TinyCheck: Easily capture network communications coming from a smartphone
github.com
github.com
Somewhat disappointingly (and different to my understanding of "easily" and "from a smartphone") followed further down by:
In order to make it working, you need a computer with a Debian-like operating system and two Wi-Fi interfaces. The best choice is to use a Raspberry Pi (3+) with a Wi-Fi dongle and a small touch screen...
Dual wifi makes for easier installation/operation in a lot of situations though, so I think its a good "default config". If there's already a wifi network people can use, hooking one wifi chipset to that then connecting the phones under test to an access point broadcast by the other - is easier than expecting there to be a live ethernet port and someone at a womens shelter-style-place having access to it and skills to use it.
This should be fairly simple too so long as there's no arbitrary restriction on requiring wlan devices preventing you from using WiFi+Ethernet rather than Wifi+Wifi.
The other interface is to connect the TinyCheck box to the internet, so it could well be a wired connection.
I suspect that if your WiFi device can support AP and client mode simultaneously it should work just as well.
"The idea of TinyCheck came to me in a meeting about stalkerware with a French women's shelter. During this meeting we talked about how to easily detect easily stalkerware without installing very technical apps nor doing forensic analysis on them. The initial concept was to develop a tiny kiosk device based on Raspberry Pi which can be used by non-tech people to test their smartphones against malicious communications issued by stalkerware or any spyware."
I think it's a great idea. I'm going to check in with a friend who has to deal with stalker ware-infected phones at a womens shelter she volunteers at to see if they'd like me to build/send them one.
It would definitely be nice to see it deployable in a quick and easy way for less tech savvy users.
Some info only goes cellular, the only way to capture that is using a hotspot which simulates the normal network.
The real sneaky spyware I found only goes over cellular and hides itself by using double encrypted SSL traffic to AWS endpoints.
However, there is also WiFi Calling - in that sense, your phone establishes some connection with the cell network. However, I don‘t think any user data may travel on this bearer, but there might be some edge case where this is possible.
Not sure if serious ...
Wouldn't it be pretty easy to fingerprint a TLS session that always starts with another TLS handshake?
I believe they also certificate pin the tunneled protocol.
Of course, you can also just check if the phone sends something by looking at the RF energy or even build an uplink decoder, but I doubt that this is very useful information by itself for this use case.
Finally, what I propose instead, is to use a private LTE network, which you can create using a SDR and srsLTE and some programmable SIM cards, which you need to insert into the phone. This way, it‘s easily possible to view any traffic leaving the phone on any connection. Plus, srsLTE has been shown to work on Raspberry Pi as well (I think).
Btw, it is great application firewall too (it installs itself as vpn) and worth a donation (unless you build it yourself without a donation the pro features like packet capture wont be available).
I wasn't familiar with the latest tooling, but I was able to accomplish this by running an Android Emulator on a low-ish version (5 I think) and using Burp suite.
This method seems like it will quickly become obsolete. Going forward will the only way to accomplish this type of work be via rooting the device?
Then you get into modifying the application itself by patching out checks, replacing embedded certs...
It's also very handy to have a rooted device or emulator to hand too for times when you might want to poke around in the private storage of an app.
This plus a Frida [1] script or two would be amazing.
I think their indicators of compromise (IoC) list is probably a pretty good alternative for their intended use case. I wouldn't want to be relying on this to protect me against state level actors, but I could easily see their IoC list being capable of detecting the sort of tools readily available to jilted ex boyfriends or abusive husbands.
As the author describes, this was inspired by a need for non-technical users to look for signs of surveillance software on personal devices. I imagine this might also be useful even to people who know how to use the aforementioned tools.
Does anyone here know an easy way to maybe run this in a limited context, such as in Docker or LXC? I don't feel like having a script modify my systemd services+dhcp config+network adapters but I'm also very curious to try it out.
What would be required to make that happen?
It seems to assume it is in-between your phone and your wireless router, so putting it on the wireless router would require some changes. My question was really what are those changes?
https://github.com/KasperskyLab/TinyCheck/blob/main/analysis...