Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,158,673 members, 7,837,483 topics. Date: Thursday, 23 May 2024 at 04:35 AM

NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones - Phones - Nairaland

Nairaland Forum / Science/Technology / Phones / NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones (21778 Views)

High Cost Of Phones In Nigeria / ### Xiaomi Thread For Tweaking Of Phones & Help Spot ### / How Long Charging Of Your Phones Destroys Phone Batteries (2) (3) (4)

(1) (2) (Reply) (Go Down)

NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by HonNL: 1:26pm On Jan 28, 2022
Press Statement

NCC-CSIRT Identifies Two Cyber Vulnerabilities


The Nigerian Communications Commission’s Cyber Security Incident Response Team (NCC-CSIRT) has independently identified two cyber vulnerabilities and advised Nigerian telecom consumers on the measures to be taken to get protected from the cyber-attacks.

The CSIRT, in its first-ever security advisories less than three months after its creation, has solely identified the two cyber-attacks targeting the consumers and proffer solutions that can help telecom consumers from falling victims to the two cyber vulnerabilities.

The first is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations and it applies to all mobile phones. The other is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.

According to CSIRT security Advisory 0001 released on January 26, 2022, with Juice Jacking, attackers have found a new way to gain unauthorized entry into unsuspecting mobile phone users devices when they charge their mobile phones at public charging stations.

Many public spaces, restaurants, malls and even in the public trains do offer complementary services to their customers in a bid to enhance customer services, one of which is providing charging ports or sockets.

However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.

Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone. This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone. The attacker can even watch the victim in real time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone's Global Positioning System (GPS) location.

When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breach in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms. Symptoms of attack may include sudden spike in battery consumption, device operating slower than usual, apps taking a long time to load, and when they load they crash frequently and cause abnormal data usage.

The NCC-CSIRT, however, proffered solutions to this attack to include using ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space; and not granting trust to portable devices prompt for USB data connection.

Other preventive measures against Juice Jacking include installing Antivirus and updating them to the latest definitions always; keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping mobile phone off when charging in public places; as well as ensuring use of one’s own charger, if one must charge in public.

On the other hand, the NCC-CSIRT Advisory 0001 of January 27, 2022, warns that Facebook for Android is vulnerable to a permission issue which gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone. The products affected include Versions 329.0.0.29.120 of Android OS.

With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.

However, to be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends to users to disable the feature from their device’s lock screen notification settings.

The NCC-CSIRT was inaugurated in October, 2021 to provide guidance and direction for the constituents in dealing with issues relating to the security of critical infrastructure in their possession, and periodically assess, review and collate the threat landscape, risks, and opportunities affecting the communications sector, in order to provide advice to relevant stakeholders in those regards.

As the telecoms-industry specific intervention, the objective of which aligns with the objective of the National Cybersecurity Policy and Strategy (NCPS) document published by the Office of the National Security Adviser (ONSA), the NCC-CSIRT ensures continuous improvement of processes and communication frameworks to guarantee secure and collaborative exchange of timely information while responding to cyber threats within the sector.

In recent times, NCC-CSIRT has raised series of cyber-vulnerability awareness based on security advisories it receives from the Nigerian Cybersecurity Emergency Response Team (ngCERT), which is the national body for the implementation of the NCPS objective. However, Juice Jacking and Facebook for Android Friend Acceptance Vulnerabilities are the two first-ever cyber vulnerabilities published by the NCC-CSIRT.

SIGNED

Dr. Ikechukwu Adinde
Director, Public Affairs

January 28,2022

Nigerian Communications Commission

11 Likes

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Muyiwaipere(m): 1:32pm On Jan 28, 2022
Una no give us light... Na still una still sat lake we no go charge outside

Abeg just tell us say make we no use phone agian

44 Likes 2 Shares

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by ItsGoodToBeGood: 1:53pm On Jan 28, 2022
Other preventive measures against Juice
Jacking include installing Antivirus and
updating them to the latest definitions
always; keeping mobile devices up to
date with the latest patches; using one’s
own power bank; keeping mobile
phone off when charging in public
places; as well as ensuring use of one’s
own charger, if one must charge in
public.





