Episode 3 Mobile Device Security Part 1

Опубликовано: 04 Октябрь 2026
на канале: MightyJocephus
666
11

Hello and welcome to the 3RD episode of Security by B3h3m0th. This topic is another fluid topic meaning that while it is based on facts now, its applicability may change in the future.
In the wake of today's announcement of the iPhone 5 and the alleged leaked FBI files detailing tracking in excess of 12 million Unique device identifies (which should be noted that while our friends at Anonymous claim to have gotten the information they published from the FBI, it was confirmed that the information was stolen by Anonymous off-shot Anti-Sec from Blue Toad, an application development firm), I am discussing mobile device security.
What is a mobile device? In this context, it is a cell phone or a tablet running an operating system such as Apple iOS, Android, or Windows Mobile.
Why should I care about securing my phone? Simple, there are tools out there allowing hackers the ability to access the phones using other phones, Wi-Fi, or Bluetooth. While using another phone requires Wi-Fi or Bluetooth, many laptops are coming standard equipped with Bluetooth in addition to Wi-Fi and Ethernet today.
As the capabilities of the devices increases, people will do more on the devices, leaving more sensitive data on the device for an intruder to pilfer through. More and more companies recognize this and are allowing devices to be used as computers in BYOD strategies. Additionally, there are solutions for people to jailbreak or root their phones on the internet that can be executed remotely using SQL injection attacks or a malformed text message showing only an empty square in the field.
This is not even grazing the surface, because the manufacturers have their "snoopware" apps that I discussed in last week's VLOG as well. This brings the security conscientious person to the crossroads of who do I want snooping? Which non secure method is safer?
While I mention the iPhone in this VLOG, similar vulnerabilities exist in Android and Windows devices as well. Android and Apple are based on Linux (BSD to be specific) whereas Windows is only a scaled down PC operating system for a mobile device. What does this tell me? That the attack vectors for all three are identical if not greater than that of a "normal" desktop or laptop.
Here is a scary scenario for iPhone users. Absinthe, one of the leaders in Jailbreak exploits can now be executed remotely. So? Well it doesn't require the consent of the device owner. After this has been conducted (easiest to do if the device is on the perp's Wi-Fi network) a session can be established using SSH (Secure Shell -- an encrypted Linux file transfer protocol, so sniffers can't see what is happening) and the attacker can copy the entire phone (pictures, phone records, contacts, and texts, etc.) to their machine.
Other exploits exist using the Metasploit framework to exploit Safari and other Apple programs allowing unauthorized access to the same. Another vector occurs when the victim leaves their Bluetooth or Wi-Fi enabled without a passcode to secure it. The attacker will pair the devices and steal all of the data. If unsuccessful, the attacker could also do a Denial of Service attack or use specially crafted text messages to destroy the phone.
Finally, apps -- a recurring theme here. In this context, I am referring to what permissions you give the apps on your device. For example, is there any good reason why an alarm clock should be able to make calls on your behalf? Why does adobe need to see your contacts? Especially in the Android arena, these apps are not tested or vetted. Anyone can write the app to do whatever they want and no one is going to stop them. Recall in 2010 or 2011 when it was discovered that the Pandora music app was stealing user's information. That is what led to the disclosure of permissions in Android so that these apps could still do this. It is not right per se and I feel it borderlines on unethical, but legally, all bases are covered.
My best advice to you is to disable wi-fi or Bluetooth when not in use and do not open any text messages from numbers you don't recognize. Be careful what wwi-fi networks you connect your device to. Always look at what the applications are getting access to, if you don't feel comfortable, uninstall it.
If you have any questions, contact me at [email protected] or facebook.com/b3h3m0th
I would like to give a shout out to Shallowpoint for providing the intro and outro music. You can find them on You Tube under Shallowpoint Official, Facebook, and Google sites at sites.google.com/site/theofficialshallowpoint.
Until Next time...stay secure