SlideShare a Scribd company logo
1 of 71
Download to read offline
GONE
•    Senior Security Consultant, SecureState	

•    Founder of SocialMediaSecurity.com	

•    Facebook Privacy & Security Guide	

•    Blogger	

•    Co-host of Security Justice, Social Media
     Security Podcasts
•    Security Consultant, Secure Ideas	

•    Author Sec542 from SANS	

•    Instructor of the SamuraiWTF class	

•    SANS Internet Storm Center Handler	

•    Project lead for:	

     –  SamuraiWTF	

     –  Yokoso!	

     –  Laudanum	

     –  WeaponizedFlash
•  Location Based Services are exactly that	

•  Services that provide your location to others	

  –  Be them friends or companies that want to know	

•  These services can be built into our devices
   and software or programs we sign up for	

  –  Can tell where we are or where we aren’t
Chart: Gigaom.com
The market for location-based
services on mobile phones will
be worth about 
$3 billion in 2013…
	

      -Frost and Sullivan (Market Research Firm)
•  The original way of performing geo-location
   checks	

•  Determined through ISP lookups and whois
   records	

•  Prone to misleading results	

  –  Due to ISP location being reported	

•  Popular with Banners/Adult Advertising
•  Researchers	
  have	
  found	
  new	
  ways	
  to	
  get	
  
   closer	
  results	
  via	
  IP	
  address	
  
•  Typical	
  results	
  used	
  to	
  get	
  you	
  within	
  200	
  
   kilometers	
  (me	
  based)	
  
•  Now	
  within	
  a	
  few	
  hundred	
  meters!	
  
•  Creates	
  new	
  ways	
  for	
  adversers	
  and	
  the	
  
   government	
  to	
  track	
  you	
  J	
  
•  Using	
  proxy’s	
  seem	
  to	
  help…but	
  who	
  controls	
  
   these?	
  
•  GPS in the mobile device was 
   revolutionary	

  –  Users have embraced it	

•  We have our phone with us everywhere	

•  Ability to use web based tech with the mobile
   GPS has changed the way we use phones!	

  –  Mash-ups for the win!
•    GPS	

•    WiFi	

•    Bluetooth	

•    RFID	

•    3G/EDGE, CDMA, GSM	

•    We pack our phones with	

      latest wireless tech…
•    IP address	

•    RFID	

•    WiFi and Bluetooth MAC addresses	

•    GSM/CDMA cell IDs	

•    Manual user input
•  Service Examples:	

   –  Google Location Services	

      •  Cell Tower 	

      •  Wifi based	

   –  Skyhook/Loki	

      •  Wifi based
•  Many new providers of Geolocation data	

•  Skyhook	

•  SimpleGeo (working on Geofences)
•  Yes, its scary and has been around for a few
   years	

•  Your phone determines if you are in a location
   or not	

•  iOS4 already supports background geo	

•  SimpleGeo can do this in 6 lines of code	

•  30 lines to support background geo tracking on
   iOS4
“So you basically just say, Track User and we handle
that in our API along with record history. 
       I can then come back and say, Show me the last 10
places the user was , Stump continues...	

   
       Creepy? Sort of. Powerful and easy? Yes. 
	

          - TechCrunch Interview w/SocialGeo co-founder Joe Stump
•  Firefox ( 3.5 uses Google) 	

•  Opera (nightly build uses
   Skyhook)	

•  Safari (uses Skyhook in
   iPhone/iPad)	

•  Chrome (uses Google)	

•  Internet Explorer 9 
   (HTML5-based)
Geolocation is not standardized…yet.	

•  Follow the Geolocation developer mailing
   list...it s fun!	


  – http://www.w3.org/2008/geolocation/
•  How will developers use this?	

•  W3C Geolocation API	

•  Code is easy to manipulate for evil
   things
•  Now available in Safari, Opera and
   Chrome	

•  The Evercookie (Samy Kamkar)	

•  Store and track your locations as well
FourSquare/Gowalla	





•  These games are supposed to be fun,
   right?
•  Opt in by default	

•  Built into the API	

•  Forgotten by 	

   many users…
•  We 3 Google	

•  Tracks your location history	

•  How many use the same password for all sites?
•  600 Million Users all
   sharing locations…	

•  Kevin loves this
•  Barcode Hero? 
   Yeah seriously…
QR Codes
Rebecca	
  Rolled?	
  
•    Geolocation DoS	

•    Randomly generate SSIDs	

•    Fake SSID flood	

•    Hardware jamming
•  2008 Research by
   Students from ETH
   Zurich	

•  AP Impersonation	

•  WLAN Jamming	

•  SkyHook DoS
•  [Disclaimer] These are
   illegal!	

•  Easy to buy overseas
•  hIp://ilektrojohn.github.com/creepy/	
  
•  Geolocation stalking tool!	

