Its pretty easy to listen in on everything that’s going on between the cell phone and something else; a cell phone is primarily a communications devices, and the communications networks themselves are vulnerable.
Totally “powning” a cell phone — as opposed to just listening in on all its communications — is a more complex task.
It’s easier on Android phones, harder on iPhones which have not been jailbroken.
It universally involves three steps:
- Execution of arbitrary code on the phone — either through an exploit of software already on the phone, such as a web browser or the text message App — a remote exploit — or through a phishing attack or similar method of getting the user to run the code themselves
- Escalation of privilege — since most Apps run in either a sandbox, do internal sandboxing, or have an assigned “role account” which partitions their access to other parts of the phone, you have to escalate privilege in order to get out of the box and gain access to the rest of the phone
- Installation of malware — this can be as simple as a one-time program to dump the phone to an external location, or as complex as a complete rootkit that permanently enables access to the phone contents
For an Android phone or a jailbroken iPhone, for example, the easiest method is to modify the hosts file so that checks for OS and App updates go through a third party server, since the installer has to run with nearly complete privilege, and then install a root certificate that you created, so that you can decrypt all HTTPS traffic, and insert your own replacement content.
This is usually less than around 4K for the X.509 root certificate and the host redirect combined.

Comments
Post a Comment