Sunday, May 22, 2022
No Result
View All Result
Donate
Sandra Talk Show
  • HOME
  • BROWSEHOT
    • LATEST
    • TRENDING
    • NEWSHot
  • LIVE TVNEW
  • VIDEOS
  • ENTERTAINMENTNEW
  • FEATURES
  • OTHER
    • ADVERTISE
    • PRIVACY POLICY
No Result
View All Result
Sandra Talk Show
Home Browse

NCC warns against charging phones in trains, restaurants and other public places

4 months ago
in Browse
A A
0
Share on FacebookShare on Twitter
ADVERTISEMENT

The Nigerian Communications Commission (NCC) has warned Nigerians about a newly discovered cyberattacks on Android devices in public places.

The commission, through its Cyber Security Incident Response Team (CSIRT), identified vulnerabilities that hackers use in gaining unauthorised access into smartphones at public charging stations.

The first is described as Juice Jacking, which can gain access into consumers’ devices when charging mobile phones at public charging stations and it applies to all mobile phones. The other is a Facebook for Android Friend Acceptance Vulnerability, which targets only Android Operating System.

In the CSIRT security Advisory 0001, it was noted that with Juice Jacking gives attackers channels to gain unauthorized entry into unsuspecting mobile phone users’ devices when they charge their mobile phones at public charging stations.

Many public spaces, restaurants, malls and even in the public trains do offer complementary services to their customers in a bid to enhance customer services, one of which is providing charging ports or sockets. However, an attacker can leverage this courtesy to load a payload in the charging station or on the cables they would leave plugged in at the stations.

Once unsuspecting persons plug their phones at the charging station or the cable left by the attacker, the payload is automatically downloaded on the victims’ phone. This payload then gives the attacker remote access to the mobile phone, allowing them to monitor data transmitted as text, or audio using the microphone.

The attacker can also watch the victim in real time if the victims’ camera is not covered. The attacker is also given full access to the gallery and also to the phone’s Global Positioning System (GPS) location.

When an attacker gains access to a user’s Mobile phone, he gets remote access to the User’s phone which leads to breach in Confidentiality, Violation of Data Integrity and bypass of Authentication Mechanisms. Symptoms of attack may include sudden spike in battery consumption, device operating slower than usual, apps taking a long time to load, and when they load they crash frequently and cause abnormal data usage.

The NCC-CSIRT, however, proffered solutions to this attack to include using ‘charging only USB cable’, to avoid Universal Serial Bus (USB) data connection; using one’s AC charging adaptor in public space; and not granting trust to portable devices prompt for USB data connection.

Other preventive measures against Juice Jacking include installing Antivirus and updating them to the latest definitions always; keeping mobile devices up to date with the latest patches; using one’s own power bank; keeping mobile phone off when charging in public places; as well as ensuring use of one’s own charger, if one must charge in public.

The NCC-CSIRT Advisory 0001 also warned that Facebook for Android is vulnerable to a permission issue which gives privilege to anyone with physical access to the android device to accept friend requests without unlocking the phone. The products affected include Versions 329.0.0.29.120 of Android OS.

With this, the attacker will be able to add the victim as a friend and collect personal information of the victim, such as Email, Date of Birth, Check-ins, Mobile phone number, Address, Pictures and other information that the victim may have shared, which would only be visible to his/her friends.

To be protected from the Facebook-associated vulnerability, NCC-CSIRT in the security advisory recommends to users to disable the feature from their device’s lock screen notification settings.

The NCC-CSIRT was inaugurated in October, 2021 to provide guidance and direction for the constituents in dealing with issues relating to the security of critical infrastructure in their possession, and periodically assess, review and collate the threat landscape, risks, and opportunities affecting the communications sector, in order to provide advice to relevant stakeholders in those regards.

Tobiloba Ayinde

RelatedPosts

Classmate of Blossom Chukwujekwu’s new wife defends her age and body size

23 hours ago

Davido’s Baby Mama Chioma Wows Many As She Joins The ‘Low-Cut Gang’

23 hours ago

Nigerian Railway Corporation cancels resumption of Abuja-Kaduna train service

24 hours ago

Alleged Blasphemy: Mob overpowered DSS operatives who tried to save Deborah Samuel – Gov Tambuwal

1 day ago

Drama As Actress Kemi Apesin Acts As Hook Up Client To Nab Online Troll Who Bashed Her

4 weeks ago

‘I can’t forget how you stood for me when someone didn’t want to work with me’-Toyin Abraham celebrates Ini Edo’s 40th birthday

4 weeks ago

“You are a bully , always been and always will be, you derive joy from the pains of other women” – Caroline Danjuma drags Linda Ikeji yet again

4 weeks ago

Nnamdi Kanu’s American lawyer drags Malami, Justice Nyako, Buhari before International Criminal Court

1 month ago

Not All Relationships End Because The Man Left – Ehi Ogbehor Weighs In Nkechi Blessing’s Saga Cites Herself As An Example

1 month ago

Kourtney Kardashian shares behind-the-scenes photos from her Las Vegas wedding to Travis Barker

1 month ago
Load More
Share130Tweet81SendShareShare
Subscribe
Connect with
Login
I allow to create an account
When you login first time using a Social Login button, we collect your account public profile information shared by Social Login provider, based on your privacy settings. We also get your email address to automatically create an account for you in our website. Once your account is created, you'll be logged-in to this account.
DisagreeAgree
Notify of
guest
Rate
I allow to create an account
When you login first time using a Social Login button, we collect your account public profile information shared by Social Login provider, based on your privacy settings. We also get your email address to automatically create an account for you in our website. Once your account is created, you'll be logged-in to this account.
DisagreeAgree
guest
0 Comments
Inline Feedbacks
View all comments
  • Contact

© 2021 Sandra Talk Show.

No Result
View All Result
  • HOME
  • BROWSE
    • LATEST
    • TRENDING
    • NEWS
  • LIVE TV
  • VIDEOS
  • ENTERTAINMENT
  • FEATURES
  • OTHER
    • ADVERTISE
    • PRIVACY POLICY
  • Login
  • Sign Up

© 2021 Sandra Talk Show.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.Accept