Уровень 0 · материалов: 7
В кластер входят документы, описывающие технические способы определения или скрытия географического положения устройства через манипуляции с сетевыми параметрами и уязвимостями.
Общие признаки: определение физического местоположения, использование VPN и прокси, уязвимости сетевых протоколов, подмена данных для обхода ограничений
Группа выше: Обход на уровне маршрутизатора и геоограничений
Смысл: The main idea is to expose a privacy vulnerability in Yandex's infrastructure that allows anyone with a router's MAC address to find its physical coordinates through a simple API request.
The author demonstrates how to use Yandex.Metro's API to geolocate users by sending their router's BSSID in a POST request.
Смысл: The text explains how a router's unique MAC address can be used to find its approximate physical location by querying Google's geolocation database, often through the use of web-based vulnerabilities like XSS.
The text demonstrates how attackers can use XSS vulnerabilities to steal a router's MAC address and then use Google Location Services to track the device's physical coordinates.
Смысл: The main idea is to demonstrate how the technical vulnerabilities and functional design of Apple's AirDrop (specifically BLE broadcasting and AWDL) can be exploited for both benign social interaction (meeting people) and malicious privacy intrusions (deanonymizing phone numbers).
A technical guide and personal account on using AirDrop's protocol vulnerabilities to meet strangers and uncover their private phone numbers in public.
Смысл: The main idea is that misconfigured DPI systems in mobile networks create severe privacy vulnerabilities, allowing external parties to steal personal identifiers and location data of subscribers through simple HTTP header manipulation.
Improperly configured DPI systems by mobile operators leak sensitive user data like phone numbers and locations via HTTP headers and can be exploited for free internet access.
Смысл: The main idea is to provide a technical workaround for relocated employees to maintain their income by masking their actual geographic location from their employer using a hardware-based VPN solution.
A technical guide on using a VPN-enabled router to simulate a Russian IP address to bypass employer restrictions on working from abroad.
Смысл: The main idea is that some smartphones may incorrectly attempt to connect to a local roaming operator's VoWiFi gateway instead of the home operator's gateway, and this can be bypassed by manually spoofing the DNS resolution of the ePDG address.
The author restored VoWiFi functionality in Turkey by using an OpenWRT router to force the phone to connect to the home operator's ePDG gateway via DNS spoofing.
Смысл: The main idea is to bypass the lack of a public static IP address in remote mobile networks by using a VPN tunnel to a VDS server, thereby enabling remote access to local IP cameras over a 3G connection.
A technical guide on using OpenVPN and OpenWRT to enable remote access to IP cameras via a 3G modem in areas without static IP addresses, including a DIY antenna build.