•  Works on Windows and Linux
•  Sniff and Spoof (Man-in-the-Middle Attacks)	

•  Or…just use FireSheep and hijack the
   account for location data	

•  Fun at conferences and hotels ;-)
•  Proxies	

•  Tor (still slow)	

•  Moxie Marlinspike s GoogleSharing
    creates interesting possibilities
•  Blackberry	

•  iPhone	

•  Android
•  Fake Location App (iPhone/Android)	

•  Geolocater Firefox Plugin	

•  Manually manipulate Firefox, use
   touch.facebook.com
•  FourSquare gaming
   the system 	

•  Lots of scripts,
   programs to do
   this…even a
   Metasploit module!
   (thanks to CG)
•  Pulls location information without the user
   knowing	

•  Hooked through Skyhook	

•  Developer gets your location	

•  Great for stalking app users…
•  Plug-ins for BeEF to retrieve HTML5
   Geolocation	

  –  Designed for PHP version of BeEF	

•  Allows the attacker to track the victims	

•  Scope testing for pen-testers
•  Enhances upon the
   BeEF framework	

  –  Part of the HTML5
     plug-ins	

•  Determines if the
   payload is supported	

•  Retrieves the location
   for the controller
•  Geolocation can be problematic	

  –  Current browsers respond erratically	

     •  Often just the first time its called	

  –  Support is getting better everyday
Ruby BeEF
•  Geolocaon	
  plug	
  in	
  is	
  part	
  of	
  the	
  Ruby	
  
   version	
  of	
  BeEF	
  
•  Supports	
  most	
  browsers	
  
    –  IE	
  is	
  sll	
  problemac	
  
    –  Kevin	
  and	
  Frank	
  are	
  working	
  on	
  an	
  update	
  
•  Displays	
  coordinates	
  in	
  the	
  results	
  
•  Inadvertent Location Sharing	

   –  Many mobile apps enable this by default!	

•  Cyberstalking	

•  Physical Security
•  You automatically allow your location shared with
   applications you use!	

•  Apple s 159+ page Terms of Service state…
   
         By	
  using	
  any	
  loca-on-­‐based	
  services	
  on	
  your	
  
       iPhone,	
  you	
  agree	
  and	
  consent	
  to	
  Apple s	
  and	
  its	
  
       partners 	
  and	
  licensees'	
  transmission,	
  collec-on,	
  
       maintenance,	
  processing,	
  and	
  use	
  of	
  your	
  loca-on	
  
       data	
  to	
  provide	
  such	
  products	
  and	
  services. 	
  
•  What does your phone or browser leave
   behind?	

•  Can you be tracked?	

•  How many of us sell our phones on eBay/
   Craigslist?
•  Anonymize your location	

•  Allow access to delete/remove location
   data	

•  Ability to turn off location based services	

•  What are the W3C devs doing?
- Image from Broadstuff.com
•  Getting more popular for promotions/
    prizes (Starbucks)	

•  How do you verify check-in? 	

•  Lot s of *fun* ways to abuse the system	

•  Two-factor geo check-in s?
•  Ensure full disclosure of how you use
   location based data	

•  Implement PETs	

•  Demand more/get involved with W3C
•  To share or not to share?	

•  Share with only a select group? Example:
   create a list in Facebook, share only with
   them	

•  Think before sharing your location	

•  Read the TOS, privacy policy of apps and
   services
•    SocialMediaSecurity.com	

•    Kevin will be submitting BeEF patches	

•    Follow us: @agent0x0 @secureideas	

•    Friend Kevin on Facebook. Really.
GONE

More Related Content

What's hot

Ipad tablet class april 2013
Ipad tablet class april 2013Ipad tablet class april 2013
Ipad tablet class april 2013Amy Smythe-Harris
 
iPad Workshop
iPad WorkshopiPad Workshop
iPad WorkshopVic Ward
 
I os class 1 of 3 actual
I os class 1 of 3 actualI os class 1 of 3 actual
I os class 1 of 3 actualVic Ward
 
Elements of Connected Products
Elements of Connected ProductsElements of Connected Products
Elements of Connected ProductsJordan Husney
 
Unleashing your parish geeks
Unleashing your parish geeksUnleashing your parish geeks
Unleashing your parish geeksNicoleParrot
 
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...Dave Amirault
 
Webvisions 2011 - Geoloqi - Location as Invisible Interface
Webvisions 2011 - Geoloqi - Location as Invisible InterfaceWebvisions 2011 - Geoloqi - Location as Invisible Interface
Webvisions 2011 - Geoloqi - Location as Invisible InterfaceAmber Case
 
What The App Presentation Podcamp East 2012
What The App Presentation Podcamp East 2012What The App Presentation Podcamp East 2012
What The App Presentation Podcamp East 2012Goldstein Media LLC
 
I phone presentation
I phone presentationI phone presentation
I phone presentationrosenbe_jenn
 
iPads in an inclusive classroom - Icon Learning
iPads in an inclusive classroom - Icon LearningiPads in an inclusive classroom - Icon Learning
iPads in an inclusive classroom - Icon Learningbellla33
 
Personal voice assistant - jarvis
Personal voice assistant - jarvisPersonal voice assistant - jarvis
Personal voice assistant - jarvisKana Ram Yadav
 
Mobile WordPress: Dale Mugford of BraveNewCode
Mobile WordPress: Dale Mugford of BraveNewCodeMobile WordPress: Dale Mugford of BraveNewCode
Mobile WordPress: Dale Mugford of BraveNewCodeBraveNewCode Inc.
 
