News / Science & Technology

Researchers Hack Verizon Device, Turn it Into Mobile Spy Station

A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
Reuters

Two security experts said they have figured out how to spy on Verizon Wireless mobile phone customers by hacking into devices the U.S. carrier sells to boost wireless signals indoors.
 

The finding, which the experts demonstrated to Reuters and will further detail at two hacking conferences this summer, comes at a time of intense global debate about electronic privacy, after top-secret U.S. surveillance programs were leaked by a former National Security Agency contractor, Edward Snowden, last month.

"This is not about how the NSA would attack ordinary people. This is about how ordinary people would attack ordinary people,'' said Tom Ritter, a senior consultant with the security firm iSEC Partners.
 

Verizon said it has updated the software on its signal-boosting devices, known as femtocells or network extenders, to prevent hackers from copying the technique of the two experts.
 

But Ritter said motivated hackers can still find other ways to hack the femtocells of Verizon, as well as those offered by some 30 carriers worldwide to their customers.

Femtocells, which act as tiny cellphone towers, can be purchased directly from Verizon for $250. Used models can be obtained online for about $150.  Ritter and his colleague, Doug DePerry, demonstrated for Reuters how they can eavesdrop on text messages, photos and phone calls made with an Android phone and an iPhone by using a Verizon femtocell that they had previously hacked.
 

They declined to disclose how they had modified the software on the device, saying they do not want to make it any easier for criminals to figure out similar ways to hack femtocells.

   
The two said they plan to give more elaborate demonstrations wo weeks from now at the Black Hat and Def Con hacking conferences in Las Vegas. More than 15,000 security professionals and hackers are expected to attend those conferences, which feature talks on newly found bugs in communications systems, smart TVs, mobile devices and computers that run facilities from factories to oil rigs.

 

Verizon Wireless released a Linux software update in March that prevents its network extenders from being compromised in the manner reported by Ritter and DePerry, according to company spokesman David Samberg.

"The Verizon Wireless Network Extender remains a very secure and effective solution for our customers,'' Samberg said in a statement. He said there have been no reports of customers being impacted by the bug that the researchers had identified. The company is a joint venture between Verizon Communications Inc and Vodafone Group Plc.

 

Samberg said his company uses an internal security team as well as outside firms to look for vulnerabilities in the devices it sells, before and after they are released.

   
Still, the two researchers said they are able to use the hacked femtocell to spy on Verizon phones even after Verizon released that update because they had modified the device before the company pushed out the software fix.


The researchers built their "proof of concept'' system that they will demonstrate in Las Vegas with femtocells manufactured by Samsung Electronics Co and a $50 antenna from Wilson Electronics Inc.
 

They said that with a little more work, they could have weaponized it for stealth attacks by packaging all equipment needed for a surveillance operation into a backpack that could be dropped near a target they wanted to monitor.

   
For example, a group interested in potential mergers might place such a backpack in Manhattan restaurants frequented by investment bankers. Verizon's website said the device has a 40-foot range, but the researchers believe that could be expanded by adding specialized antennas.
 

The iSEC researchers are not the first to warn of vulnerabilities in femtocells, but claim to be the first to hack the femtocells of a U.S. carrier and also the first running on a wireless standard known as CDMA. Other hacking experts have previously uncovered security bugs in femtocells used by carriers in Europe.

   
CTIA, a wireless industry group based in Washington, in February released a report that identified femtocells as a potential point of attack. John Marinho, CTIA's vice president for cybersecurity and Technology, said that the group is more concerned about other potential cyber threats, such as malicious apps. He is not aware of anycase where attacks were launched via femtocells.
 

Still, he said, the industry is monitoring the issue: "Threats change every day.''

 

You May Like

US Border Patrol Union Accused of Taking Sides on Immigration

Report alleges agents leaking info to immigration opponents, appearing at their private events; Center for Immigration Studies director defends agents' actions More

Video Blind Somali Journalist Defies Odds in Mogadishu

Reporting from Somali capital for past decade, Abdifatah Hassan Kalgacal has been working at one of Mogadishu's leading radio stations covering parliament More

Video Rights Monitor: Hate Groups' Use of Internet to Inflame, Recruit Growing

Wiesenthal Center's Abraham Cooper says extremists have become skilled at celebrating violence, ideology on Web More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Hate Groups Spread Influence Via Interneti
X
Mike O'Sullivan
June 30, 2015 8:20 PM
Hate groups of various kinds are using the Internet for propaganda and recruitment, and a Jewish human rights organization that monitors these groups, the Simon Wiesenthal Center, says their influence is growing. The messages are different, but the calls to hatred or violence are similar. VOA's Mike O’Sullivan reports.
Video

