Tracking Down a Cell Phone Thief
Zone-MR writes "Last Saturday, MoDaCo (the world's largest smartphone community) held a get-together for their forum members. Unfortunately the positive community spirit was soured by an individual who decided to steal one of the charity raffle prizes - a C550 mobile phone. Check out the story of how we tracked the thief down, got the phone back, and secured the thief's place in the interweb's hall-of-shame."
Yeah seriously. Everyone knows it's 'intarweb'.
That has to be the dumbest thing ever. Stealing something guarenteed to broadcast its presence. And from within a tech convention?
Go Away! Not for Sale
http://zone-mr.net/?act=entry&id=36
/services/simlock_2.php - 82.163.137.156
Last Saturday, MoDaCo (the world's largest smartphone community) held a get-together for their forum members. Unfortunately the positive community spirit was soured by an individual who decided to steal one of the charity raffle prizes - a C550 mobile phone.
On Monday, Paul O'Brien (MoDaCo founder) contacted me with information on the stolen phone's IMEI number. I operate the SPV-Developers community which offers the free online SPV-Services unlock tool for this type of phone. It seemed likely that the thief would attempt to remove the SIMLock using this service in order to switch the phone to a non-UK network - bypassing the UK's IMEI blacklist which renders stolen phones useless.
Initially it seemed like there was little I could do to help. The SPV-Services server was not programmed to log the IMEI numbers of it's users. It seemed like a dead end, until I remembered something. When a user unlocks their phone, our server keeps a backup of the phone's first flash block (kept for a few days, in case the changes need to be reversed). This block contains 64kB of RSA-encrypted data such as the phone's SIMLock state, Carrier ID, and other concealed information - it seemed likely the IMEI would be buried within it. Shortly my suspicion was confirmed - after decrypting the block, the IMEI can be found inside (albeit scrambled with a simple transposition).
I started writing a short script - which would check each backup in turn to see if it originated from the stolen phone. After 30 minutes of writing, testing, and running the script - we had a match! The stolen phone had been unlocked. The creation timestamp on the backup file gave us an exact time - August 21, 2005, 10:18:32 PM.
The next step was cross-referencing this information with our web server logs. When a user uses our software to unlock their phone the software uploads the encrypted block to our server, which sends back a list of modifications which need to be made in order to remove the SIMLock. As we knew the exact time when this happened, we could find the corresponding web server entry :
2005-08-21 22:18:32 POST
Bingo! I passed this IP address back to Paul who cross-referenced it with Modaco's database. From this, he was able to identify the guilty member. A quick lookup confirmed that the IP was used by the account "Cocky" - a member which had attended the get-together. The event registrations contained the name of our theif, and his mobile number. The next day, Cocky (AKA Krassen P.) received a short phone call:
Paul: Hi, this is Paul from MoDaCo.
Cocky: Er, Hi.
Paul: You have something of mine, and I want it back.
Not surprisingly, Paul could hear the faint sound of the guy crapping himself at the other end of the line. The phone was returned, via special delivery, the following day. Moral of the story - even if you're enough of a cunt to steal from a charity raffle, don't be fucktarded enough to steal a phone from a community of phone experts.
...and a little luck.
While some good detective work was done by the MoDaCo admin(s?), a lot of thanks can be given to chance, because the cultprit was stupid enough to unlock his phone a) from a source well known to MoDaCo and b) from the same IP address. I'm calling it 25% good sleuthing, 75% dumb criminal.
oh the reasons you couldn't steal.. It is worth a laugh.
= 2037&
http://www.longislandpress.com/bb/viewtopic.php?p
...if it weren't for those lousy kids.
Here is the turd making a comment on the thread regarding the event and the missing phone.
t 225214-s15.html
http://www.modaco.com/Event_pictures_and_a_plea_-
What an idiot.
cunt
noun (vulgar slang) 1. a woman's genitals. 2. an unpleasant or stupid person.
You've obviously never heard UKers insult someone before.
"I won't mod you down - I feel the need to call you a twit explicitly, rather than by implication."
Nope. Wikipedia disagrees. But mentions Intarweb as an alternate spelling. http://en.wikipedia.org/wiki/Interweb
You must be fun at parties.
Did you even bother to read the article?
The only "personal info" they found was the IMEI (serial number) of the phone that was unlocked, and the IP address that the request was generated from. Neither of which is "personal", BTW (the phone was stolen, and the IP address belongs to his ISP).
They just matched that IP address against people who post in their usergroup forum and tracked the guy down.
So the only "personal info" they used was the phone's serial number and the IP address the server logged the request coming from. So I fail to see the point of your rant.
N.
"Nothing strengthens authority so much as silence." - Charles de Gaulle
If this had happened at the US Department of Homeland Security, they would have raised the alert level to Orange and we would be told to be on the lookout for slightly overweight middle-aged men with glasses, wearing dockers, using a cellphone.
Anyone seen using a cellphone in a dark corner or putting a cellphone in an inside pocket (trying to conceal it!) will be immediately taken in for questioning.
Henceforth, all cellphone usage will require a licence at the county courthouse, and people must submit valid reasons for having one, and give their fingerprints and DNA for registration.
Someone stole my sisters phone in high school (just about a year and a half ago). I just kept sending the phone text messages like:
"This is the Cincinnati Police. This is a stolen phone."
"Cincinnati Bell Telephone Theft Tracking Services - LAST CELL TOWER CONTACTED: #28302"
"THEFT NOTICE: ALL CALLS ARE MONITORED AND RECORDED"
And so forth... The next day she got it back before her first class started. It passed through six hands all with the note: "Return this to Sadie XXXXXXX"
Get your Unix fortune now!
I'll bite this troll.
We have repeatedly stated that we keep a TEMPORARY backup of the flash block we change - generally as a precaution in case we screw something up and need to restore the phone.