Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The federal government has been fighting hard for years hide details about its use of so-called stingray surveillance technology from the public. . The surveillance devices simulate cell phone towers in order to trick nearby mobile phones into connecting to them and revealing the phones . Monitoring gadgets impersonate cellular towers, uncovering private information from surrounding smartphones.. Stingray Tools, Mobile Privacy, Surveillance Threats, Cell Tower Simulation. . LinuxSecurity.com Team
An O2 user, Lewis Peckover, found that the mobile phone company has been adding the phone number of any subscriber using its mobile network to the HTTP headers of web requests. The header, x-up-calling-line-id, appears to be inserted by the transparent proxies that O2 uses so it can downgrade images and insert JavaScript into the returned HTML. . To experience the problem, a user on the O2 network needs to disable Wi-Fi and, without using a proxying browser such as Opera Mini, connect to Peckover's site which displays the headers received. The issue isn't new: in 2010 Collin Mulliner presented a paperPDF to the Security in Telecommunications conference on research that had found number leakage from numerous phone carriers. Mulliner offers the MNO Privacy Checker which examines HTTP request headers for the x-up-calling-line-id, and the many other added headers he found in use, and displays the results with a green, for clear, or red, for privacy leakage, page background. The x-up-calling-line-id header is documented in a 2009 blog posting of known telco HTTP headers. The link for this article located at H Security is no longer available. . A mobile user uncovers O2 network exposing personal phone numbers in HTTP headers, underscoring serious privacy concerns in the mobile telecommunications industry.. O2 Network, Phone Number Privacy, HTTP Header Leakage, Mobile Security, User Data Exposure. . LinuxSecurity.com Team
A researcher at the Def Con security conference in Las Vegas demonstrated that he could impersonate a GSM cell tower and intercept mobile phone calls using only $1500 worth of equipment. The cost-effective solution brings mobile phone snooping to the masses, and raises some concerns for mobile phone security. . How does the GSM snooping work? Chris Paget was able to patch together an IMSI (International Mobile Identity Subscriber) catcher device for about $1500. The IMSI catcher can be configured to impersonate a tower from a specific carrier. To GSM-based cell phones in the immediate area--the spoofed cell tower appears to be the strongest signal, so the devices connect to it, enabling the fake tower to intercept outbound calls from the cell phone. What happens to the calls? The link for this article located at Network World is no longer available. . How does the GSM snooping work?Chris Paget was able to patch together an IMSI (International Mobile . researcher, security, conference, vegas, demonstrated, impersonate. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.