Assist Workshop 2016 - Nick Triantos - SRI
Assist Workshop 2016 - Nick Triantos - SRIAssist Workshop 2016 - Nick Triantos - SRI
Assist Workshop 2016 - Nick Triantos - SRIassist
 
WHOIS the Master
WHOIS the MasterWHOIS the Master
WHOIS the MasterJason Ross
 
Museum mobile tour - content production and delivery process chart
Museum mobile tour -  content production and delivery process chartMuseum mobile tour -  content production and delivery process chart
Museum mobile tour - content production and delivery process chartMinnesota Historical Society
 
Make Your WordPress Site Mobile Friendly
Make Your WordPress Site Mobile FriendlyMake Your WordPress Site Mobile Friendly
Make Your WordPress Site Mobile FriendlyDave Zille
 
I pad class 3 maple grove
I pad class 3 maple groveI pad class 3 maple grove
I pad class 3 maple groveVic Ward
 

What's hot (20)

Ipad tablet class april 2013
Ipad tablet class april 2013Ipad tablet class april 2013
Ipad tablet class april 2013
 
Amy xplode april 2013 v5
Amy xplode april 2013 v5Amy xplode april 2013 v5
Amy xplode april 2013 v5
 
iPad Workshop
iPad WorkshopiPad Workshop
iPad Workshop
 
I os class 1 of 3 actual
I os class 1 of 3 actualI os class 1 of 3 actual
I os class 1 of 3 actual
 
Elements of Connected Products
Elements of Connected ProductsElements of Connected Products
Elements of Connected Products
 
Unleashing your parish geeks
Unleashing your parish geeksUnleashing your parish geeks
Unleashing your parish geeks
 
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...
The Wireless Ski Area - How Technology and Connectivity are Impacting the Gue...
 
Webvisions 2011 - Geoloqi - Location as Invisible Interface
Webvisions 2011 - Geoloqi - Location as Invisible InterfaceWebvisions 2011 - Geoloqi - Location as Invisible Interface
Webvisions 2011 - Geoloqi - Location as Invisible Interface
 
Siri
SiriSiri
Siri
 
What The App Presentation Podcamp East 2012
What The App Presentation Podcamp East 2012What The App Presentation Podcamp East 2012
What The App Presentation Podcamp East 2012
 
I phone presentation
I phone presentationI phone presentation
I phone presentation
 
iPads in an inclusive classroom - Icon Learning
iPads in an inclusive classroom - Icon LearningiPads in an inclusive classroom - Icon Learning
iPads in an inclusive classroom - Icon Learning
 
Personal voice assistant - jarvis
Personal voice assistant - jarvisPersonal voice assistant - jarvis
Personal voice assistant - jarvis
 
Mobile WordPress: Dale Mugford of BraveNewCode
Mobile WordPress: Dale Mugford of BraveNewCodeMobile WordPress: Dale Mugford of BraveNewCode
Mobile WordPress: Dale Mugford of BraveNewCode
 
Assist Workshop 2016 - Nick Triantos - SRI
Assist Workshop 2016 - Nick Triantos - SRIAssist Workshop 2016 - Nick Triantos - SRI
Assist Workshop 2016 - Nick Triantos - SRI
 
WHOIS the Master
WHOIS the MasterWHOIS the Master
WHOIS the Master
 
Museum mobile tour - content production and delivery process chart
Museum mobile tour -  content production and delivery process chartMuseum mobile tour -  content production and delivery process chart
Museum mobile tour - content production and delivery process chart
 
Make Your WordPress Site Mobile Friendly
Make Your WordPress Site Mobile FriendlyMake Your WordPress Site Mobile Friendly
Make Your WordPress Site Mobile Friendly
 
I pad class 3 maple grove
I pad class 3 maple groveI pad class 3 maple grove
I pad class 3 maple grove
 
Android vs iOS
Android vs iOSAndroid vs iOS
Android vs iOS
 

Viewers also liked

Location Based Network Presentation
Location Based Network PresentationLocation Based Network Presentation
Location Based Network Presentationsrndur
 
Location-Based Services Overview and 5 Tips for Location-Based Marketing
Location-Based Services Overview and 5 Tips for Location-Based MarketingLocation-Based Services Overview and 5 Tips for Location-Based Marketing
Location-Based Services Overview and 5 Tips for Location-Based MarketingAdam Steinberg
 
Functional Simulation of the Integrated Onboard System For a Commercial Launc...
Functional Simulation of the Integrated Onboard System For a Commercial Launc...Functional Simulation of the Integrated Onboard System For a Commercial Launc...
Functional Simulation of the Integrated Onboard System For a Commercial Launc...irjes
 
Introduction to Foursquare: 4SQ 101
Introduction to Foursquare: 4SQ 101 Introduction to Foursquare: 4SQ 101
Introduction to Foursquare: 4SQ 101 Murat Can Demir
 
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...alta4 Geoinformatik AG
 
Inertial Navigation System
Inertial Navigation SystemInertial Navigation System
Inertial Navigation Systemaerobuddy
 
Notice gps globe_800
Notice gps globe_800Notice gps globe_800
Notice gps globe_800GPS Globe 4X4
 
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...ATECITSFRANCE
 
Audit akademik spm 2013
Audit akademik spm 2013Audit akademik spm 2013
Audit akademik spm 2013irafairus
 
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008Uwe Baltner Xonio.com Präsentation Telekom Forum 2008
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008Uwe Baltner
 
