News / Science & Technology

Researchers Hack Verizon Device, Turn it Into Mobile Spy Station

A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
Reuters

Two security experts said they have figured out how to spy on Verizon Wireless mobile phone customers by hacking into devices the U.S. carrier sells to boost wireless signals indoors.
 

The finding, which the experts demonstrated to Reuters and will further detail at two hacking conferences this summer, comes at a time of intense global debate about electronic privacy, after top-secret U.S. surveillance programs were leaked by a former National Security Agency contractor, Edward Snowden, last month.

"This is not about how the NSA would attack ordinary people. This is about how ordinary people would attack ordinary people,'' said Tom Ritter, a senior consultant with the security firm iSEC Partners.
 

Verizon said it has updated the software on its signal-boosting devices, known as femtocells or network extenders, to prevent hackers from copying the technique of the two experts.
 

But Ritter said motivated hackers can still find other ways to hack the femtocells of Verizon, as well as those offered by some 30 carriers worldwide to their customers.

Femtocells, which act as tiny cellphone towers, can be purchased directly from Verizon for $250. Used models can be obtained online for about $150.  Ritter and his colleague, Doug DePerry, demonstrated for Reuters how they can eavesdrop on text messages, photos and phone calls made with an Android phone and an iPhone by using a Verizon femtocell that they had previously hacked.
 

They declined to disclose how they had modified the software on the device, saying they do not want to make it any easier for criminals to figure out similar ways to hack femtocells.

   
The two said they plan to give more elaborate demonstrations wo weeks from now at the Black Hat and Def Con hacking conferences in Las Vegas. More than 15,000 security professionals and hackers are expected to attend those conferences, which feature talks on newly found bugs in communications systems, smart TVs, mobile devices and computers that run facilities from factories to oil rigs.

 

Verizon Wireless released a Linux software update in March that prevents its network extenders from being compromised in the manner reported by Ritter and DePerry, according to company spokesman David Samberg.

"The Verizon Wireless Network Extender remains a very secure and effective solution for our customers,'' Samberg said in a statement. He said there have been no reports of customers being impacted by the bug that the researchers had identified. The company is a joint venture between Verizon Communications Inc and Vodafone Group Plc.

 

Samberg said his company uses an internal security team as well as outside firms to look for vulnerabilities in the devices it sells, before and after they are released.

   
Still, the two researchers said they are able to use the hacked femtocell to spy on Verizon phones even after Verizon released that update because they had modified the device before the company pushed out the software fix.


The researchers built their "proof of concept'' system that they will demonstrate in Las Vegas with femtocells manufactured by Samsung Electronics Co and a $50 antenna from Wilson Electronics Inc.
 

They said that with a little more work, they could have weaponized it for stealth attacks by packaging all equipment needed for a surveillance operation into a backpack that could be dropped near a target they wanted to monitor.

   
For example, a group interested in potential mergers might place such a backpack in Manhattan restaurants frequented by investment bankers. Verizon's website said the device has a 40-foot range, but the researchers believe that could be expanded by adding specialized antennas.
 

The iSEC researchers are not the first to warn of vulnerabilities in femtocells, but claim to be the first to hack the femtocells of a U.S. carrier and also the first running on a wireless standard known as CDMA. Other hacking experts have previously uncovered security bugs in femtocells used by carriers in Europe.

   
CTIA, a wireless industry group based in Washington, in February released a report that identified femtocells as a potential point of attack. John Marinho, CTIA's vice president for cybersecurity and Technology, said that the group is more concerned about other potential cyber threats, such as malicious apps. He is not aware of anycase where attacks were launched via femtocells.
 

Still, he said, the industry is monitoring the issue: "Threats change every day.''

 

You May Like

Cambodia Seeks Official UN Maps for Vietnam Border

Notice of request comes as 2 countries open border talks Tuesday after a clash last month More

From South Africa to Vietnam, Cyclists Deliver Message Against Rhino Horns

Appalled by poaching they saw firsthand, sisters embark on tour to raise awareness in countries where rhino horn products are in demand More

Uber Wants Johannesburg Police Protection

Request follows recent protests outside ride-hailing service's Johannesburg office More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Getting it Done Beyond a Nuclear Deali
X
July 07, 2015 12:02 PM
If a nuclear deal is reached between Iran and world powers in Vienna, it will be a highly technical road map to be used to monitor nuclear activity in Iran for years to come to ensure Tehran does not make nuclear weapons. Equally as complicated will be dismantling international sanctions that were originally intended to be ironclad. VOA’s Heather Murdock talks to experts about the key challenges any deal will present.
Video

Video Getting it Done Beyond a Nuclear Deal

If a nuclear deal is reached between Iran and world powers in Vienna, it will be a highly technical road map to be used to monitor nuclear activity in Iran for years to come to ensure Tehran does not make nuclear weapons. Equally as complicated will be dismantling international sanctions that were originally intended to be ironclad. VOA’s Heather Murdock talks to experts about the key challenges any deal will present.
Video

Video Rice Farmers Frustrated As Drought Grips Thailand

A severe drought in Thailand is limiting the growing season of the country’s important rice crop. Farmers are blaming the government for not doing more to protect a key export. Steve Sandford reports from Chiang Mai, Thailand.
Video

Video Making Music, Fleeing Bombs: New Film on Sudan’s Internal Refugees

In 2012, Sudanese filmmaker Hajooj Kuka went to make a documentary among civil war refugees in Sudan’s Blue Nile and Nuba Mountains region. What he found surprised him: music was helping to save people from bombing raids by their own government. VOA’s Carolyn Weaver has more.
Video

Video 'From This Day Forward' Reveals Difficult Journey of Transgender Parent

In her documentary, "From This Day Forward", filmmaker Sharon Shattuck reveals the personal journey of her transgender father, as he told his family that he always felt he was a woman inside and decided to live as one. VOA’s Penelope Poulou has more.
Video

Video Floodwaters Threaten Iconic American Home

The Farnsworth House in the Midwest State of Illinois is one of the most iconic homes in America. Thousands of tourists visit the site every year. Its location near a river inspired the design of the house, but, as VOA’s Kane Farabaugh reports, that very location is now threatening the existence of this National Historic Landmark.
Video

Video Olympics Construction Scars Sacred Korean Mountain

Environmentalists in South Korea are protesting a Winter Olympics construction project to build a ski slope through a 500-year-old protected forest. Brian Padden reports that although there is strong national support for hosting the 2018 Pyeongchang Winter Olympics, there are growing public concerns over the costs and possible ecological damage at the revered mountain.
Video

Video Xenophobia Victims in South Africa Flee Violence, Then Return

Many Malawians fled South Africa early this year after xenophobic attacks on African immigrants. But many quickly found life was no better at home and have returned to South Africa – often illegally and without jobs, and facing the tough task of having to start over. Lameck Masina and Anita Powell file from Johannesburg.
Video

Video Family of American Marine Calls for Release From Iranian Prison

As the crowd of journalists covering the Iran talks swells, so too do the opportunities for media coverage.  Hoping to catch the attention of high-level diplomats, the family of American-Iranian marine Amir Hekmati is in Vienna, pleading for his release from an Iranian prison after nearly 4 years.  VOA’s Heather Murdock reports from Vienna.
Video

Video UK Holds Terror Drill as MPs Mull Tunisia Response

After pledging a tough response to last Friday’s terror attack in Tunisia, which came just days before the 10th anniversary of the bomb attacks on London’s transport network, British security services are shifting their focus to overseas counter-terror operations. VOA's Henry Ridgwell has more.
Video

Video Obama on Cuba: This is What Change Looks Like

President Barack Obama says the United States will soon reopen its embassy in Cuba for the first time since 1961, ending a half-century of isolation. VOA White House correspondent Luis Ramirez reports.
Video

Video Hate Groups Spread Influence Via Internet

Hate groups of various kinds are using the Internet for propaganda and recruitment, and a Jewish human rights organization that monitors these groups, the Simon Wiesenthal Center, says their influence is growing. The messages are different, but the calls to hatred or violence are similar. VOA's Mike O’Sullivan reports.
Video

Video Blind Somali Journalist Defies Odds in Mogadishu

Despite improving security in the last few years, Somalia remains one of the most dangerous countries to be a journalist – even more so for someone who cannot see. Abdulaziz Billow has the story of journalist Abdifatah Hassan Kalgacal, who has been reporting from the Somali capital for the last decade despite being blind.

VOA Blogs