Privacy Leaks in Mobile Phone Internet Access
|
|
|
- Shawn Woods
- 10 years ago
- Views:
Transcription
1 1 Privacy Leaks in Mobile Phone Internet Access Collin Mulliner Security in Telecommunications Technische Universität Berlin / Deutsche Telekom Labs Berlin D-10587, Germany [email protected] Abstract Accessing the Internet and specifically the World Wide Web from a mobile phone is common today. Especially since the usage fees for packet-data access dropped to a point where anybody who can can afford a mobile phone can afford mobile Internet access. Almost every mobile phone today comes with an integrated web browser that can display HTML web pages and execute JavaScript. Almost all major web sites such as news sites, social networks, and shopping sites run websites that are optimized for small displays of mobile phones. Due to the broad use of mobile web access we investigated possible privacy problems of mobile phone web access. We conducted a study where we monitor all HTTP headers sent from mobile phones to our web server. We analyzed the logged data for privacy problems. Through this study we determined that a world wide privacy problem exists when accessing the world wide web from a mobile phone. We show what kind of data is leaked and who leaks it. Keywords: Web Security, Mobile Phone Internet, Privacy, Data Collection. I. INTRODUCTION Accessing the Internet and specifically the World Wide Web from a mobile phone is common today. In the past mobile web access was purely in the domain of high-end smart phones since only those devices had the processing power to render and display HTML content. The cheaper feature phones were mostly bound to the Wireless Application Protocol (WAP) [6] part of the Internet. Further, packet-data was expensive in the past but today packet-data is relatively cheap all around the world (even without a special packet-data plan). Today most feature phones posses the processing power to display HTML pages. Therefore, current feature phones come with real web browsers that even support JavaScript. The combination of both, cheap packet-data and cheap phones with web browsing capabilities enable mobile web access all around the world. Especially users in developing countries seem to profit from these developments. Due to the broader use of this technology we decided to investigate the privacy implications that arise through mobile phone web access. Our investigation specifically targets the so-called feature phones and low price range smart phones. We specifically do not investigate high-end smart phones such as the iphone and Android-based devices, since those platforms are study quite well [5]. Our interest in the topic was further sparked since we stumbled across multiple online /10/$26.00 c 2010 IEEE discussion forums 1 where this topic was discussed. The main issue was that those discussions did not come to any meaningful result since only rumors and very simple studies where presented by the individuals. Therefore, we decided to investigate for ourselfs. The only bit of information that seemed coherent is that some private information is leaked through HTTP [3] headers. In this paper we presented a study on if and how private data is leaked through mobile phone-based web access. The study concentrates on data that is leaked through HTTP headers. One important point is that in order to access the leaked data communication does not need to be intercepted in any way. The data is delivered to any web server visited from a mobile phone. The main study was conducted over the period of 12 month, overall we spent 18 month on this project since we only slowly learned what kind of data exists and how we can find it. The work is separated in four parts. First, data acquisition. Second, identifying interesting HTTP header fields. Third, data analysis. Forth, determine how and why data is added to the HTTP connections in the first place. Relatively early in the project we decided to mainly look for leaked mobile phone numbers, but we briefly discuss the other kind of information we found. At the end of our study we created our mobile privacy checker where privacy concerned users can go and test if their private data is leaked. The main contributions of this paper are: We show that private data is leaked by many mobile operators around the world. We show that anybody owning a website that gets viewed from a mobile phone has the ability to collect personal information about his visitors. We show why this leak hasn t gotten any attention so far, this is because until now nobody knew what to look for exactly. The rest of this paper is structured in the following way. In Section II we briefly describe how mobile phone Internet access works. In Section III we explain how we acquired
2 2 is shown in Figure 2. Fig. 1. Typical Internet settings that are provided by a mobile operator. our data. In Section IV we describe in great detail how we analyzed our data. Section V shows where and why the data is injected into the HTTP connection. In Section VI we present our findings. Section VII discusses potential cases for abuse of such data, and in Section VIII we draw our conclusions. Further we acquired pre-paid SIM cards from all mobile operators in Germany in order to do some minimal testing ourselfs. We did not want to purely rely on external data. The hope was that one of the operators or the reseller of their pre-paid product would cause a data leakage that we could investigate further and analyze. Luckily one of our test cards caused such a data leakage. The complete log entry containing all HTTP headers is shown in Figure 2. The logged phone number is actually the phone number of the author s test SIM card, therefore, we are confident that the leaked data is a real privacy leak. We want to emphasis that we do not want to discredit this operator. We just tested local operators and show the for us lucky result. II. MOBILE PHONE INTERNET ACCESS Mobile phone Internet access depends on a few settings in the mobile phone. The Access Point Name (APN), user name and password (mostly unused in consumer contracts), and HTTP