Tourisme Gps Aec Mopa Pau 13 Mars08v1
Tourisme Gps Aec Mopa Pau 13 Mars08v1Tourisme Gps Aec Mopa Pau 13 Mars08v1
Tourisme Gps Aec Mopa Pau 13 Mars08v1MONA
 
Notice Globe 360 - GPS GLOBE
Notice Globe 360 - GPS GLOBENotice Globe 360 - GPS GLOBE
Notice Globe 360 - GPS GLOBEGPS Globe 4X4
 
Nouvelles tendances web et cartographie
Nouvelles tendances web et cartographieNouvelles tendances web et cartographie
Nouvelles tendances web et cartographieNicolas_Delffon
 
Gps ins odometer data fusion
Gps ins odometer data fusionGps ins odometer data fusion
Gps ins odometer data fusionRappy Saha
 
Ins for dp methods full
Ins for dp methods   fullIns for dp methods   full
Ins for dp methods fullJames Titcomb
 

Viewers also liked (20)

Location Based Network Presentation
Location Based Network PresentationLocation Based Network Presentation
Location Based Network Presentation
 
Location-Based Services Overview and 5 Tips for Location-Based Marketing
Location-Based Services Overview and 5 Tips for Location-Based MarketingLocation-Based Services Overview and 5 Tips for Location-Based Marketing
Location-Based Services Overview and 5 Tips for Location-Based Marketing
 
Functional Simulation of the Integrated Onboard System For a Commercial Launc...
Functional Simulation of the Integrated Onboard System For a Commercial Launc...Functional Simulation of the Integrated Onboard System For a Commercial Launc...
Functional Simulation of the Integrated Onboard System For a Commercial Launc...
 
Introduction to Foursquare: 4SQ 101
Introduction to Foursquare: 4SQ 101 Introduction to Foursquare: 4SQ 101
Introduction to Foursquare: 4SQ 101
 
13 sadia riaz _13
13 sadia riaz _1313 sadia riaz _13
13 sadia riaz _13
 
Nasa space app challenge
Nasa space app challengeNasa space app challenge
Nasa space app challenge
 
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...
GPS-Kameras und Photo-Asset-Management – Anwendungsbeispele aus der Wasserwir...
 
Inertial Navigation System
Inertial Navigation SystemInertial Navigation System
Inertial Navigation System
 
Satspeed
SatspeedSatspeed
Satspeed
 
Notice gps globe_800
Notice gps globe_800Notice gps globe_800
Notice gps globe_800
 
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...
Pierre-Yves GILLIERON, Research and Teaching Associate – Ecole Polytechnique ...
 
Audit akademik spm 2013
Audit akademik spm 2013Audit akademik spm 2013
Audit akademik spm 2013
 
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008Uwe Baltner Xonio.com Präsentation Telekom Forum 2008
Uwe Baltner Xonio.com Präsentation Telekom Forum 2008
 
Tourisme Gps Aec Mopa Pau 13 Mars08v1
Tourisme Gps Aec Mopa Pau 13 Mars08v1Tourisme Gps Aec Mopa Pau 13 Mars08v1
Tourisme Gps Aec Mopa Pau 13 Mars08v1
 
Notice Globe 360 - GPS GLOBE
Notice Globe 360 - GPS GLOBENotice Globe 360 - GPS GLOBE
Notice Globe 360 - GPS GLOBE
 
Nouvelles tendances web et cartographie
Nouvelles tendances web et cartographieNouvelles tendances web et cartographie
Nouvelles tendances web et cartographie
 
CNA S03#08: 3D printing hub institute
CNA S03#08: 3D printing hub instituteCNA S03#08: 3D printing hub institute
CNA S03#08: 3D printing hub institute
 
Gps waas class 5 nov10
Gps waas class 5 nov10Gps waas class 5 nov10
Gps waas class 5 nov10
 
Gps ins odometer data fusion
Gps ins odometer data fusionGps ins odometer data fusion
Gps ins odometer data fusion
 
Ins for dp methods full
Ins for dp methods   fullIns for dp methods   full
Ins for dp methods full
 

Similar to Social Zombies Gone Wild: Totally Exposed and Uncensored

SXSW 2010 Future15 : Rise of Mobile, APIs and Web Runtimes
SXSW 2010 Future15 : Rise of Mobile, APIs and Web RuntimesSXSW 2010 Future15 : Rise of Mobile, APIs and Web Runtimes
SXSW 2010 Future15 : Rise of Mobile, APIs and Web RuntimesDaniel Appelquist
 
Rise of Mobile and Web Runtimes - for Standards-Next
Rise of Mobile and Web Runtimes - for Standards-NextRise of Mobile and Web Runtimes - for Standards-Next
Rise of Mobile and Web Runtimes - for Standards-NextDaniel Appelquist
 
Building Mobile Apps with HTML, CSS, and JavaScript
Building Mobile Apps with HTML, CSS, and JavaScriptBuilding Mobile Apps with HTML, CSS, and JavaScript
Building Mobile Apps with HTML, CSS, and JavaScriptJonathan Stark
 
Mobeers waterloo-2011
Mobeers waterloo-2011Mobeers waterloo-2011
Mobeers waterloo-2011Brian LeRoux
 
