Hi List
I have read:
https://nakedsecurity.sophos.com/2012/01/25/smartphone-website-telephone-num...
And I have sniffed the traffic between my swisscom mobile Samsung Mobile and my Website, but can't find any of the additional headers disclosing my phone number.
Is there a trick to make a mobile phone disclose it's phone number while connected via the mobile network's operator network?
How can 'website payment' operator like 'obligo' get the phone number associated with a visitor? Obligo states they got the phone number to bill 'from the service operator'.
Would it be possible, that a fraudster injects such headers from a client to make obligo bill the wrong number?
PS: I know obligo's reputation.
Mit freundlichen Grüssen
-Benoît Panizzon-