Search Whitehat Blog

Friday, 30 January 2015

Safaricom Leaked Data Bundles Frauds.

Safaricom, Ltd is a leading mobile network operator in Kenya.It provides telecommunication services including cellular network provision , internet services to homes and offices, mobile banking and others.

Safaricom provides internet data to its mobile subscribers. In this way ,as a carrier user, you purchase your data bundle through credit cards , online services, the mobile banking service dubbed M-pesa or get subscriptions depending on your plan.

This telecommunication company is one of the most preferred providers by the citizens and covers most of the countries network system.

Cause of the blunder.

Late in 2014 and early this year , Safaricom sold out some brands of mobile phones and smartphones in their outlets and care centers,e.g Samsung , Nokia ,Techno and Alcatel includes others . This kind of purchase was given out with customers promotions of free airtime and data bundles. Before customers were given this promotions , they used their purchased mobiles EMEI numbers to verify grants of promotions.

Concept of the fraud.

This is where everything become a fraud, technology enthusiasts thought further and dug out how the mobile brand suppliers generate their EMEI  numbers. They then used one valid EMEI address from the vendor to calculate and generate EMEI addresses of corresponding mobile phone produced at a particular time . This mobile brands manufacturers may have sold out this phones in bulk and this made every EMEI calculation SUCCESSFUL.

Fraud Accelerated.

When the fraudsters had identified the formula to generate this EMEI  addresses , an android application was written to ease out  calculations and this turned alarming to Safaricom.

The Theory Behind. (Formula)

The formula that is used by most mobile manufacturers to assign EMEI addresses to every devise is called The Luhn algorithm or Luhn formula . 
As summarized bellow , it is used to generate a code that exits in an encrypted sequence.


PICTURE CREDIT: GOOGLE.COM



Tuesday, 21 October 2014

System on a chip (SoC)

This is really interesting, a small component that executes multiple tasks in an intelligent procedure.An SOC is simply a micro controller mostly used in smartphones.

 
(SOC - On fingers)

In reference to Wiki, A system on a chip or system on chip (SoC or SOC) is an integrated circuit (IC) that integrates all components of a computer or other electronic system into a single chip.

 It may contain digital, analog, mixed-signal, and often radio-frequency functions all on a single chip substrate. SoCs are very common in the mobile electronics market because of their low power consumption. A typical application is in the area of embedded systems.

What makes me curious on this issue is the design and the know how that requires one to make a system of such intelligence and capability.The following is an over view of its interior with functions.



This processors are widely known by the following brands
  • Intel
  • AMD
  • Qualcomm
  • Mediatek etc.