HTML5 is the Future of Mobile, PhoneGap Takes You There Today
HTML5 is the Future of Mobile, PhoneGap Takes You There TodayHTML5 is the Future of Mobile, PhoneGap Takes You There Today
HTML5 is the Future of Mobile, PhoneGap Takes You There Todaydavyjones
 
Navigation & Location Europe 2009 Condensed
Navigation & Location Europe 2009 CondensedNavigation & Location Europe 2009 Condensed
Navigation & Location Europe 2009 CondensedAlex Housley
 
Firefox os the web, mobile (for yahoo! hack europe - april 2013)
Firefox os  the web, mobile (for yahoo! hack europe - april 2013)Firefox os  the web, mobile (for yahoo! hack europe - april 2013)
Firefox os the web, mobile (for yahoo! hack europe - april 2013)Yahoo Developer Network
 
Mobile code mining for discovery and exploits nullcongoa2013
Mobile code mining for discovery and exploits nullcongoa2013Mobile code mining for discovery and exploits nullcongoa2013
Mobile code mining for discovery and exploits nullcongoa2013Blueinfy Solutions
 
PhoneGap - Now and the Future
PhoneGap - Now and the FuturePhoneGap - Now and the Future
PhoneGap - Now and the FutureTim Kim
 
A Brave New World
A Brave New WorldA Brave New World
A Brave New WorldSensePost
 
Getting Started with Mobile Websites if You Don't Know Code
Getting Started with Mobile Websites if You Don't Know CodeGetting Started with Mobile Websites if You Don't Know Code
Getting Started with Mobile Websites if You Don't Know CodeCarli Spina
 
Web 2.0 & 3.0 technologies & SoLoMo
Web 2.0 & 3.0 technologies & SoLoMoWeb 2.0 & 3.0 technologies & SoLoMo
Web 2.0 & 3.0 technologies & SoLoMoJake Aull
 
Phonegap for Engineers
Phonegap for EngineersPhonegap for Engineers
Phonegap for EngineersBrian LeRoux
 
Cross Platform HTML5 Mobile Development
Cross Platform HTML5 Mobile DevelopmentCross Platform HTML5 Mobile Development
Cross Platform HTML5 Mobile DevelopmentRobert 'Bob' Reyes
 
Lg Web Network Mobile Presentation August 2009
Lg Web Network Mobile Presentation August 2009Lg Web Network Mobile Presentation August 2009
Lg Web Network Mobile Presentation August 2009Oliver Weidlich
 

Similar to Social Zombies Gone Wild: Totally Exposed and Uncensored (20)

SXSW 2010 Future15 : Rise of Mobile, APIs and Web Runtimes
SXSW 2010 Future15 : Rise of Mobile, APIs and Web RuntimesSXSW 2010 Future15 : Rise of Mobile, APIs and Web Runtimes
SXSW 2010 Future15 : Rise of Mobile, APIs and Web Runtimes
 
Rise of Mobile and Web Runtimes - for Standards-Next
Rise of Mobile and Web Runtimes - for Standards-NextRise of Mobile and Web Runtimes - for Standards-Next
Rise of Mobile and Web Runtimes - for Standards-Next
 
Future of Mobile
Future of MobileFuture of Mobile
Future of Mobile
 
Building Mobile Apps with HTML, CSS, and JavaScript
Building Mobile Apps with HTML, CSS, and JavaScriptBuilding Mobile Apps with HTML, CSS, and JavaScript
Building Mobile Apps with HTML, CSS, and JavaScript
 
Mobeers waterloo-2011
Mobeers waterloo-2011Mobeers waterloo-2011
Mobeers waterloo-2011
 
HTML5 is the Future of Mobile, PhoneGap Takes You There Today
HTML5 is the Future of Mobile, PhoneGap Takes You There TodayHTML5 is the Future of Mobile, PhoneGap Takes You There Today
HTML5 is the Future of Mobile, PhoneGap Takes You There Today
 
Navigation & Location Europe 2009 Condensed
Navigation & Location Europe 2009 CondensedNavigation & Location Europe 2009 Condensed
Navigation & Location Europe 2009 Condensed
 
Adam w. mosher - geo tagging - atlseccon2011
Adam w. mosher - geo tagging - atlseccon2011Adam w. mosher - geo tagging - atlseccon2011
Adam w. mosher - geo tagging - atlseccon2011
 
Firefox os the web, mobile (for yahoo! hack europe - april 2013)
Firefox os  the web, mobile (for yahoo! hack europe - april 2013)Firefox os  the web, mobile (for yahoo! hack europe - april 2013)
Firefox os the web, mobile (for yahoo! hack europe - april 2013)
 
Mobile Web High Performance
Mobile Web High PerformanceMobile Web High Performance
Mobile Web High Performance
 
Mobile code mining for discovery and exploits nullcongoa2013
Mobile code mining for discovery and exploits nullcongoa2013Mobile code mining for discovery and exploits nullcongoa2013
Mobile code mining for discovery and exploits nullcongoa2013
 
PhoneGap - Now and the Future
PhoneGap - Now and the FuturePhoneGap - Now and the Future
PhoneGap - Now and the Future
 
A Brave New World
A Brave New WorldA Brave New World
A Brave New World
 
Getting Started with Mobile Websites if You Don't Know Code
Getting Started with Mobile Websites if You Don't Know CodeGetting Started with Mobile Websites if You Don't Know Code
Getting Started with Mobile Websites if You Don't Know Code
 
