nerdexam
EC-Council

312-50V11 · Question #958

Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker…

The correct answer is D. ASpearphone attack. Bob performed an ASpearphone attack, a side-channel attack that exploits loudspeaker hardware vibrations to covertly capture audio output from a mobile device.

Hacking Mobile Platforms

Question

Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker, takes advantage of this vulnerability and secretly exploits the hardware of Kate's phone so that he can monitor the loudspeaker's output from data sources such as voice assistants, multimedia messages, and audio files by using a malicious app to breach speech privacy. What is the type of attack Bob performed on Kate in the above scenario?

Options

  • AMan-in-the-disk attack
  • BaLTEr attack
  • CSIM card attack
  • DASpearphone attack

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    9% (2)
  • C
    5% (1)
  • D
    82% (18)

Why each option

Bob performed an ASpearphone attack, a side-channel attack that exploits loudspeaker hardware vibrations to covertly capture audio output from a mobile device.

AMan-in-the-disk attack

A Man-in-the-disk attack exploits Android's external storage to tamper with application data between storage and the app, not to monitor loudspeaker audio.

BaLTEr attack

An aLTEr attack is a network-layer attack that targets LTE communications by impersonating a base station, and is unrelated to device loudspeaker hardware.

CSIM card attack

A SIM card attack targets the subscriber identity module to intercept calls or clone the device identity, not to exploit loudspeaker hardware for eavesdropping.

DASpearphone attackCorrect

ASpearphone is a side-channel attack that leverages the device's accelerometer to eavesdrop on loudspeaker output by sensing the physical vibrations produced by the speaker hardware. In this scenario, Bob exploited Kate's already-active loudspeaker via a malicious app to monitor voice calls, multimedia messages, and audio files, which precisely matches the definition of an ASpearphone attack targeting speech privacy through hardware exploitation.

Concept tested: ASpearphone side-channel loudspeaker eavesdropping on mobile

Topics

#Spearphone attack#loudspeaker eavesdropping#hardware exploitation#mobile privacy

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice