nethemba","twitter_misc":{"Odhadovan\u00e1 doba \u010dten\u00ed":"1 minuta"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/","url":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/","name":"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek - Nethemba","isPartOf":{"@id":"https:\/\/nethemba.com\/de\/#website"},"datePublished":"2015-11-09T12:38:37+00:00","dateModified":"2019-08-19T08:41:08+00:00","description":"C\u00edlem na\u0161eho v\u00fdzkumu bylo pouk\u00e1zat na v\u00e1\u017en\u00e9 bezpe\u010dnostn\u00ed zranitelnosti SMS l\u00edstk\u016f. (SMS ticket hacker server + SMS ticket hack clients)","breadcrumb":{"@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/#breadcrumb"},"inLanguage":"cs","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/vazne-zranitelnosti-v-systemu-tzv-sms-jizdenek\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nethemba.com\/cs\/home-new-2025\/"},{"@type":"ListItem","position":2,"name":"O n\u00e1s","item":"https:\/\/nethemba.com\/cs\/?page_id=319"},{"@type":"ListItem","position":3,"name":"V\u00fdzkum","item":"https:\/\/nethemba.com\/cs\/o-nas-old\/vyzkum\/"},{"@type":"ListItem","position":4,"name":"V\u00e1\u017en\u00e9 zranitelnosti v syst\u00e9mu tzv. SMS j\u00edzdenek"}]},{"@type":"WebSite","@id":"https:\/\/nethemba.com\/de\/#website","url":"https:\/\/nethemba.com\/de\/","name":"Nethemba","description":"We care about your security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nethemba.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"cs"}]}},"_links":{"self":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/comments?post=781"}],"version-history":[{"count":0,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/781\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/pages\/524"}],"wp:attachment":[{"href":"https:\/\/nethemba.com\/cs\/wp-json\/wp\/v2\/media?parent=781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}