Web 2.0 & 3.0 technologies & SoLoMo
Web 2.0 & 3.0 technologies & SoLoMoWeb 2.0 & 3.0 technologies & SoLoMo
Web 2.0 & 3.0 technologies & SoLoMo
 
Phonegap for Engineers
Phonegap for EngineersPhonegap for Engineers
Phonegap for Engineers
 
Cross Platform HTML5 Mobile Development
Cross Platform HTML5 Mobile DevelopmentCross Platform HTML5 Mobile Development
Cross Platform HTML5 Mobile Development
 
Lg Web Network Mobile Presentation August 2009
Lg Web Network Mobile Presentation August 2009Lg Web Network Mobile Presentation August 2009
Lg Web Network Mobile Presentation August 2009
 
Phone gap
Phone gapPhone gap
Phone gap
 
Using Location in Games
Using Location in GamesUsing Location in Games
Using Location in Games
 

More from Tom Eston

Privacy Exposed: Ramifications of Social Media and Mobile Technology
Privacy Exposed: Ramifications of Social Media and Mobile TechnologyPrivacy Exposed: Ramifications of Social Media and Mobile Technology
Privacy Exposed: Ramifications of Social Media and Mobile TechnologyTom Eston
 
Cash is King: Who's Wearing Your Crown?
Cash is King: Who's Wearing Your Crown?Cash is King: Who's Wearing Your Crown?
Cash is King: Who's Wearing Your Crown?Tom Eston
 
Social Zombies: Rise of the Mobile Dead
Social Zombies: Rise of the Mobile DeadSocial Zombies: Rise of the Mobile Dead
Social Zombies: Rise of the Mobile DeadTom Eston
 
The Android vs. Apple iOS Security Showdown
The Android vs. Apple iOS Security Showdown The Android vs. Apple iOS Security Showdown
The Android vs. Apple iOS Security Showdown Tom Eston
 
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...Tom Eston
 
Smart Bombs: Mobile Vulnerability and Exploitation
Smart Bombs: Mobile Vulnerability and ExploitationSmart Bombs: Mobile Vulnerability and Exploitation
Smart Bombs: Mobile Vulnerability and ExploitationTom Eston
 
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers Tom Eston
 
Attacking and Defending Apple iOS Devices
Attacking and Defending Apple iOS DevicesAttacking and Defending Apple iOS Devices
Attacking and Defending Apple iOS DevicesTom Eston
 
Social Zombies II: Your Friends Need More Brains
Social Zombies II: Your Friends Need More BrainsSocial Zombies II: Your Friends Need More Brains
Social Zombies II: Your Friends Need More BrainsTom Eston
 
Enterprise Open Source Intelligence Gathering
Enterprise Open Source Intelligence GatheringEnterprise Open Source Intelligence Gathering
Enterprise Open Source Intelligence GatheringTom Eston
 
Staying Safe & Secure on Twitter
Staying Safe & Secure on TwitterStaying Safe & Secure on Twitter
Staying Safe & Secure on TwitterTom Eston
 
New School Man-in-the-Middle
New School Man-in-the-MiddleNew School Man-in-the-Middle
New School Man-in-the-MiddleTom Eston
 
Rise of the Autobots: Into the Underground of Social Network Bots
Rise of the Autobots: Into the Underground of Social Network BotsRise of the Autobots: Into the Underground of Social Network Bots
Rise of the Autobots: Into the Underground of Social Network BotsTom Eston
 
Information Gathering With Maltego
Information Gathering With MaltegoInformation Gathering With Maltego
Information Gathering With MaltegoTom Eston
 
Automated Penetration Testing With Core Impact
Automated Penetration Testing With Core ImpactAutomated Penetration Testing With Core Impact
Automated Penetration Testing With Core ImpactTom Eston
 
Automated Penetration Testing With The Metasploit Framework
Automated Penetration Testing With The Metasploit FrameworkAutomated Penetration Testing With The Metasploit Framework
Automated Penetration Testing With The Metasploit FrameworkTom Eston
 
Physical Security Assessments
Physical Security AssessmentsPhysical Security Assessments
Physical Security AssessmentsTom Eston
 
Online Social Networks: 5 threats and 5 ways to use them safely
Online Social Networks: 5 threats and 5 ways to use them safelyOnline Social Networks: 5 threats and 5 ways to use them safely
Online Social Networks: 5 threats and 5 ways to use them safelyTom Eston
 

More from Tom Eston (18)

Privacy Exposed: Ramifications of Social Media and Mobile Technology
Privacy Exposed: Ramifications of Social Media and Mobile TechnologyPrivacy Exposed: Ramifications of Social Media and Mobile Technology
Privacy Exposed: Ramifications of Social Media and Mobile Technology
 
Cash is King: Who's Wearing Your Crown?
Cash is King: Who's Wearing Your Crown?Cash is King: Who's Wearing Your Crown?
Cash is King: Who's Wearing Your Crown?
 
Social Zombies: Rise of the Mobile Dead
Social Zombies: Rise of the Mobile DeadSocial Zombies: Rise of the Mobile Dead
Social Zombies: Rise of the Mobile Dead
 
The Android vs. Apple iOS Security Showdown
The Android vs. Apple iOS Security Showdown The Android vs. Apple iOS Security Showdown
The Android vs. Apple iOS Security Showdown
 
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...
Five Lessons Learned From Breaking Into A Casino: Confessions of a Penetratio...
 
