Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Using a whatsapp vulnerability for profiling individuals

: Kurowski, Sebastian

Hühnlein, Detlef (Ed.); Roßnagel, Heiko (Ed.) ; Gesellschaft für Informatik -GI-, Bonn:
Open Identity Summit 2014 : 04. - 06.11.2014 in Stuttgart, Germany
Bonn: GI, 2014 (GI-Edition - Lecture Notes in Informatics (LNI) - Proceedings 237)
ISBN: 978-3-88579-631-2
Open Identity Summit <2014, Stuttgart>
Fraunhofer IAO ()

This paper aims at raising awareness on the issue of unfixed vulnerabilities for targeted attacks in order to harness private or even corporate information. We demonstrate an attack by using a well-known, yet not fixed whatsapp vulnerability, enabling us to eavesdrop the cell-phone number of a victim. We identified the concrete states, in which whatsapp leaks the cell-phone number of a victim. By using a volunteering individual, we demonstrate the feasibility of profiling the individual and provide further steps on how to disclose private and corporate information by using the leaked cell-phone number and the profiled information to introduce the adversary into a trust relationship with the victim. One the victim trusts the adversary, social phishing can be used to retrieve further private or even corporate information.