Ravindra BagaleCourses & study guides

44. Mobile Device Security – Android, iPhone, Bluetooth and Wi-Fi

Chala mitrano, Chapter 43 madhe IoT / OT baghitla – aata mobile phones. Pocket madhe full computer: bank apps, OTP, WhatsApp business, camera, GPS. CEH exam modules madhe mobile topic yeto, pan aapan he shikto defence-first: lost phone, rogue APK, evil twin Wi-Fi, Bluetooth pairing risk – kasa Blue harden karto. Ghabru naka – OWN emulator / second test phone / host-only lab (Kali 192.168.56.10, optional target 192.168.56.50). Neighbour / colleague / stranger cha phone never. Stalkerware, OTP steal, silent spyware recipes – nahi. Lakshat theva: phone hacked aahe ka? – checklist + cleanup from a clean device; scare tactics with invented numbers nahi.

What you will learn in this chapter

  • Mobile threat model – lost/stolen, malware, phishing, rogue apps, network attacks
  • Android security basics – permissions, Play Protect concepts, sideloading risks (Blue hardening)
  • iPhone / iOS basics – App Store, sandbox, Lockdown Mode awareness (Blue hardening)
  • Signs a phone may be compromised – practical checklist, no invented scare stats
  • Cleanup / response – passwords from a clean device, revoke sessions, factory reset last, bank / CERT awareness
  • MDM / BYOD concepts for SME (fictional Sahyadri Traders)
  • Bluetooth risks – pairing hygiene; BlueBorne-class awareness only (no exploit recipes)
  • Wi-Fi on phones – evil twin / captive portal awareness; HTTPS / VPN concepts; own lab only
  • App permissions, screen lock, biometrics, encryption at rest, updates + permission-hygiene lab
  • Project Build-Hack-Fix for Raja-Rani Traders + ethics / IT Act (never touch others' phones)

Lab scope

Practice only on devices and VMs you own: Android emulator, a spare test phone you wiped, or host-only lab (Kali 192.168.56.10, Metasploitable 192.168.56.20, optional mobile-portal VM 192.168.56.50). Never install stalkerware, never steal OTP / SMS from someone else's phone, never pair Bluetooth "for fun" to strangers' earbuds, never run evil-twin gear against café / college Wi-Fi users. BlueBorne / Stagefright / Pegasus names = awareness and patching, not weaponized recipes. IT Act sections such as 43 and 66 apply if you access others' devices or accounts without authority (verify current text). Lab = learn hardening. Other people's phones = out of scope forever.

Concepts in this chapter

  1. 44.1Mobile Threat Model – What Can Go Wrong
  2. 44.2Android Security Model – Permissions, Play Protect, Sideloading
  3. 44.3iPhone / iOS Security Model – App Store, Sandbox, Lockdown Mode
  4. 44.4Signs a Phone May Be Compromised – Practical Checklist
  5. 44.5Cleanup and Response – If You Believe the Phone Is Compromised
  6. 44.6MDM and BYOD – SME Concepts for Sahyadri Traders
  7. 44.7Bluetooth Risks – Pairing Hygiene and BlueBorne Awareness
  8. 44.8Wi-Fi on Phones – Evil Twin and Captive Portal Awareness
  9. 44.9Hardening Checklist and Permission-Hygiene Lab
  10. 44.10Project, Ethics, IT Act and Purple Interview Lines

The chapter recap is at the end of the last concept page.