News / Science & Technology

Researchers Hack Verizon Device, Turn it Into Mobile Spy Station

A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
A cell phone user passes a Verizon store in New York in this April 27, 2006 file photo.
Reuters

Two security experts said they have figured out how to spy on Verizon Wireless mobile phone customers by hacking into devices the U.S. carrier sells to boost wireless signals indoors.
 

The finding, which the experts demonstrated to Reuters and will further detail at two hacking conferences this summer, comes at a time of intense global debate about electronic privacy, after top-secret U.S. surveillance programs were leaked by a former National Security Agency contractor, Edward Snowden, last month.

"This is not about how the NSA would attack ordinary people. This is about how ordinary people would attack ordinary people,'' said Tom Ritter, a senior consultant with the security firm iSEC Partners.
 

Verizon said it has updated the software on its signal-boosting devices, known as femtocells or network extenders, to prevent hackers from copying the technique of the two experts.
 

But Ritter said motivated hackers can still find other ways to hack the femtocells of Verizon, as well as those offered by some 30 carriers worldwide to their customers.

Femtocells, which act as tiny cellphone towers, can be purchased directly from Verizon for $250. Used models can be obtained online for about $150.  Ritter and his colleague, Doug DePerry, demonstrated for Reuters how they can eavesdrop on text messages, photos and phone calls made with an Android phone and an iPhone by using a Verizon femtocell that they had previously hacked.
 

They declined to disclose how they had modified the software on the device, saying they do not want to make it any easier for criminals to figure out similar ways to hack femtocells.

   
The two said they plan to give more elaborate demonstrations wo weeks from now at the Black Hat and Def Con hacking conferences in Las Vegas. More than 15,000 security professionals and hackers are expected to attend those conferences, which feature talks on newly found bugs in communications systems, smart TVs, mobile devices and computers that run facilities from factories to oil rigs.

 

Verizon Wireless released a Linux software update in March that prevents its network extenders from being compromised in the manner reported by Ritter and DePerry, according to company spokesman David Samberg.

"The Verizon Wireless Network Extender remains a very secure and effective solution for our customers,'' Samberg said in a statement. He said there have been no reports of customers being impacted by the bug that the researchers had identified. The company is a joint venture between Verizon Communications Inc and Vodafone Group Plc.

 

Samberg said his company uses an internal security team as well as outside firms to look for vulnerabilities in the devices it sells, before and after they are released.

   
Still, the two researchers said they are able to use the hacked femtocell to spy on Verizon phones even after Verizon released that update because they had modified the device before the company pushed out the software fix.


The researchers built their "proof of concept'' system that they will demonstrate in Las Vegas with femtocells manufactured by Samsung Electronics Co and a $50 antenna from Wilson Electronics Inc.
 

They said that with a little more work, they could have weaponized it for stealth attacks by packaging all equipment needed for a surveillance operation into a backpack that could be dropped near a target they wanted to monitor.

   
For example, a group interested in potential mergers might place such a backpack in Manhattan restaurants frequented by investment bankers. Verizon's website said the device has a 40-foot range, but the researchers believe that could be expanded by adding specialized antennas.
 

The iSEC researchers are not the first to warn of vulnerabilities in femtocells, but claim to be the first to hack the femtocells of a U.S. carrier and also the first running on a wireless standard known as CDMA. Other hacking experts have previously uncovered security bugs in femtocells used by carriers in Europe.

   
CTIA, a wireless industry group based in Washington, in February released a report that identified femtocells as a potential point of attack. John Marinho, CTIA's vice president for cybersecurity and Technology, said that the group is more concerned about other potential cyber threats, such as malicious apps. He is not aware of anycase where attacks were launched via femtocells.
 

Still, he said, the industry is monitoring the issue: "Threats change every day.''

 

You May Like

Photogallery Obama Announces Plan to Send 3,000 Troops to Liberia in Ebola Fight

At US Centers for Disease Control and Prevention, Obama details troop deployment and other pieces of US plan More

China Muslims Work to Change Perceptions After Knife Attacks

Muslims in Kunming say that they condemn the violence, it is not a reflection of the true beliefs of their faith More

Humanitarian Aid, Equipment Blocked in Cameroon

Move is seen as a developing supply crisis in West Africa More

Featured Videos

Your JavaScript is turned off or you have an old version of Adobe's Flash Player. Get the latest Flash player.
Enviropreneur Seeks to Save the Environment, Empower the Communityi
X
September 16, 2014 2:06 PM
Lorna Rutto, a former banker, is now an ‘enviropreneur’ - turning plastic waste into furniture and fences discusses the challenges she faces in Africa with raw materials and the environment.
Video

Video Enviropreneur Seeks to Save the Environment, Empower the Community

Lorna Rutto, a former banker, is now an ‘enviropreneur’ - turning plastic waste into furniture and fences discusses the challenges she faces in Africa with raw materials and the environment.
Video

Video West Trades Accusations Over Ransoms

As world leaders try to forge a common response to the threat posed by Islamic State militants in Iraq and Syria, there is simmering tension over differing policies on paying ransoms. In the past month, the jihadist group has beheaded two Americans and one Briton. Both countries refuse to pay ransom money. As Henry Ridgwell reports for VOA from London, there is uncertainty in the approach of some other European nations.
Video

Video Scotland Independence Bid Stokes Global Interest

The people of Scotland are preparing to vote on whether to become independent and break away from the rest of Britain, in a referendum being watched carefully in many other countries. Some see it as a risky experiment; while others hope a successful vote for independence might energize their own separatist demands. Foreign immigrants to Scotland have a front row seat for the vote. VOA’s Henry Ridgwell spoke to some of them in Edinburgh.
Video

Video Washington DC Mural Artists Help Beautify City

Like many cities, Washington has a graffiti problem. Buildings and homes, especially in low-income neighborhoods, are often targets of illegal artwork. But as we hear from VOA’s Julie Taboh, officials in the nation's capital have come up with an innovative program that uses the talents of local artists to beautify the city.
Video

Video US Muslim Leaders Condemn Islamic State

Leaders of America's Muslim community are condemning the violent extremism of the Islamic State group in Iraq and Syria. The U.S. Muslim leaders say militants are exploiting their faith in a failed effort to justify violent extremism. VOA correspondent Meredith Buel reports.
Video

Video Americans' Reaction Mixed on Obama Strategy for Islamic State Militants

President Barack Obama’s televised speech on how the United States plans to “degrade and destroy” the group known as the Islamic State reached a prime-time audience of millions. And it came as Americans appear more willing to embrace a bolder, tougher approach to foreign policy. VOA producer Katherine Gypson and reporter Jeff Seldin have this report from Washington.
Video

Video Authorities Allege LA Fashion Industry-Cartel Ties

U.S. officials say they have broken up crime rings that funneled tens of millions of dollars from Mexican drug cartels through fashion businesses in Los Angeles. Mike O'Sullivan reports that authorities announced nine arrests, as 1,000 law enforcement agents fanned out through the city on Wednesday.
Video

Video Bedouin Woman Runs Successful Business in Palestinian City

A Bedouin woman is breaking social taboos by running a successful vacation resort in the Palestinian town of Jericho. Bedouins are a sub-group of Arabs known for their semi-nomadic lifestyle. Zlatica Hoke says the resort in the West Bank's Jordan Valley is a model of success for women in the region.


Carnage and mayhem are part of daily life in northern Nigeria, the result of a terror campaign by the Islamist group Boko Haram. Fears are growing that Nigeria’s government may not know how to counter it, and may be making things worse. More

AppleAndroid