Video Hate Groups Spread Influence Via Internet

Hate groups of various kinds are using the Internet for propaganda and recruitment, and a Jewish human rights organization that monitors these groups, the Simon Wiesenthal Center, says their influence is growing. The messages are different, but the calls to hatred or violence are similar. VOA's Mike O’Sullivan reports.
Video

Video US Silica Sand Mining Surge Worries Illinois Residents, Businesses

Increased domestic U.S. oil and gas production, thanks to advances known as “fracking,” has created a boom for other industries supporting that extraction. Demand for silica sand, used in fracking, could triple over the next five years. In the Midwest state of Illinois, people living near the mines are worried about how increased silica sand mining will affect their businesses and their health. VOA’s Kane Farabaugh has more in this first of a series of reports.
Video

Video Blind Somali Journalist Defies Odds in Mogadishu

Despite improving security in the last few years, Somalia remains one of the most dangerous countries to be a journalist – even more so for someone who cannot see. Abdulaziz Billow has the story of journalist Abdifatah Hassan Kalgacal, who has been reporting from the Somali capital for the last decade despite being blind.
Video

Video Texas Defies Same-Sex Marriage Ruling

Texas state officials have criticized the US Supreme Court decision giving same-sex couples the right to marry nationwide. The attorney general of Texas says last week's decision did not overrule constitutional "rights of religious liberty," and therefore officials performing wedding services can refuse to perform them for same-sex couples if it is against their religious beliefs. Zlatica Hoke reports on the controversy.
Video

Video Syrians Flee IS Advance in Hasaka

The Syrian government said Monday it has taken back one of several districts in Hasaka overrun by Islamic State militants. But continued fighting elsewhere in the northern city has forced thousands of civilians from their homes. In this report narrated by Bill Rodgers, VOA Kurdish Service reporter Zana Omer describes the scene in Amouda, where some of the displaced are taking refuge.
Video

Video Rabbi Hits Road to Heal Jewish-Muslim Relations in France

France is on high alert after last week's terrorist attack near the city Lyon, just six months after deadly Paris shootings. The attack have added new tensions to relations between French Jews and Muslims. France’s Jewish and Muslim communities also share a common heritage, though, and as far as one French rabbi is concerned, they are destined to be friends. From the Paris suburb of La Courneuve, Lisa Bryant reports about Rabbi Michel Serfaty and his friendship bus.
Video

Video S. Korea Christians Protest Gay Rights Festival

The U.S. Supreme Court decision mandating marriage equality nationwide has energized gay rights supporters around the world. Gay rights remain a highly contentious issue in a key U.S. ally, South Korea, where police did a deft job Sunday of preventing potential clashes between Christian protesters and gay activists. Kurt Achin reports from Seoul.
Video

Video Saudi Leaks Expose ‘Checkbook Diplomacy’ In Battle With Iran

Saudi Arabia’s willingness to wield its oil money on the global diplomatic stage appears to have been laid bare, after the website WikiLeaks published tens of thousands of leaked cables from Riyadh’s Ministry of Foreign Affairs. VOA's Henry Ridgwell reports.
Video

Video Nubians in Kenya Face Land Challenges

East Africa's ethnic Nubians have a rich cultural history that dates back thousands of years, but in Kenya they are facing hardships, including the loss of lands they have lived on for generations. They say the government has reneged on its pledge to award them title deeds for the plots. VOA's Lenny Ruvaga reports.
Video

Video Military Experts Question New Russian Tank Capabilities

Russia has been showing off its new tank design – the Armata T-14. Designers claim it is 20 years ahead of current Western designs - and driving it feels like playing a computer game. But military analysts question those assertions, and warn the cost could be too heavy a burden for Russia’s struggling economy. Henry Ridgwell reports.
Video

Video In Kenya, Police Said to Shoot First, Ask Questions Later

An organization that documents torture and extrajudicial killings says Kenyan police were responsible for 1,252 shooting deaths in five cities, including Nairobi, between 2009 and 2014, representing 67 percent of all gun deaths in the areas reviewed. Gabe Joselow has more from Nairobi.
Video

Video In Syrian Crisis, Social Media Offer Small Comforts

Za’atari, a makeshift city in Jordan, may be the only Syrian refugee camp to tweet its activities, in an effort to keep donors motivated as the war in Syria intensifies and the humanitarian crisis deepens. Inside the camp, families say mobile phone applications help hold together families that are physically torn apart. VOA’s Heather Murdock reports.

VOA Blogs