and WAP proxy address and ports. These settings are either pre-configured in the mobile phone or are configured into the mobile phone by either the mobile operator through Over-The-Air (OTA) Provisioning or the user by going to the phones settings and manually entering each configuration parameter. A typical set of configuration options for mobile phone Internet access is shown in Figure 1. The information was obtained from a mobile network operators website, we blurred out any information that are operator specific since this is not relevant. III. DATA ACQUISITION Data acquisition for such a project is complicated for a very simple reason. How to get enough people to visit your website using their mobile phone. Luckily the author of this paper owns a website that falls in this criteria. A few years ago he developed some games for the J2ME 2 (Java 2 Micro Edition) platform and thus people visits his website 3 to download the games. Furthermore a big mobile gaming website embeds images (screen shots of these games) from the authors website, therefore, every time a visitor loads the relevant page at the gaming website a request is sent to our web server. Due to this circumstances we get quite a lot of relevant traffic. The logging itself was done in two parts. First we added a rewrite rule to the configuration of our Apache 4 web server. The rewrite rule redirected all request that requested an image file to a script. The script logged all HTTP headers send by the client and returned the request image. The second part of the logging was done by adding a few lines of PHP[1] to the code that generates the web pages for the authors website. Therefore, every access to the authors website could be logged just as with the image requests. A typical data set IV. DATA ANALYSIS We analyzed the data in two steps. In the first step we sort all HTTP headers by occurrence so that the header that was seen the least number of times is on top of the list. We did this since we were sure that only very few of the log entries would contain interesting headers, and, therefore, a low number of occurrences indicate interesting content. From this list we manually extracted interesting header names. We discuss what makes a header interesting further below. In the second step we filter for log entries that contain these interesting headers. Finally we build a tool to analyze the list of log entries that contain the interesting headers. In this step we extract information such as the MSISDN 5 (the mobile phone number) and the IMSI 6 (the unique ID of a SIM 7 card). A. Identifying Interesting HTTP Headers In order to be able to identify interesting HTTP header names one has to be familiar with some parts of the mobile phone service terminology. Words and abbreviations such as MSISDN, IMSI, IMEI 8, line ID, APN, roaming, and subscriber to name just a few. Armed with a list of words one can start hunting for header names. Once you get a feeling for it you constantly find more and more headers that look interesting. Our primary goal was to find headers that contain the users mobile phone number (MSISDN) so we started looking for fields that contain only numbers. We had multiple strangely interesting finds during the search. For example the COOKIE header that contained a list of other HTTP headers including a header named MSISDN. Further we found that some of the headers contain the MSISDN in hex encoded form, this is shown in the first example in Figure 4. V. THE DATA LEAKAGE Now that we found a substantial amount of private data in HTTP headers sent to our web server we investigated the 5 Mobile Subscriber Integrated Services Digital Network Number 6 Integrated Mobile Subscriber Identity 7 Subscriber Identity Module 8 International Mobile Equipment Identity
3 3 Header Name Content ==================== ============================================================== HOST mulliner.org USER-AGENT Mozilla/5.0 (X11; U; Linux armv7l; en-us; rv:1.9.2a1pre) Gecko/ Firefox/3.5 Maemo Browser RX-51 N900 ACCEPT image/png,image/*;q=0.8,*/*;q=0.5 ACCEPT-LANGUAGE en ACCEPT-ENCODING * ACCEPT-CHARSET ISO ,utf-8;q=0.7,*;q=0.7 REFERER X-UP-SUBNO xxx xxx X-UP-FORWARDED_FOR X-FORWARDED_FOR X-UP-CALLING-LINE-ID xxxx X-UP-SUBSCRIBER-COS System,UMTS,SX-LIVPRT,A02-MADRID-1BILD-VF-DE,Vodafone,Prepaid, Rot MAX-FORWARDS 10 VIA 1.1 rn2wwpsv161-ncl-0.wwp.vodafone.de CONNECTION close REMOTE_ADDR Fig. 2. Header information leaked by BILDmobil. The log was produced by the author using his own SIM card. VI. FINDINGS We split our findings in to two parts. In part one we discuss the technical part of what HTTP headers leak what kind of data. In part two we discuss our quantitative results. Fig. 3. cause for this. The proxy adding private data to the HTTP connection. We determine that the HTTP headers are added by the HTTP and/or WAP proxy on the mobile operators network. Multiple facts add to this conclusion. First, we know that some operators do this in order to provide their third party application developers with the means to identify users for billing purposes [2]. Second, a mobile phone does not store all the data that shows up in the various headers. Data that is not present on the phone can not be sent out. A good example is the subscriber number (X-UP-SUBNO shown in Figure 2) that we found in the log entry that we produced with our own SIM card. Third, we do not have any log entries from smart phones that normally do not use an HTTP proxy by default such as the iphone or Android-based devices. Therefore, we conclude that the HTTP/WAP proxy is adding the relevant HTTP headers. Figure 3 shows a simplified picture of this setup. A. HTTP Headers Since we concentrated on identifying HTTP headers that contain the MSISDN we spent the most time on this subject. Figure 5 shows a list of all the HTTP headers we identified to contain the MSISDN in some form. The fact that twenty (20) different headers can contain the mobile phone number adds to the fact that nobody before us was able to point out the huge privacy problem of this leakage. Also notable is the COOKIE header since this header is normally used for another purpose, and, therefore, is clearly abused. Further we found headers such as X-FH-SUBSCRIBER-INFO and X-NETWORK-INFO that contain multiple pieces of information related to the users connectivity (including the MSISDN). Figure 4 shows some example of these combined headers. B. Quantitative Results In the previous section we discussed what HTTP headers contain what data. In this section we want to give a brief overview of how many individual mobile phone numbers (MSISDNs) we actually logged. We further show where the phone numbers belong to, meaning from which country. We used the international country code number prefix to identify the country an individual phone number is registered at. The country codes are standardized by the International Telecommunications Union (ITU) and can be found in [4]. In addition we used the IP address of each data set (REMOTE- ADDR) to verify the name of the operator and country. This works well since all operators that serve multiple countries
4 4 COOKIE: User-Identity-Forward-msisdn= xxxxxxxx;Bearer-Type= w-tcp;wtls-security-level=none;network-access-type=gprs;called-station-id=wap.mascom COOKIE: User-Identity-Forward-msisdn= xxxx;Bearer-Type=w-TCP; wtls-security-level=none;network-access-type=gprs;roaming-information=no_info COOKIE: X-SDP-MSISDN= xxxx; Bearer-Type=w-TCP; wtls-security-level=none; network-access-type=gprs X-WAP-FH-SUBSCRIBER-INFO: IP= ,MSISDN= xxxx,APN=postpaid.celcom3g X-WAP-FH-SUBSCRIBER-INFO: IP= ,MSISDN= xxxx,APN=prepaid.celcom3g X-NETWORK-INFO: 3G, , xxxx, ,unsecured Fig. 4. HTTP headers that contain multiple items. Fig. 5. Header Name Count X-UP-CALLING-LINE-ID 324 X-NOKIA-MSISDN 238 X-MSISDN 203 X-H3G-MSISDN 125 MSISDN 106 COOKIE 67 RAPMIN 41 X-WAP-FH-SUBSCRIBER-INFO 16 X-FH-MSISDN 16 X-HTS-CLID 16 X-MSP-CLID 15 X-UP-LSID 12 X-JINNY-CID 7 X-NETWORK-INFO 5 X-MSP-MSISDN 4 X-NX-CLID 4 X-WAP-MSISDN 3 IGCLI 2 X-WSB-CLI 2 X-ORANGE-CLI 2 HTTP headers that contain the MSISDN. seem to have separate IP ranges for their mobile customers in each country. Therefore, the IP address can used to verify the country of origin of a individual data set. In some rare cases this was not possible here we spent more time verifying the origin. Figure 6 shows the count of unique mobile phone numbers per country in our log file. We only list countries where we at least have two unique phone numbers. We have 13 additional countries where we only logged one individual number. This means we have collected 1183 phone numbers of 67 countries. Note, adding the numbers of Figure 5 will show a higher number this is the case since some log entries actually contain up to three headers that contain the MSISDN. Count Fig Algeria Australia Bangladesh Bosnia Botswana Brazil Brunei China Ecuador Egypt Fiji Finland Germany Guadeloupe Guyana India Iran Ireland Israel Italy Ivory Coast Jordan Kuwait Kyrgyzstan Libya Malawi Malaysia Mauritius Montenegro Nepal New Zealand Nigeria Pakistan Paraguay Peru Philippines Romania Saudi Arabia Singapore South Africa Sri Lanka Thailand Tunisia Turkey UK USA/Canada Ukraine Uruguay Uzbekistan Venezuela Vietnam Countries Countries we collected more then one MSISDN from. C. Other interesting data Besides hunting for HTTP headers that contain the MSISDN we further analyzed our data set. We stumbled upon multiple interesting kinds of headers. These headers contain the IMSI (the unique SIM card ID), Bearer type (the type of communication channel), the roaming status, and the access point name (APN). Figure 7 shows a list of HTTP headers that contain bearer information. Through looking at this header one can easily determine how a particular mobile phone is connected to the Internet. What is unique about the bearer header is that it is inserted by the mobile phone itself. Figure 8 shows a list of HTTP headers that indicate of the subscriber is currently roaming (out side of his home network). Some of the examples in Figure 4 also contain the APN. Also additional headers exist that just contain the APN. VII. ABUSE The main abuse of this information leak is user tracking. In some countries one can do a reverse lookup of phone numbers. This means for those countries one can take a mobile phone number and actually determine the name (first and last) and
5 5 Header Name X-NOKIA-MUSICSHOP-BEARER X-NOKIA-BEARER X-UP-BEAR-TYPE BEARER-INDICATION X-UP-BEARER-TYPE X-BEARER-TYPE NOKIA-BEARER BEARER NEW-BEARER-HEADER Observed Content (separated by comma) WLAN,GPRS/3G GPRS,UMTS-p,GPRS or 3G,CSD,UMTS,258,2G,4,3G GPRS,WCDMA,gprs,GPRS/EDGE 11,0,gprs,gsm gprs ipv4 GPRS,128,0 GPRS,UMTS GPRS GPRS GPRS Fig. 7. HTTP headers that contain bearer information. Header Name Observed Content (separated by comma) X-ORANGE-ROAMING YES,NO X-ROAMING True,Yes,False,NO X-SDP-ROAMDING True,False X-NOKIA-ROAMING 0 Fig. 8. HTTP headers that contain roaming information. maybe even the address of the visitors of his website. Das Telefonbuch 9 offers such a backward search for Germany. User tracking is very likely since the phone number is internationally unique. Further the phone number will stay even if the user changes to a new mobile phone (e.g. after an upgrade or warranty replace). This enables reliable longterm tracking possibilities. Large commercial and social networking sites that operate a mobile version of their site can collect this information to enrich the profile data that they already have about their users. A. Counter Measures The true solution is to change the configuration in the HTTP proxies operated by the mobile network operators and the external companies that run those proxies for the operators. In the best case the data injection is completely turned off. If the data is actually used by either the operator himself or by authorized third parties, measures must be taken so that the data is only injected into connections that terminate inside the operator network or at hosts belonging to authorized third parties. The user has actually no way of disabling the data leakage himself besides disabling the HTTP proxy in the configuration of his mobile phone. This may not be possible since the users mobile phone contract conditions may require using this specific proxy. In order to provide concerned users with means to check if their mobile service operator for HTTP header privacy leaks we have setup a simple web page. When a user browses to our page we analyze the transmitted HTTP headers and give an instant feedback to the user. The feedback contains a general YES or NO feedback and in addition we display the transmitted headers that raised our concern. 