Page 17 - Security testing for USSD and STK based Digital Financial Services applications Security, Infrastructure and Trust Working Group
P. 17

Figure 7 - Sample SIMtrace output






































            Figure 8 - Sample wire shark output from SIMtrace – This Wireshark trace shows that the PIN was captured in
            clear text by SIMtrace.




























            The Wireshark capture above is a sample result and demonstrates that an attacker can read the PIN and data
            as it is keyed to the device with the SIM trace.








                                                 Security testing for USSD and STK based Digital Financial Services applications  15
   12   13   14   15   16   17   18   19   20   21   22