The Nigerian Communications Commission’s Cyber Security Incident Response Team (NCC-CSIRT) has solely identified the two cyber-attacks targeting the consumers.
This was revealed in CSIRT security Advisory 0001 released on January 26, 2022.
In the advisory, The NCC-CSIRT which was inaugurated in October 2021 also gave proffer solutions that can help telecom consumers from falling victims to the two cyber vulnerabilities.
The first cyber-attack is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations This applies to all mobile phones.
As you may know, many public spaces, restaurants, malls and even public trains do offer complementary services to their customers in a bid to enhance customer services.
One of these services includes providing charging ports or sockets.
However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.
Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone.
This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone.
The attacker can even watch the victim in real-time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone’s Global Positioning System (GPS) location.
When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breaches in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms.
Symptoms of attack may include a sudden spike in battery consumption, devices operating slower than usual, apps taking a long time to load, and when they load they crash frequently and cause abnormal data usage.
The second is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.
The NCC-CSIRT warns that Facebook for Android is vulnerable to a permission issue that gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone. The products affected include Versions 329.0.0.29.120 of Android OS.
With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.
Providing solutions to this, CSIRT revealed that one has to use ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space, and not granting trust to portable devices prompt for USB data connection.
Other preventive measures against Juice Jacking include installing Antivirus and updating them to the latest definitions always.
Also, you can prevent it by keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping a mobile phone off when charging in public places; as well as ensuring the use of one’s own charger, if one must charge in public.
To be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends that users should disable the feature from their device’s lock screen notification settings.
This is NCC-CSIRT’s first-ever security advisories less than three months after its creation.
Credit: Daily Post
ALSO READ: REVEALED: How Buhari’s govt squandered $550billion it inherited from PDP in 2015