9 Fig. 9. Our mobile network operator privacy checking website. VIII. CONCLUSIONS In this paper we present a study on privacy leaks of mobile phone web access. The privacy leak is related to the HTTP proxies operated by the mobile phone network operators. The proxies inject additional headers into HTTP connections and thus cause the privacy leak. The leaked data can be acquired by anybody who runs a website that gets visited from a mobile phone. Through our study we now know why this privacy leak has not been detected by other people like those discussing in various online forums. The answer is the large number of different HTTP headers that carry the information. Looking only at one particular HTTP header does not provide you with the real picture, one needs to look at all headers. Also the kind of headers used seems largely dependent on the operator. The privacy leak is not necessary and could potentially be exploited by malicious parties. Attacks based on the leaked data could range from longterm user tracking since some of the data is depended on the users account at the operator rather
6 6 than being bound to the users handset. The real names of website visitors could be determined through the use of reverse lookup databases that map phone numbers to real names. REFERENCES [1] PHP: Hypertext Processor. [2] AT&T. WAP 2.0 User Identification for Secure Services. technologies/technologies/ docs/wap 2-0 User Identification Secure Services.pdf, [3] R. Fielding, J. Gettys, J. Mogul, H. Frystyk, L. Masinter, P. Leach, and T. Berners-Lee. Hypertext transfer protocol http/1.1, [4] International Telecommunication Union. LIST OF ITU-T RECOMMEN- DATION E.164 ASSIGNED COUNTRY CODES. dms pub/itu-t/opb/sp/t-sp-e.164d-2009-pdf-e.pdf, April [5] Nicolas Seriot. iphone Privacy. papers/ iphoneprivacy.pdf, [6] WAP Forum. WAP-230-WSP Wireless Application Protocol Wireless Session Protocol Specification
Appendix 1: Full Country Rankings
Appendix 1: Full Country Rankings Below please find the complete rankings of all 75 markets considered in the analysis. Rankings are broken into overall rankings and subsector rankings. Overall Renewable
Cisco Global Cloud Index Supplement: Cloud Readiness Regional Details
White Paper Cisco Global Cloud Index Supplement: Cloud Readiness Regional Details What You Will Learn The Cisco Global Cloud Index is an ongoing effort to forecast the growth of global data center and
Your Access to a World of Global Connectivity. www.nevigate.net
Your Access to a World of Global Connectivity Agenda Company Background / Profile Our Commitment Coverage Strengths Products Portfolio Deliverables Measurable Benefits Support Company Background Nevigate
Consolidated International Banking Statistics in Japan
Total (Transfer Consolidated cross-border claims in all currencies and local claims in non-local currencies Up to and including one year Maturities Over one year up to two years Over two years Public Sector
World Consumer Income and Expenditure Patterns
World Consumer Income and Expenditure Patterns 2014 14th edi tion Euromonitor International Ltd. 60-61 Britton Street, EC1M 5UX TableTypeID: 30010; ITtableID: 22914 Income Algeria Income Algeria Income
Bangladesh Visa fees for foreign nationals
Bangladesh Visa fees for foreign nationals No. All fees in US $ 1. Afghanistan 5.00 5.00 10.00 2. Albania 2.00 2.00 3.00 3. Algeria 1.00 1.00 2.00 4. Angola 11.00 11.00 22.00 5. Argentina 21.00 21.00 42.00
Proforma Cost for international UN Volunteers for UN Partner Agencies for 2016. International UN Volunteers (12 months)
Proforma Cost for international UN Volunteers for UN Partner Agencies for 2016 Country Of Assignment International UN Volunteers (12 months) International UN Youth Volunteers (12 months) University Volunteers
Carnegie Mellon University Office of International Education Admissions Statistics for Summer and Fall 2015
Carnegie Mellon University Admissions Statistics for and Fall 2015 New International Students and Fall 2015 Undergraduate 344 15.2% Master's 1599 70.6% Doctorate 167 7.4% Exchange 73 3.2% 81 3.6% Total
TRANSFERS FROM AN OVERSEAS PENSION SCHEME
PENSIONS PROFILE DECEMBER 2011 TRANSFERS FROM AN OVERSEAS PENSION SCHEME = Summary A simplified guide to the process: 1. Individual requests transfer from their overseas pension scheme to their UK registered
Carnegie Mellon University Office of International Education Admissions Statistics for Summer and Fall 2013
Carnegie Mellon University Admissions Statistics for and Fall 2013 New International Students and Fall 2012 Undergraduate 270 14.3% Master's 1301 68.7% Doctorate 192 10.1% Exchange 99 5.2% 31 1.6% Total
List of Agreements on Mutual Visa Exemption. Between the People s Republic of China and Foreign Countries
List of Agreements on Mutual Visa Exemption Between the People s Republic of China and Foreign Countries (In alphabetical order of foreign countries) Last Update: May 9, 2015 No. Foreign Country Passport
Senate Committee: Education and Employment. QUESTION ON NOTICE Budget Estimates 2015-2016
Senate Committee: Education and Employment QUESTION ON NOTICE Budget Estimates 2015-2016 Outcome: Higher Education Research and International Department of Education and Training Question No. SQ15-000549
DuchenneConnect. www.duchenneconnect.org
DuchenneConnect www.duchenneconnect.org 1 What is DuchenneConnect? Web based patient self report registry to link the resources and needs of the Duchenne/Becker muscular dystrophy community, including:
Raveh Ravid & Co. CPA. November 2015
Raveh Ravid & Co. CPA November 2015 About Us Established in 1986 by Abir Raveh, CPA & Itzhak Ravid, CPA 6 Partners, 80 employees Located in Tel Aviv, Israel wide range of professional services highly experienced
