TGViewer
cKure Red cKure Red @ckured · 2.78K subscribers
Post #468 2.52K
p25.pdf593.2 KB
🖥 Header Enrichment: A technique used by Telco operators to acquire MSISDN (phone number) through a website (HTTP-GET is enough).

It can be used to trace users and target them for ads by the ISP or their associated vendors. And if the API key 🔑 is leaked through a vendor or ISP itself.

Scenarios:
1. The token can be used by anyone in a get request to fetch the end-user's phone number. This request can be posted via QR-codes of restaurant menus where there will be HTTP-302 (redirection) to the actual menu or by injecting 💉.js in a vulnerable website (viz. XSS); which is famous (like some blog or forum).

2. A user sharing hotspot from their phone, the hotspot client can acquire the phone number. In addition to this, if the HE enables authentication. This would lead to 0-click account takeover.


● I had tested systems for this implementation for a telco. The telco without informing users (IMHO) was sharing data to third parties.
-Admin cKure


Source: https://conferences.sigcomm.org/sigcomm/2015/pdf/papers/hotmiddlebox/p25.pdf
More from @ckured
  1. Oct 11, 2026cKure Red pinned «🖥 REA: Reverse Engineer Anything One MCP for reverse engineering across…
  2. Oct 11, 2026🖥 REA: Reverse Engineer Anything One MCP for reverse engineering across binaries, applica…
  3. Oct 3, 2026Update: Archivegenocide has now crossed 200,000 videos & images, which is almost triple wh…
  4. Sep 29, 2026📱 Telegram OSINT tactics
  5. Sep 26, 2026☁️ Italian firm Dataflow Security, founded in 2019 by young hacker Luca Todesco, develops…
  6. Sep 23, 2026Alleged Google Pixel 10 Zero Day at 2.5K USD only as chain included some n-days. An intere…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →