☎️💨🤯 I have found an exploit that allows every app to steal a users phone number without asking for any permissions.
I have found an exploit that allows every app to steal a user’s phone number without asking for any permissions.
This hack is made possible because of a security flaw from providers like Telekom, Vodafone, or O2.
This repository demonstrates an implementation of this hack for Deutsche Telekom. Other providers seem to have similar privacy issues, though. Feel free to submit a PR.
This is a research project! Do not use in production!
Please disconnect from WiFi in order to execute the attack.
Right now, this is only implemented with my service provider (Deutsche Telekom, Germany).
Telekom is my phone provider so they know who I am when visiting their websites (@seboslaw explained on Twitter how that works).
This is why they automatically “sign me in”. My script just grabs the information form there using a invisible web view loading a link like this: https://cap.telekom.de/auth?module=substore&subtempid=11110438&wt_mc=im_co_1842_0001_0001_1510306748 (only works from within Telekom’s cellular network).
It’s not a feature. It’s a bug.
We can definitely assume that evil apps like Facebook and Uber use this flaw already.