170 likes | 383 Views
CELLFOR Social Footprint Analyzer Ben McGee, CISSP, CEH, MCTS DIGITAL FORENSICs. Mobile Threat Model Attack Tree. Corporate. Sms, Data, Voice. VPN. GPS RADIO SENSORS OS MICROPHONE CAMERA. TAKE IT TO THE CLOUD!. Experiment - This is Bob. Recon. 1 – Target Recon & Footprinting.
E N D
CELLFOR Social Footprint AnalyzerBen McGee, CISSP, CEH, MCTSDIGITAL FORENSICs
Mobile Threat ModelAttack Tree Corporate Sms, Data, Voice VPN GPS RADIO SENSORSOS MICROPHONE CAMERA
Recon 1 – Target Recon & Footprinting 2 – Ask Dr. Google 3 - OSINT 4 – Social Engineering
Clear! Corporate Emails Images Intellectual Property / Documents Contacts, Text Messages, Personal Email contact records: select data1 from data; -- /data/data/com.android.providers.contacts/databases/contacts.db sms/mms records: select address, date, body from sms; -- /data/data/com.android.providers.telephony/mmssms.db calendar records: select title, eventLocation, description, dtstart, dtend, eventTimezone from events; -- /data/data/ mail messages (gmail only?): select * from blah; -- /data/data/com.motorola.motoemail/databases/EmailProvider.db
Oh and the Social Network….. Graph it !!
Recommendations • Have a corporate policy for using personal cell phones for corporate business • Invest in good ‘DoD’ level wipe of phone • Store on to SD Card, not the HD of device • Encrypt your device • Use proximity virtual machines within Device • Work | Home | School • Buy a good wood chipper ?