Smart Bombs: Mobile Vulnerability and Exploitation
Smart Bombs: Mobile Vulnerability and ExploitationSmart Bombs: Mobile Vulnerability and Exploitation
Smart Bombs: Mobile Vulnerability and Exploitation
 
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
Don't Drop the SOAP: Real World Web Service Testing for Web Hackers
 
Attacking and Defending Apple iOS Devices
Attacking and Defending Apple iOS DevicesAttacking and Defending Apple iOS Devices
Attacking and Defending Apple iOS Devices
 
Social Zombies II: Your Friends Need More Brains
Social Zombies II: Your Friends Need More BrainsSocial Zombies II: Your Friends Need More Brains
Social Zombies II: Your Friends Need More Brains
 
Enterprise Open Source Intelligence Gathering
Enterprise Open Source Intelligence GatheringEnterprise Open Source Intelligence Gathering
Enterprise Open Source Intelligence Gathering
 
Staying Safe & Secure on Twitter
Staying Safe & Secure on TwitterStaying Safe & Secure on Twitter
Staying Safe & Secure on Twitter
 
New School Man-in-the-Middle
New School Man-in-the-MiddleNew School Man-in-the-Middle
New School Man-in-the-Middle
 
Rise of the Autobots: Into the Underground of Social Network Bots
Rise of the Autobots: Into the Underground of Social Network BotsRise of the Autobots: Into the Underground of Social Network Bots
Rise of the Autobots: Into the Underground of Social Network Bots
 
Information Gathering With Maltego
Information Gathering With MaltegoInformation Gathering With Maltego
Information Gathering With Maltego
 
Automated Penetration Testing With Core Impact
Automated Penetration Testing With Core ImpactAutomated Penetration Testing With Core Impact
Automated Penetration Testing With Core Impact
 
Automated Penetration Testing With The Metasploit Framework
Automated Penetration Testing With The Metasploit FrameworkAutomated Penetration Testing With The Metasploit Framework
Automated Penetration Testing With The Metasploit Framework
 
Physical Security Assessments
Physical Security AssessmentsPhysical Security Assessments
Physical Security Assessments
 
Online Social Networks: 5 threats and 5 ways to use them safely
Online Social Networks: 5 threats and 5 ways to use them safelyOnline Social Networks: 5 threats and 5 ways to use them safely
Online Social Networks: 5 threats and 5 ways to use them safely
 

Recently uploaded

Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxNavinnSomaal
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyAlfredo García Lavilla
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 

Recently uploaded (20)

Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
The State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptxThe State of Passkeys with FIDO Alliance.pptx
The State of Passkeys with FIDO Alliance.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
SAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptxSAP Build Work Zone - Overview L2-L3.pptx
SAP Build Work Zone - Overview L2-L3.pptx
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
Commit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easyCommit 2024 - Secret Management made easy
Commit 2024 - Secret Management made easy
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 

