Bypassing voice encryption on cell phones (including CryptoPhone)

From: Eric Schmiedl <eric.s..._at_gmail.com>
Date: Thu, 28 Jan 2010 20:30:55 -0500

http://infosecurityguard.com/?p=26

"I installed FlexiSpy on the cryptophone and would later call it from my
3rd party phone to activate the listening mode. (Again, the user has no
idea). FlexiSpy silently picks up my phone call and allows me to
eavesdrop undetected. If the user has a call in progress (even if it is
encrypted!), I am able to hear anything being said into the microphone.

[...]

on my own Trojan I was able to resolve this, and was able to capture
the conversation in full duplex even with an encrypted call in progress.

Rohde & Schwarz (TopSec) & PhoneCrypt successfully blocked these attacks
as their architecture prevented the attack.
[...] PhoneCrypt actually alerted me when it detected my Trojan and
FlexiSpy respectively which was pretty cool."

Full table of tested products:
http://infosecurityguard.com/?p=28
Received on Sat Mar 02 2024 - 00:57:27 CST

This archive was generated by hypermail 2.3.0 : Sat Mar 02 2024 - 01:11:46 CST