Random tales from a mobile phone hacker
Random tales from a mobile phone hacker Collin Mulliner Security in Telecommunications Technical University Berlin, Germany CanSecWest 2010 Vancouver, Canada 1 About Myself Mobile device security researcher
GLOBAL PAYMENTS AND CASH MANAGEMENT. HSBCnet Application Guide August 2006
GLOBAL PAYMENTS AND CASH MANAGEMENT HSBCnet Application Guide August 2006 HSBCnet Application Guide TABLE OF CONTENT Page Overview 1 Step 1 Verifying the Minimum System Requirements 2 1.1 Operating System
LTE Technology and Rural Broadband DiploFoundation Webinar. Milan Vuckovic Analyst, Wireless Policy Development Verizon Communications
LTE Technology and Rural Broadband DiploFoundation Webinar Milan Vuckovic Analyst, Wireless Policy Development Verizon Communications August 28, 2012 Presentation Outline Snapshot of Verizon & US Mobile
Global Dialing Comment. Telephone Type. AT&T Direct Number. Access Type. Dial-In Number. Country. Albania Toll-Free 00-800-0010 888-426-6840
Below is a list of Global Access Numbers, in order by country. If a Country has an AT&T Direct Number, the audio conference requires two-stage dialing. First, dial the AT&T Direct Number. Second, dial
Contact Centers Worldwide
A Contact Centers Worldwide Country Tel.no. Supported lang. Contact Center Albania Algeria 852 665 00 +46 10 71 66160 Angola 89900 +34 91 339 2121 (Port) and Portuguese +34 913394044 +34 913394023 (Por)
CISCO CONTENT SWITCHING MODULE SOFTWARE VERSION 4.1(1) FOR THE CISCO CATALYST 6500 SERIES SWITCH AND CISCO 7600 SERIES ROUTER
PRODUCT BULLETIN NO. 2438 CISCO CONTENT SWITCHING MODULE SOFTWARE VERSION 4.1(1) FOR THE CISCO CATALYST 6500 SERIES SWITCH AND CISCO 7600 SERIES ROUTER NEW FEATURES New features of the Cisco Content Switching
89% 96% 94% 100% 54% Williams 93% financial aid at Williams. completion statistics $44,753 76% class of 2013 average four-year debt: $12,749
financial aid at Average - $, financial aid is comprehensive, covering books, health insurance, study abroad costs, travel, and personal expenses % % % % cost met by average % of with demonstrated need
FDI performance and potential rankings. Astrit Sulstarova Division on Investment and Enterprise UNCTAD
FDI performance and potential rankings Astrit Sulstarova Division on Investment and Enterprise UNCTAD FDI perfomance index The Inward FDI Performance Index ranks countries by the FDI they receive relative
Composition of Premium in Life and Non-life Insurance Segments
2012 2nd International Conference on Computer and Software Modeling (ICCSM 2012) IPCSIT vol. 54 (2012) (2012) IACSIT Press, Singapore DOI: 10.7763/IPCSIT.2012.V54.16 Composition of Premium in Life and
Bug Report. Date: March 19, 2011 Reporter: Chris Jarabek ([email protected])
Bug Report Date: March 19, 2011 Reporter: Chris Jarabek ([email protected]) Software: Kimai Version: 0.9.1.1205 Website: http://www.kimai.org Description: Kimai is a web based time-tracking application.
Outsource International Ltd
Providing global technology solutions for: Carriers Systems Integrators Resellers Outsource Manufacturers International Ltd Government agencies Financial sector Global Technology Solutions Providing global
Know the Facts. Aon Hewitt Country Profiles can help: Support a decision to establish or not establish operations in a specific country.
Aon Hewitt Country Profiles Your eguide to employment requirements and practices Profiles for nearly 90 countries worldwide Risk. Reinsurance. Human Resources. Know the Facts Whether you are a newcomer
CMMI for SCAMPI SM Class A Appraisal Results 2011 End-Year Update
CMMI for SCAMPI SM Class A 2011 End-Year Update Software Engineering Institute Carnegie Mellon University Pittsburgh, PA 15213 1 Outline Introduction Current Status Community Trends Organizational Trends
Business Phone. Product solutions. Key features
Product solutions Enjoy free calls and significant savings on your business landline bills with from International. Set-up is simple and you don t need to change your existing telephone numbers, plus there
Mineral Industry Surveys
4 Mineral Industry Surveys For information contact: Robert L. Virta, Asbestos Commodity Specialist U.S. Geological Survey 989 National Center Reston, VA 20192 Telephone: 703-648-7726, Fax: (703) 648-7757
Digital TV Research. http://www.marketresearch.com/digital-tv- Research-v3873/ Publisher Sample
Digital TV Research http://www.marketresearch.com/digital-tv- Research-v3873/ Publisher Sample Phone: 800.298.5699 (US) or +1.240.747.3093 or +1.240.747.3093 (Int'l) Hours: Monday - Thursday: 5:30am -
Global Education Office University of New Mexico MSC06 3850, Mesa Vista Hall, Rm. 2120 Tel. 505 277 4032, Fax 505 277 1867, geo@unm.
Global Education Office University of New Mexico MSC06 3850, Mesa Vista Hall, Rm. 220 Tel. 505 277 4032, Fax 505 277 867, [email protected] Report on International Students, Scholars and Study Abroad Programs
The World Market for Medical, Surgical, or Laboratory Sterilizers: A 2013 Global Trade Perspective
Brochure More information from http://www.researchandmarkets.com/reports/2389480/ The World Market for Medical, Surgical, or Laboratory Sterilizers: A 2013 Global Trade Perspective Description: This report
THE ADVANTAGES OF A UK INTERNATIONAL HOLDING COMPANY
THE ADVANTAGES OF A UK INTERNATIONAL HOLDING COMPANY Ideal Characteristics for the Location of an International Holding Company Laurence Binge +44 (0)1372 471117 [email protected] www.woolford.co.uk
MAUVE GROUP GLOBAL EMPLOYMENT SOLUTIONS PORTFOLIO
MAUVE GROUP GLOBAL SOLUTIONS PORTFOLIO At Mauve Group, we offer a variety of complete employee management services such as Global Employment Solutions (GES), Professional Employment Outsourcing (PEO),
ISO is the world s largest developer of voluntary international
The ISO Survey 2005 ISO and The ISO Survey ISO is the world s largest developer of voluntary international standards for business, government and society. Its portfolio at the beginning of June 2006 comprised
Strong in service. Worldwide. CHOOSE THE NUMBER ONE.