There is always a solution,, they did well by keeping us informed. Kudos to them

47 Likes 4 Shares

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by gistray: 2:20pm On Jan 28, 2022
After spending Billions


This is the best they could come up with


Idiots

20 Likes 5 Shares

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Nbotee(m): 2:21pm On Jan 28, 2022
Mtcheeeeew
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by richiemcgold: 6:19pm On Jan 28, 2022
public charging of phones have many disadvantages, but I don't think it could lead to more cyber vulnerabilities than Facebook friend request.
Many people are just too careless with the way they confirm all friend requests from every Tom, dick and harry on Facebook. This is very dangerous.

Ournolly:

Please what are the vulnerability in the Facebook friends requests?

answer to your question is already in the report. You haven't read it all I guess.

18 Likes 3 Shares

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Nobody: 6:38pm On Jan 28, 2022
Mtcheew
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by donpapa(m): 7:10pm On Jan 28, 2022
Ok
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by slawormiir: 7:10pm On Jan 28, 2022
Damnnn niggar
Isoright
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Mophor: 7:10pm On Jan 28, 2022
Issokay!!!
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by jericco1(m): 7:10pm On Jan 28, 2022
Interesting.

With the power situation, most people charge their phones publicly.
People need to be extra vigilant and careful.

4 Likes

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Emuforlife1: 7:11pm On Jan 28, 2022
Let the Minister of Communication handle it, shebi he is a Professor of Cyber Security?

1 Like 1 Share

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by RichDad1(m): 7:11pm On Jan 28, 2022
This is no news. They should look for something groundbreaking.

1 Like

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by biroo: 7:11pm On Jan 28, 2022
Okay, see where constant electric supply would have come in handy now, or make I just buy Pova so that I go dey charge my phone once in 4 days?

3 Likes 1 Share

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by talk2hb1(m): 7:12pm On Jan 28, 2022
Fenks, Noted
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Sonnobax15(m): 7:13pm On Jan 28, 2022
lipsrsealed
If no be say our Nepa (BEDC) dey kolo for their heads normally before,na wetin for dey carry our legs dey go charge our phones for public charge-and-pay station undecided

2 Likes

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Qwerty4u(m): 7:15pm On Jan 28, 2022
Jukwese before you charge
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by Adewale1603(m): 7:15pm On Jan 28, 2022
not for naija
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by nairaman66(m): 7:16pm On Jan 28, 2022
NCC must have smoked hot pot! When do we have public phone charging centers in Nigeria ?

1 Like

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by teejayreal(m): 7:17pm On Jan 28, 2022
NCC dey yarn dust. As NEPA no bring light. Make I no charge my phone again.
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by mamoh35126: 7:19pm On Jan 28, 2022
All this ncc dy mad ah swr
Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by izzy4shizzy(m): 7:19pm On Jan 28, 2022
The whole thing sounds useful and still sounds useless at the same time

3 Likes

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by princeemmma(m): 7:20pm On Jan 28, 2022
It is in Nigeria you will see someone living in House no 9, peeking hear up and down if house no 24 has turn on their generator.................... Una don hear am now

2 Likes 2 Shares

Re: NCC Identifies 2 Cyber Vulnerabilities, Warns Against Public Charging Of Phones by faithfull18(f): 7:21pm On Jan 28, 2022
Using free public WiFi exposes you as well, come and buy data, free things aren't always free in the real sense of it.

(1) (2) (Reply)

My Data Wasted Away Without Me Using It. / Lollipop Rom For All Devices. Inc Mtk Devices. / Tecno P9, Tecno S5, & D9 Released For Christmas

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 70
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.