Social Zombies Gone Wild: Totally Exposed and Uncensored

  • 2. •  Senior Security Consultant, SecureState •  Founder of SocialMediaSecurity.com •  Facebook Privacy & Security Guide •  Blogger •  Co-host of Security Justice, Social Media Security Podcasts
  • 3. •  Security Consultant, Secure Ideas •  Author Sec542 from SANS •  Instructor of the SamuraiWTF class •  SANS Internet Storm Center Handler •  Project lead for: –  SamuraiWTF –  Yokoso! –  Laudanum –  WeaponizedFlash
  • 4. •  Location Based Services are exactly that •  Services that provide your location to others –  Be them friends or companies that want to know •  These services can be built into our devices and software or programs we sign up for –  Can tell where we are or where we aren’t
  • 6. The market for location-based services on mobile phones will be worth about $3 billion in 2013… -Frost and Sullivan (Market Research Firm)
  • 7.
  • 8. •  The original way of performing geo-location checks •  Determined through ISP lookups and whois records •  Prone to misleading results –  Due to ISP location being reported •  Popular with Banners/Adult Advertising
  • 9.
  • 10. •  Researchers  have  found  new  ways  to  get   closer  results  via  IP  address   •  Typical  results  used  to  get  you  within  200   kilometers  (me  based)   •  Now  within  a  few  hundred  meters!   •  Creates  new  ways  for  adversers  and  the   government  to  track  you  J   •  Using  proxy’s  seem  to  help…but  who  controls   these?  
  • 11. •  GPS in the mobile device was revolutionary –  Users have embraced it •  We have our phone with us everywhere •  Ability to use web based tech with the mobile GPS has changed the way we use phones! –  Mash-ups for the win!
  • 12. •  GPS •  WiFi •  Bluetooth •  RFID •  3G/EDGE, CDMA, GSM •  We pack our phones with latest wireless tech…
  • 13.
  • 14.
  • 15. •  IP address •  RFID •  WiFi and Bluetooth MAC addresses •  GSM/CDMA cell IDs •  Manual user input
  • 16. •  Service Examples: –  Google Location Services •  Cell Tower •  Wifi based –  Skyhook/Loki •  Wifi based
  • 17. •  Many new providers of Geolocation data •  Skyhook •  SimpleGeo (working on Geofences)
  • 18. •  Yes, its scary and has been around for a few years •  Your phone determines if you are in a location or not •  iOS4 already supports background geo •  SimpleGeo can do this in 6 lines of code •  30 lines to support background geo tracking on iOS4
  • 19. “So you basically just say, Track User and we handle that in our API along with record history. I can then come back and say, Show me the last 10 places the user was , Stump continues... Creepy? Sort of. Powerful and easy? Yes. - TechCrunch Interview w/SocialGeo co-founder Joe Stump
  • 20.
  • 21. •  Firefox ( 3.5 uses Google) •  Opera (nightly build uses Skyhook) •  Safari (uses Skyhook in iPhone/iPad) •  Chrome (uses Google) •  Internet Explorer 9 (HTML5-based)
  • 22. Geolocation is not standardized…yet. •  Follow the Geolocation developer mailing list...it s fun! – http://www.w3.org/2008/geolocation/
  • 23. •  How will developers use this? •  W3C Geolocation API •  Code is easy to manipulate for evil things
  • 24. •  Now available in Safari, Opera and Chrome •  The Evercookie (Samy Kamkar) •  Store and track your locations as well
  • 25.
  • 26. FourSquare/Gowalla •  These games are supposed to be fun, right?
  • 27. •  Opt in by default •  Built into the API •  Forgotten by many users…
  • 28. •  We 3 Google •  Tracks your location history •  How many use the same password for all sites?
  • 29.
  • 30. •  600 Million Users all sharing locations… •  Kevin loves this
  • 31.
  • 32. •  Barcode Hero? Yeah seriously…
  • 35.
  • 36. •  Geolocation DoS •  Randomly generate SSIDs •  Fake SSID flood •  Hardware jamming
  • 37. •  2008 Research by Students from ETH Zurich •  AP Impersonation •  WLAN Jamming •  SkyHook DoS
  • 38. •  [Disclaimer] These are illegal! •  Easy to buy overseas
  • 39.
  • 40.
  • 41.
  • 42. •  hIp://ilektrojohn.github.com/creepy/   •  Geolocation stalking tool! •  Works on Windows and Linux
  • 43. •  Sniff and Spoof (Man-in-the-Middle Attacks) •  Or…just use FireSheep and hijack the account for location data •  Fun at conferences and hotels ;-)
  • 44.
  • 45. •  Proxies •  Tor (still slow) •  Moxie Marlinspike s GoogleSharing creates interesting possibilities
  • 46.
  • 47.
  • 49. •  Fake Location App (iPhone/Android) •  Geolocater Firefox Plugin •  Manually manipulate Firefox, use touch.facebook.com
  • 50.
  • 51. •  FourSquare gaming the system •  Lots of scripts, programs to do this…even a Metasploit module! (thanks to CG)
  • 52.
  • 53. •  Pulls location information without the user knowing •  Hooked through Skyhook •  Developer gets your location •  Great for stalking app users…
  • 54.
  • 55. •  Plug-ins for BeEF to retrieve HTML5 Geolocation –  Designed for PHP version of BeEF •  Allows the attacker to track the victims •  Scope testing for pen-testers
  • 56. •  Enhances upon the BeEF framework –  Part of the HTML5 plug-ins •  Determines if the payload is supported •  Retrieves the location for the controller
  • 57. •  Geolocation can be problematic –  Current browsers respond erratically •  Often just the first time its called –  Support is getting better everyday
  • 58. Ruby BeEF •  Geolocaon  plug  in  is  part  of  the  Ruby   version  of  BeEF   •  Supports  most  browsers   –  IE  is  sll  problemac   –  Kevin  and  Frank  are  working  on  an  update   •  Displays  coordinates  in  the  results  
  • 59.
  • 60. •  Inadvertent Location Sharing –  Many mobile apps enable this by default! •  Cyberstalking •  Physical Security
  • 61. •  You automatically allow your location shared with applications you use! •  Apple s 159+ page Terms of Service state… By  using  any  loca-on-­‐based  services  on  your   iPhone,  you  agree  and  consent  to  Apple s  and  its   partners  and  licensees'  transmission,  collec-on,   maintenance,  processing,  and  use  of  your  loca-on   data  to  provide  such  products  and  services.  
  • 62. •  What does your phone or browser leave behind? •  Can you be tracked? •  How many of us sell our phones on eBay/ Craigslist?
  • 63.
  • 64. •  Anonymize your location •  Allow access to delete/remove location data •  Ability to turn off location based services •  What are the W3C devs doing?
  • 65.
  • 66. - Image from Broadstuff.com
  • 67. •  Getting more popular for promotions/ prizes (Starbucks) •  How do you verify check-in? •  Lot s of *fun* ways to abuse the system •  Two-factor geo check-in s?
  • 68. •  Ensure full disclosure of how you use location based data •  Implement PETs •  Demand more/get involved with W3C
  • 69. •  To share or not to share? •  Share with only a select group? Example: create a list in Facebook, share only with them •  Think before sharing your location •  Read the TOS, privacy policy of apps and services
  • 70. •  SocialMediaSecurity.com •  Kevin will be submitting BeEF patches •  Follow us: @agent0x0 @secureideas •  Friend Kevin on Facebook. Really.
  • 71. GONE