44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi
Chala mitrano, Chapter 43 madhe IoT / OT baghitla – aata mobile phones. Pocket madhe full computer: bank apps, OTP, WhatsApp business, camera, GPS. CEH exam modules madhe mobile topic yeto, pan aapan he shikto defence-first: lost phone, rogue APK, evil twin Wi-Fi, Bluetooth pairing risk – kasa Blue harden karto. Ghabru naka – OWN emulator / second test phone / host-only lab (Kali 192.168.56.10, optional target 192.168.56.50). Neighbour / colleague / stranger cha phone never. Stalkerware, OTP steal, silent spyware recipes – nahi. Lakshat theva: phone hacked aahe ka? – checklist + cleanup from a clean device; scare tactics with invented numbers nahi.
What you will learn in this chapter
- Mobile threat model – lost/stolen, malware, phishing, rogue apps, network attacks
- Android security basics – permissions, Play Protect concepts, sideloading risks (Blue hardening)
- iPhone / iOS basics – App Store, sandbox, Lockdown Mode awareness (Blue hardening)
- Signs a phone may be compromised – practical checklist, no invented scare stats
- Cleanup / response – passwords from a clean device, revoke sessions, factory reset last, bank / CERT awareness
- MDM / BYOD concepts for SME (fictional Sahyadri Traders)
- Bluetooth risks – pairing hygiene; BlueBorne-class awareness only (no exploit recipes)
- Wi-Fi on phones – evil twin / captive portal awareness; HTTPS / VPN concepts; own lab only
- App permissions, screen lock, biometrics, encryption at rest, updates + permission-hygiene lab
- Project Build-Hack-Fix for Raja-Rani Traders + ethics / IT Act (never touch others' phones)
Lab scope
Practice only on devices and VMs you own: Android emulator, a spare test phone you wiped, or host-only lab (Kali 192.168.56.10, Metasploitable 192.168.56.20, optional mobile-portal VM 192.168.56.50). Never install stalkerware, never steal OTP / SMS from someone else's phone, never pair Bluetooth "for fun" to strangers' earbuds, never run evil-twin gear against café / college Wi-Fi users. BlueBorne / Stagefright / Pegasus names = awareness and patching, not weaponized recipes. IT Act sections such as 43 and 66 apply if you access others' devices or accounts without authority (verify current text). Lab = learn hardening. Other people's phones = out of scope forever.
Concepts in this chapter
- 44.1Mobile Threat Model – What Can Go Wrong
- 44.2Android Security Model – Permissions, Play Protect, Sideloading
- 44.3iPhone / iOS Security Model – App Store, Sandbox, Lockdown Mode
- 44.4Signs a Phone May Be Compromised – Practical Checklist
- 44.5Cleanup and Response – If You Believe the Phone Is Compromised
- 44.6MDM and BYOD – SME Concepts for Sahyadri Traders
- 44.7Bluetooth Risks – Pairing Hygiene and BlueBorne Awareness
- 44.8Wi-Fi on Phones – Evil Twin and Captive Portal Awareness
- 44.9Hardening Checklist and Permission-Hygiene Lab
- 44.10Project, Ethics, IT Act and Purple Interview Lines
The chapter recap is at the end of the last concept page.