Strong in service. Worldwide. CHOOSE THE NUMBER ONE. We are always there for you! Our most important asset is our commitment and our technical expertise. Peter Pauli, Head of After Sales (middle) Roland
List of tables. I. World Trade Developments
List of tables I. World Trade Developments 1. Overview Table I.1 Growth in the volume of world merchandise exports and production, 2010-2014 39 Table I.2 Growth in the volume of world merchandise trade
GLOBAL. 2014 Country Well-Being Rankings. D Social (% thriving) E Financial (% thriving) F Community (% thriving) G Physical (% thriving)
0 0 GLOBAL 0 Country Rankings 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 : >0.0% 0.% 0.0% 0.% 0.0% 0.% 0.0% 0.0% A Country s global rank B in three or more elements of well-being C (% thriving) D (% thriving) E
EMEA BENEFITS BENCHMARKING OFFERING
EMEA BENEFITS BENCHMARKING OFFERING COVERED COUNTRIES SWEDEN FINLAND NORWAY ESTONIA R U S S I A DENMARK LITHUANIA LATVIA IRELAND PORTUGAL U. K. NETHERLANDS POLAND BELARUS GERMANY BELGIUM CZECH REP. UKRAINE
International Call Services
International Call Services Affordable rates for business calls. Wherever you are in the world. We ve got plenty to say when it comes to staying in touch when you re overseas. We have agreements with 443
Enterprise Mobility Suite (EMS) Overview
Enterprise Mobility Suite (EMS) Overview Industry trends driving IT pressures Devices Apps Big data Cloud 52% of information workers across 17 countries report using 3+ devices for work Enable my employees
Netherlands Country Profile
Netherlands Country Profile EU Tax Centre March 2012 Key factors for efficient cross-border tax planning involving Netherlands EU Member State Yes Double Tax Treaties With: Albania Czech Rep. Jordan Nigeria
Introducing GlobalStar Travel Management
Introducing GlobalStar Travel Management GlobalStar is a worldwide travel management company owned and managed by local entrepreneurs. In total over 80 market leading enterprises, representing over US$13
International Fuel Prices 2012/2013
International Fuel Prices 212/213 8 th Edition Published by International Fuel Prices 212/213 8 th Edition Disclaimer Findings, interpretation and conclusions expressed in this document are based on the
PAY MONTHLY ADDITIONAL SERVICES TERMS AND CONDITIONS
4GEE PHONE PLANS ADDITIONAL SERVICES (ALL STANDARD 12 & 24 MONTH PLANS INCLUDING SIM ONLY PLANS) The following add-ons are available on your plan. We reserve the right to change the add-ons available to
Fall 2015 International Student Enrollment
Fall 2015 International Student Enrollment Prepared by The Office of International Affairs Nova Southeastern University Nova Southeastern University International Student Statistics Fall 2015 International
What it costs. Pay as you go.
What it costs Pay as you go. Price Plans and call charges for pay as you go customers. After 1 July 2014 2 Price Plans Everyday plan When you first join us on pay as you go, you ll automatically join our
Anatomy of a Pass-Back-Attack: Intercepting Authentication Credentials Stored in Multifunction Printers
Anatomy of a Pass-Back-Attack: Intercepting Authentication Credentials Stored in Multifunction Printers By Deral (PercX) Heiland and Michael (omi) Belton Over the past year, one focus of the Foofus.NET
DEPLOYMENT GUIDE Version 1.1. Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5
DEPLOYMENT GUIDE Version 1.1 Deploying the BIG-IP LTM v10 with Citrix Presentation Server 4.5 Table of Contents Table of Contents Deploying the BIG-IP system v10 with Citrix Presentation Server Prerequisites
Cisco IOS Public-Key Infrastructure: Deployment Benefits and Features
Data Sheet Cisco IOS Public-Key Infrastructure: Deployment Benefits and Features Introduction to Public Key Infrastructure Public Key Infrastructure (PKI) offers a scalable method of securing networks,
steam & condensate management solutions STAPS Wireless steam trap monitoring
steam & condensate management solutions STAPS Wireless steam trap monitoring S T A P S W i r e l e s s STAPS Total acoustic performance solutions The STAPS wireless steam trap monitor from Spirax Sarco
INTERNATIONAL AIR SERVICES TRANSIT AGREEMENT SIGNED AT CHICAGO ON 7 DECEMBER 1944
State INTERNATIONAL AIR SERVICES TRANSIT AGREEMENT SIGNED AT CHICAGO ON 7 DECEMBER 1944 Entry into force: The Agreement entered into force on 30 January 1945. Status: 130 Parties. This list is based on
Audio Conferencing Service Comprehensive Telecommunications Services Group Number 77017 Award Number 20268 Contract Number PS63110
Audio Conferencing Comprehensive Telecommunications s Number PS63110 Audio Conferencing, Function or Device Reservationless Conferencing Solution Setup Meeting Center Multimedia Minute - Self-, Automated
WPAD TECHNOLOGY WEAKNESSES. Sergey Rublev Expert in information security, "Positive Technologies" ([email protected])
WPAD TECHNOLOGY WEAKNESSES Sergey Rublev Expert in information security, "Positive Technologies" ([email protected]) MOSCOW 2009 CONTENTS 1 INTRODUCTION... 3 2 WPAD REVIEW... 4 2.1 PROXY AUTO CONFIGURATION
Non-Resident Withholding Tax Rates for Treaty Countries 1
Non-Resident Withholding Tax Rates for Treaty Countries 1 firms Non-Resident Withholding Tax Rates for Treaty Countries 1 Country 2 Interest 3 Dividends 4 Royalties 5 Annuities 6 Pensions/ Algeria 15%
Praise for Directory of Global Professional Accounting and Business Certifications
Brochure More information from http://www.researchandmarkets.com/reports/2214904/ Directory of Global Professional Accounting and Business Certifications Description: Praise for Directory of Global Professional
When was UNCITRAL established? And why?
The significance of technology neutrality in support of trade facilitation 6 June 2013 Jaesung Lee (Secretary of Working Group IV on Electronic Commerce) Ahreum Lee (Former Legal Officer) Secretariat Vienna,
Introducing Clinical Trials Insurance Services Ltd
Introducing Clinical Trials Insurance Services Ltd Important Staff Richard Kelly Managing Director Richard joined CTIS in 2006 having previously managed the Pharmaceutical wholesale division at Heath Lambert
Cisco Smart Care Service
Q. What is Cisco Smart Care Service? A. Cisco Smart Care Service is a collaborative, comprehensive network wide service that enables your partner to deliver proactive network monitoring, health checkups,
Anonymous Subscriber ID (ASID) - A Mobile Web Site Developers Cookbook. Version 1.0 8/7/2008. This Cookbook is written by Alex Rutgers (MoMac).
Anonymous Subscriber ID (ASID) - A Mobile Web Site Developers Cookbook Version 1.0 8/7/2008 This Cookbook is written by Alex Rutgers (MoMac). With the special help of: Wim de Koning (Fenestrae) Jeroen
Technical & Trade School Lines World Report
Brochure More information from http://www.researchandmarkets.com/reports/1836899/ Technical & Trade School Lines World Report Description: TECHNICAL & TRADE SCHOOL LINES WORLD REPORT The Technical & Trade
Dial 00-800-0010, when prompted to enter calling number, enter 800-544-6666 American Samoa 1-800-544-6666 Number can be dialed directly Angola 0199
National Financial Services International Calling Instructions Albania 00-800-0010 Dial 00-800-0010, when prompted to enter American Samoa 1-800-544-6666 Number can be dialed directly Angola 0199 Dial
International Mobile Roaming
International Mobile Roaming Dr. Antony Srzich A presentation to the WTO Symposium on International Mobile Roaming 22 March 202 What is International Mobile Roaming? Customers can seamlessly continue to
Sophos Mobile Control Technical guide
Sophos Mobile Control Technical guide Product version: 2 Document date: December 2011 Contents 1. About Sophos Mobile Control... 3 2. Integration... 4 3. Architecture... 6 4. Workflow... 12 5. Directory
Excerpt Sudan Fixed Telecommunications: Low Penetration Rates Get a Boost from Broadband Internet and VoIP Services
Excerpt Sudan Fixed Telecommunications: Low Penetration Rates Get a Boost from Broadband Internet and VoIP Services This report is part of Pyramid Research s series of Africa & Middle East Country Intelligence
Region Country AT&T Direct Access Code(s) HelpLine Number. Telstra: 1 800 881 011 Optus: 1 800 551 155
Mondelēz International HelpLine Numbers March 22, 2013 There are many ways to report a concern or suspected misconduct, including discussing it with your supervisor, your supervisor s supervisor, another
Cyber Security Workshop Ethical Web Hacking
Cyber Security Workshop Ethical Web Hacking May 2015 Setting up WebGoat and Burp Suite Hacking Challenges in WebGoat Concepts in Web Technologies and Ethical Hacking 1 P a g e Downloading WebGoat and Burp
Telephony Toolbar Corporate. User Guide
Telephony Toolbar Corporate User Guide Release 7.1 March 2011 Table of Contents 1 About This Guide...7 1.1 Open Telephony Toolbar - Corporate... 7 1.2 First Time Login... 8 1.3 Subsequent Use... 11 2 Using
Carnegie Mellon University Office of International Education Admissions Statistics for Summer and Fall 2010
Carnegie Mellon University Admissions Statistics for and Fall 2010 New International Students and Fall 2010 Undergraduate 208 16.1% Master's 799 61.7% Doctorate 177 13.7% Exchange 80 6.2% 31 2.4% Total
Migration and Remittances: Top Countries
Migration and Remittances: Top Countries Top Immigration Countries a, 010 number of immigrants, millions United States b Russian Federation b Germany b Saudi Arabia b Canada b United Kingdom b Spain b
Regional analysis - Italy
Regional analysis - Italy Bar charts Level Level (000s) 0.00 20.00 40.00 60.00 Level (000s) 0.00 1.00 2.00 3.00 4.00 5.00 Algeria Egypt Level (000s) 0.00 10.00 20.00 30.00 40.00 50.00 Level (000s) 0.00
ICSA Labs Web Application Firewall Certification Testing Report Web Application Firewall - Version 2.1 (Corrected) Radware Inc. AppWall V5.6.4.
ICSA Labs Web Application Firewall Certification Testing Report Radware Inc. V5.6.4.1 May 30, 2013 Prepared by ICSA Labs 1000 Bent Creek Blvd., Suite 200 Mechanicsburg, PA 17050 www.icsalabs.com WAFX RADWAREINC-2013-0530-01
Research of Web Real-Time Communication Based on Web Socket
Int. J. Communications, Network and System Sciences, 2012, 5, 797-801 http://dx.doi.org/10.4236/ijcns.2012.512083 Published Online December 2012 (http://www.scirp.org/journal/ijcns) Research of Web Real-Time
Cisco Conference Connection
Data Sheet Cisco Conference Connection Cisco IP Communications a comprehensive system of powerful, enterprise-class solutions including IP telephony, unified communications, IP video/audio conferencing,
http://docs.trendmicro.com
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the product, please review the readme files,
Culture in the Cockpit Collision or Cooperation?
Culture in the Cockpit Collision or Cooperation? Dr. Nicklas Dahlstrom Human Factors Manager Understanding Safety - The Changing Nature of Safety 1 Lives lost per year How safe is flying? 100 000 10 000
How To Find Out What Countries Do With Management System Certification
PAULO SAMPAIO University of Minho, School of Engineering, Systems and Production Department Campus Gualtar 4710-057 Braga, Portugal [email protected] MANAGEMENT SYSTEMS: A GLOBAL PERSPECTIVE Summary
Load balancing Microsoft IAG
Load balancing Microsoft IAG Using ZXTM with Microsoft IAG (Intelligent Application Gateway) Server Zeus Technology Limited Zeus Technology UK: +44 (0)1223 525000 The Jeffreys Building 1955 Landings Drive
Apache Server Implementation Guide
Apache Server Implementation Guide 340 March Road Suite 600 Kanata, Ontario, Canada K2K 2E4 Tel: +1-613-599-2441 Fax: +1-613-599-2442 International Voice: +1-613-599-2441 North America Toll Free: 1-800-307-7042
Triple-play subscriptions to rocket to 400 mil.
Triple-play criptions to rocket to 400 mil. Global triple-play criptions will reach 400 million by 2017; up by nearly 300 million on the end-2011 total and up by 380 million on the 2007 total, according
Brandeis University. International Student & Scholar Statistics
1 Brandeis University International Student & Scholar Statistics 2014 2 TABLE OF CONTENTS OVERVIEW OF INTERNATIONAL STUDENT & SCHOLAR POPULATION 3 DETAILED INFORMATION ON INTERNATIONAL STUDENT POPULATION
Guidelines for DBA Coverage for Direct and Host Country Contracts
Guidelines for DBA Coverage for Direct and Host Country Contracts An Additional Help document for ADS Chapter 302 New Reference: 06/14/2007 Responsible Office: OAA/P File Name: 302sap_061407_cd48 BACKGROUND:
Your Business Connection
Your Business Connection What Kompass can do for you: Provide highly targeted leads Give in depth information about a company s structure and activity Help with market research and prospect evaluation
HP Technology Services HP NonStop Server Support
Reference guide HP Technology Services HP NonStop Server Support HP Global NonStop Solution Center (GNSC) Table of contents Global NonStop Solution Center... 2 Product support for HP NonStop and Neoview
Global AML Resource Map Over 2000 AML professionals
www.pwc.co.uk Global AML Resource Map Over 2000 AML professionals January 2016 Global AML Resources: Europe France Italy Jersey / Guernsey 8 Ireland 1 Portugal 7 Luxembourg 5 United Kingdom 1 50 11 Spain
The face of consistent global performance
Building safety & security global simplified accounts The face of consistent global performance Delivering enterprise-wide safety and security solutions. With more than 500 offices worldwide Johnson Controls
Internet Banking System Web Application Penetration Test Report
Internet Banking System Web Application Penetration Test Report Kiev - 2014 1. Executive Summary This report represents the results of the Bank (hereinafter the Client) Internet Banking Web Application
BLOOMBERG ANYWHERE FOR MOBILE CUSTOMERS
BLOOMBERG ANYWHERE FOR MOBILE CUSTOMERS Software & Connectivity Requirements 11 March 2014 Version: 1.03 BLOOMBERG ANYWHERE users have access to their information on a variety of mobile platforms including
Sulfuric Acid 2013 World Market Outlook and Forecast up to 2017
Brochure More information from http://www.researchandmarkets.com/reports/2547547/ Sulfuric Acid 2013 World Market Outlook and Forecast up to 2017 Description: Sulfuric Acid 2013 World Market Outlook and
HEALTHIEST COUNTRIES 1 to 40
BLOOMBERG RANKINGS THE WORLD'S HEALTHIEST COUNTRIES HEALTHIEST COUNTRIES 1 to 40 1 Singapore 89.45% 92.52% 3.07% 2 Italy 89.07 94.61 5.54 3 Australia 88.33 93.19 4.86 4 Switzerland 88.29 93.47 5.17 5 Japan
Wireless Broadband Access
Wireless Broadband Access Fueling Growth in Latin America, Today and Tomorrow Tony Sarallo Director of Distribution, Latin America Motorola Canopy Products Telephony/IT Connectivity Workshop Santiago,
ANALYSIS. wikia.com. YOUR NAME & SLOGAN Call Me: +11-223-444-5556
ANALYSIS wikia.com -- YOUR NAME & SLOGAN Content MOBILE DEVICES Mobile optimisation GOOGLE SEARCH RESULT LIST PREVIEW DOMAIN / URL AUDIT NUMBER OF SOCIAL MEDIA SHARES META DATA SEO AUDIT: CONTENT ANALYSIS
DEPLOYMENT GUIDE Version 1.2. Deploying the BIG-IP system v10 with Microsoft Exchange Outlook Web Access 2007
DEPLOYMENT GUIDE Version 1.2 Deploying the BIG-IP system v10 with Microsoft Exchange Outlook Web Access 2007 Table of Contents Table of Contents Deploying the BIG-IP system v10 with Microsoft Outlook Web
Cyclope Internet Filtering Proxy. - Installation Guide -
Cyclope Internet Filtering Proxy - Installation Guide - 1. Overview 3 2. Installation 4 2.1 System requirements 4 2.2 Cyclope Internet Filtering Proxy Installation 4 2.3 Client Browser Configuration 6
HTTP Response Splitting
The Attack HTTP Response Splitting is a protocol manipulation attack, similar to Parameter Tampering The attack is valid only for applications that use HTTP to exchange data Works just as well with HTTPS
Faster voice/data integration for global mergers and acquisitions
Global agility in technology solutions. sm Faster voice/data integration for global mergers and acquisitions >The InTech Group, Inc. Worldwide in-country technical resources for newly merged companies
NetFlow Feature Acceleration
WHITE PAPER NetFlow Feature Acceleration Feature Description Rapid growth in Internet and intranet deployment and usage has created a major shift in both corporate and consumer computing paradigms. This
How To Contact A Lugmarine
Sales contacts by country A - B Angola +33 1 41 35 32 64 [email protected] Australia Brazil TOTAL LUBRICANTS USA, INC. 5 North Stiles Street LINDEN NJ +507 6619 86 09 (Commercial issues) Argentina
Detecting and Exploiting XSS with Xenotix XSS Exploit Framework
Detecting and Exploiting XSS with Xenotix XSS Exploit Framework [email protected] keralacyberforce.in Introduction Cross Site Scripting or XSS vulnerabilities have been reported and exploited since 1990s.
TELECOMMUNICATION SYSTEMS AND TECHNOLOGIES Vol. I - Wireless Terrestrial Communications: Cellular Telephony - Ariel Pashtan
WIRELESS TERRESTRIAL COMMUNICATIONS: CELLULAR TELEPHONY Ariel Pashtan Aware Networks, Inc., Buffalo Grove, Illinois, USA Keywords: mobile network, mobile terminal, cellular phone, cellular service, cellular
