ArsTechnica reports: Hackers have reverse engineered the femtocells used by British mobile operator Vodafone, and discovered that they can be used to eavesdrop on callers and used to fraudulently place calls and send text messages. Femtocells are being used increasingly often to provide better phone reception in areas with a weak signal. They contain short-range mobile base stations—typically with a range of 30-60 feet—paired up with Internet connections. Users within the range of the femtocell have their calls routed over a home Internet connection to the mobile operator's system.
Vodafone calls its femtocells Sure Signal. The Sure Signal costs £50, and supports up to 32 phone numbers belonging to 3G phones or Internet dongles. They can be used by any Vodafone customer, whether contracted or pay-as-you-go, with an Internet connection of 1Mbps or faster.
Security research group The Hacker's Choice took a look at how the Vodafone femtocells worked, and havediscovered that they're both poorly secured and fundamentally poorly designed. A little soldering enables access to the femtocell's serial console, which is secured only by a weak, fixed password. From there, network access can be enabled, custom software can be installed and run, tamper detection can be disabled, and most significantly of all, the phone network can be attacked. The unit runs Linux, so it offers a familiar environment and easy development of custom software.
(Via: ArsTechnica)

Comments